• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS Resolver Log Error sending queries to 1.1.1.1

Scheduled Pinned Locked Moved DHCP and DNS
49 Posts 16 Posters 10.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    behemyth
    last edited by Apr 4, 2018, 11:25 PM

    I'm also getting the following error once i switch to using cloudflare

    There were error(s) loading the rules: /tmp/rules.debug:19: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [19]: table <bogonsv6> persist file "/etc/bogonsv6"
    @ 2018-04-04 19:21:23

    This is using 2.4.3 w/8gb of mem.

    I'm pretty sure I saw this was being looked at in 2.4.4

    1 Reply Last reply Reply Quote 0
    • P
      promo
      last edited by Apr 5, 2018, 2:08 AM

      Do we have to wait for an update for this to be fixed? Was anybody successful in getting the Cloudflare config to work?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • G
        gsmornot
        last edited by Apr 5, 2018, 3:04 AM

        @promo:

        Do we have to wait for an update for this to be fixed? Was anybody successful in getting the Cloudflare config to work?

        Thanks!

        It worked until this morning so I left the config in place and added entries for Quad9 as well. If they both provide the DNS TLS might as well have both in the list.

        1 Reply Last reply Reply Quote 0
        • P
          promo
          last edited by Apr 5, 2018, 2:00 PM

          @gsmornot:

          @promo:

          Do we have to wait for an update for this to be fixed? Was anybody successful in getting the Cloudflare config to work?

          Thanks!

          It worked until this morning so I left the config in place and added entries for Quad9 as well. If they both provide the DNS TLS might as well have both in the list.

          The point is to be able to use Cloudflare as the primary DNS since their service is faster.

          1 Reply Last reply Reply Quote 0
          • G
            gsmornot
            last edited by Apr 5, 2018, 2:10 PM Apr 5, 2018, 2:04 PM

            @promo:

            @gsmornot:

            @promo:

            Do we have to wait for an update for this to be fixed? Was anybody successful in getting the Cloudflare config to work?

            Thanks!

            It worked until this morning so I left the config in place and added entries for Quad9 as well. If they both provide the DNS TLS might as well have both in the list.

            The point is to be able to use Cloudflare as the primary DNS since their service is faster.

            Agree but it does not work for me. If I only have Cloudflare in my config I cannot resolve.

            Apr 5 09:08:16 unbound 70814:1 error: SSL_read syscall: Connection reset by peer

            Quad9 works though.

            1 Reply Last reply Reply Quote 0
            • W
              wgstarks
              last edited by Apr 5, 2018, 2:31 PM

              The Cloudflare settings still are not working and Cloudflare is reporting that they are not experiencing any service problems. Perhaps they have made some change that either inadvertently or deliberately blocks this? Regardless, it seems that it isn’t likely to work “as is”.

              Hope I’m wrong.😕

              Box: SG-4200

              1 Reply Last reply Reply Quote 0
              • P
                promo
                last edited by Apr 5, 2018, 2:39 PM

                @wgstarks:

                The Cloudflare settings still are not working and Cloudflare is reporting that they are not experiencing any service problems. Perhaps they have made some change that either inadvertently or deliberately blocks this? Regardless, it seems that it isn’t likely to work “as is”.

                Hope I’m wrong.😕

                I was reading a post on one of the forums and some there seems to think this is a pfsense issue with the Cloudflare certificate.

                1 Reply Last reply Reply Quote 0
                • G
                  gsmornot
                  last edited by Apr 5, 2018, 3:01 PM

                  @promo:

                  @wgstarks:

                  The Cloudflare settings still are not working and Cloudflare is reporting that they are not experiencing any service problems. Perhaps they have made some change that either inadvertently or deliberately blocks this? Regardless, it seems that it isn’t likely to work “as is”.

                  Hope I’m wrong.😕

                  I was reading a post on one of the forums and some there seems to think this is a pfsense issue with the Cloudflare certificate.

                  Stange thing is, it worked for two days before it stopped at @ Midnight local two nights ago.

                  1 Reply Last reply Reply Quote 0
                  • K
                    KOM
                    last edited by Apr 5, 2018, 3:21 PM

                    https://tech.slashdot.org/story/18/04/05/0420247/1111-cloudflares-new-dns-attracting-gigabits-per-second-of-rubbish

                    If they can't handle the bogus traffic, maybe they should move to a host that specializes in DDoS protections…  ;D ;D

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by Apr 5, 2018, 3:34 PM

                      ^ exactly… Why anyone would even want to point their dns to this is beyond me....

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • P
                        promo
                        last edited by Apr 5, 2018, 3:38 PM

                        @johnpoz:

                        ^ exactly… Why anyone would even want to point their dns to this is beyond me....

                        Do you use QUAD9?

                        1 Reply Last reply Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator
                          last edited by Apr 5, 2018, 3:52 PM

                          No I resolve with dnssec.. Not going to forward my queries to any specific dns thank you very much.  I will just run my own resolver as it should be..

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • R
                            Ralphys
                            last edited by Apr 5, 2018, 3:56 PM

                            I use Quad9 and I find value in their service. I have had 2 issues with them and contacting Quad9 has been to my surprise very easy; they are very professional and responsive. They have addressed the issues rather quickly and have been kind enough to follow up with me.

                            1 Reply Last reply Reply Quote 0
                            • R
                              rdlugosz
                              last edited by Apr 5, 2018, 4:04 PM

                              Quad9 seems to provide a nice value-add by attaching block lists to their results. Likely a setup that you could easily recreate with pfSense, although something to be said for the ease of pointing to them & getting it for free. Also I'd assume they have access to more exhaustive lists than what we could maintain privately.

