Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver with Enable Forwarding Mode

    Scheduled Pinned Locked Moved DHCP and DNS
    4 Posts 2 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Michael
      last edited by

      Hello!

      According to this documentation - https://www.netgate.com/docs/pfsense/dns/unbound-dns-resolver.html - the Enable Forwarding Mode checkbox only defines what dns servers - either root or some other upstream servers - will answer the quiries. But when I select this checkbox, DNS Resolver stops listening on 53 port (at least Diagnostic\Test Port displays "Connection Failed on the pfsense's port 53) and no dns quieries can be sent from the lan network to the pfsense's lan address (the pfsense itself does access the upstream servers correctly).

      Is this behaviour by desing or anything works incorrectly?

      Thank you in advance,
      Michael

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Check the resolver log. Odds are, you have some custom DNS Resolver option that ends up in the wrong context, which causes unbound to fail.

        In the advanced options of the DNS resolver, add a line at the top that says server: and then re-save.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M
          Michael
          last edited by

          Hi jimp,

          "Odds are, you have some custom DNS Resolver option" - no, it's configuration is as out of box. The single change is selecting the "Enable Forwarding Mode" option. If I clear the resolver's log and apply the change the only log records would be

          notice: init module 0: validator
          notice: init module 1: iterator
          info: start of service (unbound 1.7.3).

          From this point onwards unbound stops listening on port 53.

          Regarding "add a line at the top that says server:" - sorry but I don't see a way to add any line in the Advanced tab - there are only fields to type something.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Not the advanced options tab, but here:

            0_1543326632641_Selection_107.jpg

            That's on the main DNS Resolver tab

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.