  • Guys. So i've read a lot of posts here of resolver vs dns forwarder. Help me understand one thing with my testings. I'm a newbie so if i'm asking something obvious to you please school me.

    Why is dns resolver SO slow 1 sec but in real time it takes 10 seconds to display NEW full page that heasn't been visted before but when i enable DNS Query Forwarding pfsense is fastest then.

    DISABLED(UNCHECKED) DNS Query Forwarding pffire is 1000 ms  10 seconds to display full page with rest of the content

    VS DNS Query Forwarding enabled (CHECKED) which is now displays my pfsense being fastest. Why is unchecked forwarding SO slow. Isn't that preffered way of dns resolution. It simply does not work for

    me in any configuration i tried. I'm newbie so help me understand what i'm not understanting here, why unless checked it's so freaking slow??? There will be plenty of newly visited sites.

    I don't wanna wait 10 seconds for each. It's a turtle. Also notice queries improve by half from 60ms to 30ms not that it's much difference but 1000ms or 3500ms vs 35m-60ms is huge difference

    especially with other html content that needs to be pulled down as well. Also look at the max 200ms vs 3500ms …that's huge. Version of pfsense is 2.4.2-RELEASE-p1 (amd64)

    Is this something to do with the way pfsense settings are setup or is this caused by ISP Comcast/Xfinity in my case?

    With dns query forwarding those dns A records are still being cached on in pfsense dns resolver server correct?

    And check this out. The fastest server now slows down, not that it matters as my pfsense is fastest now but it says it shares cache with pfsense box, good but why is it slow?

  • After few more test, few more reads here at forum and few more settings changes i have figured it out myself. Much better now. I will backup the config, just in case i decide to play with settings later and screw this up lol. This is using DNS Resolver.

    Now that DNS and dhcp are working correctly and my asus router is now access point only mode,  i will move onto firewall and packages. I spent 2 days getting DNS working correctly. I will eventually be moving onto OpenVPN encryption and have AES-NI chip. If i'm still not understanding something here please comment.

    I'm still unsure why there is so much hijacking and incorrect notes. It could be false positive but i simply am wondering. Anyone cares to comment?

  • Simple advice : dump the program and your problem is solved.

    One simple line in it's output says it all :
    When it asks to "" : "what is the A for google.com" it comes back with
    google.com appears incorrect
    And a go for www.google.com comes back with the hijacked message.

    But wait … it won't take you very long (using Google !) to find out that "" IS a valid IP for google.com ...

    So, what now ? You call Google, the ones who run to tell them that their master DNS has been tampered with ? (please, record the call and drop in on youtube, I guarantee high scores).

    Somehow, this program isn't able to obtain all DNS A records ... (the author didin't read and programmed all this : https://www.google.fr/search?q=How+to+find+all+IP+og+Google&ie=utf-8&oe=utf-8&client=firefox-b&gfe_rd=cr&dcr=0&ei=D6ifWoTmGO-stgfu45igCg)

    "Why is dns resolver SO slow 1 sec but in real time it takes 10 seconds to display NEW full page"

    I am with Gertjan on this - and yes I would love to see this recorded call to google about how their dns has been hijacked… Could do that with double feature on twitter as well ;)

    Vs using some nonsense tool about how fast X NS is over another... Why don't you actually troubleshoot why you might be having a problem with lookups..  Unless your on a really bad internet connection, or trying to look up something where their NS are on the other side of the planet walking the tree from roots should be really quick... Your talking ms to do a full lookup..

    Keep in mind only walk down from roots when nothing has been cached already.  unbound prob already knows NS for .com, so doesn't need to ask for that, just go straight to those to ask for your domain.com authoritative ns, and then direct to one of those..

    A simple dig www.domain.tld +trace should give you all the NS in line from roots to the authoritative servers for the domain.  So lets see that to where your having a problem and can figure out where you might be having a problem that is dns related - if anything.

    example... here is dig to www.google.com

  • .. added to that : the whole boatload is DNSSEC certified, if the domain adopted DNSSEC.