                              I'm actually in touch with their support right now and agree that they're pretty responsive. There's one or two hops between me and their service that drop lots of packets… Results in occasional long delays for a DNS lookup (at least, that's my theory as to why I see this). I sent them a couple example reports from mtr; maybe they'll have better luck contacting whomever is responsible for those systems than I would.

                              1 Reply Last reply Reply Quote 0
                              • I
                                ivor
                                last edited by Apr 5, 2018, 4:11 PM

                                @promo:

                                I was reading a post on one of the forums and some there seems to think this is a pfsense issue with the Cloudflare certificate.

                                I'm not sure what you read, but Cloudflare person said clearly:

                                Thanks for the report! This is going to be fixed in the next upgrade that's being rolled out.
                                There was an interop issue in the last upgrade with Unbound as it sends the frame size and the actual DNS message in two separate packets instead of both at once.

                                From: https://community.cloudflare.com/t/1-1-1-1-was-working-but-not-anymore/15136/4

                                Need help fast? Our support is available 24/7 https://www.netgate.com/support/

                                1 Reply Last reply Reply Quote 0
                                • J
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by Apr 5, 2018, 4:12 PM

                                  Yeah shepherds are normally very attentive to their sheep, as they gather their flock ;) heheheeh

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • P
                                    promo
                                    last edited by Apr 5, 2018, 4:15 PM

                                    @ivor:

                                    @promo:

                                    I was reading a post on one of the forums and some there seems to think this is a pfsense issue with the Cloudflare certificate.

                                    I'm not sure what you read, but Cloudflare person said clearly:

                                    Thanks for the report! This is going to be fixed in the next upgrade that's being rolled out.
                                    There was an interop issue in the last upgrade with Unbound as it sends the frame size and the actual DNS message in two separate packets instead of both at once.

                                    From: https://community.cloudflare.com/t/1-1-1-1-was-working-but-not-anymore/15136/4

                                    I stand corrected! My apologies!

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      promo
                                      last edited by Apr 5, 2018, 4:35 PM

                                      @johnpoz:

                                      No I resolve with dnssec.. Not going to forward my queries to any specific dns thank you very much.  I will just run my own resolver as it should be..

                                      So when your resolver does not know a host's IP because it is not cached, where does it forward the query? No need to get upset, I am just asking a question!

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        MoonKnight
                                        last edited by Apr 5, 2018, 4:37 PM

                                        @ivor:

                                        We have updated the blog post with Quad9 settings https://www.netgate.com/blog/dns-over-tls-with-pfsense.html

                                        Hi,

                                        First of all, thanks for the Tips&Tricks guide :)

                                        DNS over TLS doesn't work for me. I run into this issue and lost Internet to.

                                        Apr 5 18:29:19    unbound    7412:0    info: start of service (unbound 1.6..
                                        Apr 5 18:29:19    unbound    7412:0    error: duplicate forward zone . ignored.
                                        Apr 5 18:29:19    unbound    7412:3    error: duplicate forward zone . ignored.
                                        Apr 5 18:29:19    unbound    7412:2    error: duplicate forward zone . ignored.
                                        Apr 5 18:29:19    unbound    7412:1    error: duplicate forward zone . ignored.
                                        Apr 5 18:29:19    unbound    7412:0    notice: init module 1: iterator
                                        Apr 5 18:29:19    unbound    7412:0    notice: init module 0: validator
                                        Apr 5 18:29:19    unbound    7412:0    notice: Restart of unbound 1.6.8.
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 3: requestlist max 0 avg 0 exceeded 0 jostled 0
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 3: 0 queries, 0 answers from cache, 0 recursions, 0 prefetch, 0 rejected by ip ratelimiting
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 2: requestlist max 0 avg 0 exceeded 0 jostled 0
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 2: 0 queries, 0 answers from cache, 0 recursions, 0 prefetch, 0 rejected by ip ratelimiting
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 1: requestlist max 0 avg 0 exceeded 0 jostled 0
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 1: 0 queries, 0 answers from cache, 0 recursions, 0 prefetch, 0 rejected by ip ratelimiting
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 0: requestlist max 0 avg 0 exceeded 0 jostled 0
                                        Apr 5 18:29:19    unbound    7412:0    info: server stats for thread 0: 0 queries, 0 answers from cache, 0 recursions, 0 prefetch, 0 rejected by ip ratelimiting
                                        Apr 5 18:29:19    unbound    7412:0    info: service stopped (unbound 1.6..
                                        Apr 5 18:29:19    unbound    7412:0    info: start of service (unbound 1.6..
                                        

                                        --- 24.11 ---
                                        Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                                        Kingston DDR4 2666MHz 16GB ECC
                                        2 x HyperX Fury SSD 120GB (ZFS-mirror)
                                        2 x Intel i210 (ports)
                                        4 x Intel i350 (ports)

                                        1 Reply Last reply Reply Quote 0
                                        • K
                                          KOM
                                          last edited by Apr 5, 2018, 5:20 PM

                                          So when your resolver does not know a host's IP because it is not cached, where does it forward the query?

                                          The root servers, of course.

                                          https://en.wikipedia.org/wiki/Root_name_server

                                          1 Reply Last reply Reply Quote 0
                                          29 out of 49
                                          • First post
                                            29/49
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received