<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Can&#x27;t resolve names after blocking rfc1918]]></title><description><![CDATA[<p dir="auto">So I just finished setting up a new box. Pretty much just default 2.4.4 firewall rules except for OpenVPN.<br />
Our old ISP used private addresses so I wasn't blocking them on the WAN. Our new ISP is a straight public address, so after I got it running with the new IP's, I went through and did a check for any settings that I could tweak and the only thing I did was block the private addresses on the WAN port.<br />
Now things are really screwed up. Clients say name resolution error on any webpage, but I can dig www.google.com from the console just fine. Can't ping google or anything other than 8.8.8.8.<br />
Is there any known bugs that would cause this?<br />
Can't post details now, but I will.<br />
And I did try to unblock the private addresses on the WAN with no change.<br />
I'm thinking something just got hosed in the OS itself but I don't know what.<br />
Any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/137078/can-t-resolve-names-after-blocking-rfc1918</link><generator>RSS for Node</generator><lastBuildDate>Sat, 11 Apr 2026 04:56:35 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/137078.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 24 Oct 2018 21:19:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Can&#x27;t resolve names after blocking rfc1918 on Thu, 25 Oct 2018 17:15:21 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kom">@<bdi>kom</bdi></a> said in <a href="/post/799964">Can't resolve names after blocking rfc1918</a>:</p>
<blockquote>
<p dir="auto">Block rfc1918 only applies to unsolicited inbound traffic, not replies to your outbound traffic.</p>
</blockquote>
<p dir="auto">Yes, I know, that's why I don't understand why making that one changed caused this.<br />
Clients are both, can't resolve anything from any of them.<br />
I've since replaced the router with a spare I had and everything is working again.<br />
Something got screwed up in the config, kinda wish I can figure out what it is but I'll probably just reset it and see if it works again.</p>
]]></description><link>https://forum.netgate.com/post/800042</link><guid isPermaLink="true">https://forum.netgate.com/post/800042</guid><dc:creator><![CDATA[Jarhead]]></dc:creator><pubDate>Thu, 25 Oct 2018 17:15:21 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t resolve names after blocking rfc1918 on Thu, 25 Oct 2018 13:24:20 GMT]]></title><description><![CDATA[<p dir="auto">Block rfc1918 only applies to unsolicited inbound traffic, not replies to your outbound traffic.  Are your clients dynamic or static?  From your client, if you try to resolve manually, does it work?  For example:</p>
<pre><code class="language-java">kom@kimono:~$ nslookup
&gt; server 10.10.4.1
Default server: 10.10.4.1
Address: 10.10.4.1#53
&gt; www.google.com
Server:         10.10.4.1
Address:        10.10.4.1#53

Non-authoritative answer:
Name:   www.google.com
Address: 172.217.2.164
Name:   www.google.com
Address: 2607:f8b0:400b:80d::2004
</code></pre>
]]></description><link>https://forum.netgate.com/post/799964</link><guid isPermaLink="true">https://forum.netgate.com/post/799964</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Thu, 25 Oct 2018 13:24:20 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t resolve names after blocking rfc1918 on Wed, 24 Oct 2018 23:04:55 GMT]]></title><description><![CDATA[<p dir="auto">I can also VPN into the box but I keep getting disconnected.</p>
]]></description><link>https://forum.netgate.com/post/799868</link><guid isPermaLink="true">https://forum.netgate.com/post/799868</guid><dc:creator><![CDATA[Jarhead]]></dc:creator><pubDate>Wed, 24 Oct 2018 23:04:55 GMT</pubDate></item><item><title><![CDATA[Reply to Can&#x27;t resolve names after blocking rfc1918 on Wed, 24 Oct 2018 22:57:22 GMT]]></title><description><![CDATA[<p dir="auto">Here's a few things I tried.</p>
<p dir="auto">"/etc/resolv.conf"<br />
nameserver 8.8.8.8<br />
nameserver 8.8.4.4<br />
search localdomain</p>
<p dir="auto">traceroute -nI 8.8.8.8<br />
traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 48 byte packets<br />
1  144.121.52.201  1.568 ms  1.450 ms  1.443 ms<br />
2  104.207.214.233  11.748 ms  8.506 ms  9.067 ms<br />
3  144.121.35.31  8.654 ms  8.679 ms  8.402 ms<br />
4  144.121.35.39  8.379 ms  8.459 ms  8.325 ms<br />
5  4.30.132.253  8.882 ms  8.857 ms  8.858 ms<br />
6  * * *<br />
7  72.14.213.34  8.776 ms  8.718 ms  8.712 ms<br />
8  108.170.248.97  8.706 ms  8.686 ms  8.733 ms<br />
9  209.85.245.195  8.813 ms  8.819 ms  8.813 ms<br />
10  8.8.8.8  9.320 ms  9.315 ms  9.329 ms</p>
<p dir="auto">ping www.google.com<br />
PING www.google.com (172.217.10.68): 56 data bytes<br />
ping: sendto: No route to host<br />
ping: sendto: No route to host<br />
ping: sendto: No route to host<br />
ping: sendto: No route to host<br />
ping: sendto: No route to host<br />
ping: sendto: No route to host</p>
<p dir="auto">Starting to wonder if it's my ISP.</p>
]]></description><link>https://forum.netgate.com/post/799866</link><guid isPermaLink="true">https://forum.netgate.com/post/799866</guid><dc:creator><![CDATA[Jarhead]]></dc:creator><pubDate>Wed, 24 Oct 2018 22:57:22 GMT</pubDate></item></channel></rss>