Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    DNS over TLS - 2.4.3 to 2.4.4

    pfBlockerNG
    2
    4
    1328
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      smerm07 last edited by

      Hi,

      I just updated my pfsense from 2.4.3 to 2.4.4.

      pfblockerng configured with custom dns resolver config as the following:

      ssl-upstream: yes
      do-tcp: yes
      forward-zone:
      name: "."
      # Below 4 addresses are Cloudflare DNS
      forward-addr: 1.1.1.1@853
      forward-addr: 1.0.0.1@853
      forward-addr: 2606:4700:4700::1111@853
      forward-addr: 2606:4700:4700::1001@853
      server:include: /var/unbound/pfb_dnsbl.*conf

      Now with the 2.4.4 version, i believe the options are now GUI based. Can i remove all the above custom config and have the following in the GUI selected:

      Respond to incoming SSL/TLS queries from local clients
      Enable Forwarding Mode
      Use SSL/TLS for outgoing DNS Queries to Forwarding Servers

      Will pfblockerng still work?

      thanks in advanced.

      1 Reply Last reply Reply Quote 0
      • jimp
        jimp Rebel Alliance Developer Netgate last edited by

        As long as you set the same DNS servers under System > General, then those options will be fine. You do not need to have the "respond to incoming SSL/TLS queries from local clients" option set unless you want it. That lets unbound work as an SSL/TLS Server, the outgoing query option is to act as an SSL/TLS Client which is what you had before.

        pfBlockerNG should be unaffected.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 2
        • S
          smerm07 last edited by

          thanks for the response.

          do i need to keep anything in the custom options field then? i presume no.

          1 Reply Last reply Reply Quote 0
          • jimp
            jimp Rebel Alliance Developer Netgate last edited by

            No, you do not.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 1
            • First post
              Last post