Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall Alias FQDN not working in rule

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 746 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jbsbigboy
      last edited by

      I have an openvpn rule setup on my wan int with the source address configured as a FQDN alias. The vpn will connect, but after a long period of uptime if the remote side goes down and reconnects, the FQDN based rule is not longer working. I can see that the IP of the host is still the same, but the connection is being blocked by a lower rule I have setup for logging. I need this to work as the remote side is using DynDNS and I can't rely on the IP staying the same.

      Anyone know why pfsense is failing to resolve the FQDN for this rule? If I reboot the box, everything is happy again, but just rebooting the resolver isn't effective.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        You understand the aliases are only resolved every so often. So if the client goes down and backup and gets a different IP then you could have a problem.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • J
          jbsbigboy
          last edited by

          Yes, I understand that. I can deal with a short delay. It appears that these entries are supposed to be refreshed every 300 secs, but in this case, the entries no longer continue to be refreshed at all.

          1 Reply Last reply Reply Quote 0
          • GrimsonG
            Grimson Banned
            last edited by

            https://redmine.pfsense.org/issues/8758

            J 1 Reply Last reply Reply Quote 0
            • J
              jbsbigboy @Grimson
              last edited by

              @grimson Thanks. That appears to be just what the problem is. Hopefully its patched soon.

              1 Reply Last reply Reply Quote 0
              • J
                jbsbigboy
                last edited by

                This appears to be the same issue. https://forum.netgate.com/topic/124467/filterdns-stops-working/36 Too bad no progress is being made on a fix.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.