• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS not resolving over VPN

Scheduled Pinned Locked Moved IPsec
6 Posts 4 Posters 865 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    msalonius
    last edited by Mar 19, 2018, 5:41 PM

    Hi All,

    I have a IPSEC site to site VPN

    Site 1: 192.168.1.0/24
    Site 2: 10.10.10.0/24 -> DNS Server 10.10.10.9

    The PC's in Site 1 cannot resolve DNS via the remote DNS Server…I can ping anything from Site 1 to Site 2 and vice versa via their IP addresses but I can't resolve anything.

    Any Ideas?

    1 Reply Last reply Reply Quote 0
    • M
      msalonius
      last edited by Mar 20, 2018, 2:01 AM

      Any ideas anyone?

      1 Reply Last reply Reply Quote 0
      • M
        MrV0
        last edited by Mar 21, 2018, 12:40 PM

        Have you setup DNS suffixes in TCP/IP settings on the site 1 systems?
        Please can you show your DHCP scope options.

        1 Reply Last reply Reply Quote 0
        • N
          NogBadTheBad
          last edited by Mar 21, 2018, 3:51 PM

          Tried adding site 1 subnet to the access list ?

          Services -> DNS Resolver -> Access Lists

          https://doc.pfsense.org/index.php/Unbound_DNS_Resolver#Access_Lists_Tab

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • M
            MrV0
            last edited by Mar 21, 2018, 4:46 PM Mar 21, 2018, 4:41 PM

            @NogBadTheBad:

            Tried adding site 1 subnet to the access list ?

            Services -> DNS Resolver -> Access Lists

            https://doc.pfsense.org/index.php/Unbound_DNS_Resolver#Access_Lists_Tab

            Do you have a windows server handling DHCP?

            1 Reply Last reply Reply Quote 0
            • D
              derjuden
              last edited by derjuden Apr 19, 2023, 5:22 PM Apr 19, 2023, 4:38 PM

              Since this is basically my same problem.
              I setup a site to site VPN.
              Site 1 is a remote office.
              Site 2 is our DC with our domain controller and DNS servers.
              users at site 1 need to reach systems by DNS at site 2.

              I added a Domain Override to the DNS resolver in the pfsense firewall at site 1 with our domain and the DNS server at site 2 to send the queries to. When I did this the only thing that can be resolved by a DNS is my primary Domain controller. It happens to be a DNS server as well.
              I've tried adding the DNS servers at site 2 to the general setup DNS server list as well after the ISP DNS servers.
              at Site 2 I have a watchguard firewall.
              I looked at this as well https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/access-firewall-over-ipsec.html#ipsec-fwtraffic
              but I don't think this is relates since if I set the DNS server on a local machine to the IP of the DNS server at site 2 I can resolve everything at site 2. I'd like to just do this through the pfsense at site 1.

              I just put my domain DNS server as the primary DNS for the DHCP leases ( Services / DHCP Server / LAN) then google DNS, and then lastly our ISP DNS. Everything works as expected this way.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received