PfBlockerNG and another DNS server within LAN



  • Hi guys,

    If the question has been asked before I apologize.
    My setup is as follows:
    pfsense v2.4.2 x64 with squid, squidguard, dhcp and dnsresolver with forwarding mode disabled.
    Another DNS server within LAN, a bind9 running on a ubuntu 16.04 forwarding all the requests to the pfsense DNS.
    My LAN devices are getting both DNS addresses (pfsense and ubuntu) when dhcp address is assigned as dns autoconfiguration.
    My question:
    Is this setup going to work if I want to use pfblockerng or I am defeating the purpose of this package?
    In my mind, I believe it should work but I just need another opinion to be sure.

    Thanks


  • Moderator

    You can still use an internal DNS server. You just have to make sure that the internal DNS server has its external forwarders set to only pfSense. To utilize DNSBL, you will need to use Unbound and not the DNSMasq forwarder in pfSense.



  • @BBcan177:

    You can still use an internal DNS server. You just have to make sure that the internal DNS server has its external forwarders set to only pfSense. To utilize DNSBL, you will need to use Unbound and not the DNSMasq forwarder in pfSense.

    That's what I thought, thank you!


Log in to reply