<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Intermittently losing DNS]]></title><description><![CDATA[<p dir="auto">I using pfsense 2.4.4 and just recently noticed intermittently I'm loosing my DNS. When I ping www.google.com from my computer I get Host name lookup failure.  I'm using Quad9 DNS servers over TLS.  Adding 208.67.220.220 to the System/General setup/DNS Server Settings will fix it.<br />
I've tried upgrading to 2.4.4_1 and getting the same problem.  I believe this problem started after trying to migrate to new hardware but I'm back on the original pfsense box without any configuration changes.<br />
I have no idea what the issue is.</p>
]]></description><link>https://forum.netgate.com/topic/138738/intermittently-losing-dns</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Jul 2026 09:43:53 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/138738.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 15 Dec 2018 01:06:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Intermittently losing DNS on Sun, 17 Feb 2019 03:52:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/naskar">@<bdi>naskar</bdi></a></p>
<p dir="auto">I don't have a good answer for you about enabling DNSSEC when using Cloudflare DoT.  The sites that do support DNSSEC are few. I saw something the other day that DNSSEC sites are in the single digit percentage of all sites on the internet. I added the DNSSEC detector add-on on Firefox and I can confirm from my own experience that not too many sites I visit support DNSSEC.  With DNSSEC disabled on the DNS Resolver, I still pass all of the DNSSEC tests on these sites:</p>
<ul>
<li><a href="https://rootcanary.org/test.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://rootcanary.org/test.html</a></li>
<li><a href="http://dnssec.vs.uni-due.de/" target="_blank" rel="noopener noreferrer nofollow ugc">http://dnssec.vs.uni-due.de/</a></li>
<li><a href="http://en.conn.internet.nl/connection/" target="_blank" rel="noopener noreferrer nofollow ugc">http://en.conn.internet.nl/connection/</a></li>
<li><a href="http://0skar.cz/dns/en/" target="_blank" rel="noopener noreferrer nofollow ugc">http://0skar.cz/dns/en/</a></li>
</ul>
<p dir="auto">This <a href="https://forum.netgate.com/topic/134037/dnssec-on-cloudflare-tls/3">thread</a> does shed some light on the topic.</p>
]]></description><link>https://forum.netgate.com/post/824460</link><guid isPermaLink="true">https://forum.netgate.com/post/824460</guid><dc:creator><![CDATA[Xentrk]]></dc:creator><pubDate>Sun, 17 Feb 2019 03:52:26 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Sat, 19 Jan 2019 14:52:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xentrk">@<bdi>xentrk</bdi></a> said in <a href="/post/818530">Intermittently losing DNS</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/naskar">@<bdi>naskar</bdi></a><br />
Yes, Cloudflare was the other DNS we tested with and it had no issues like Quad 9. It seems to play better. Just note that the Cloudflare help site https://1.1.1.1/help does not support DNSSEC and will fail the DoT test if you have DNSSEC turned on.</p>
</blockquote>
<p dir="auto">I changed to Cloudfare and have DNSSEC enabled and it seems to be working. But after going to your link I realized that DoT wasn't working.  After turning it off DoT works.  Is DNSSSEC not important?  Is it ok to not use it?</p>
<p dir="auto">Or are you just saying leave DNSSEC on and ignore what the https://1.1.1.1/help says about DoT?</p>
]]></description><link>https://forum.netgate.com/post/818547</link><guid isPermaLink="true">https://forum.netgate.com/post/818547</guid><dc:creator><![CDATA[NasKar]]></dc:creator><pubDate>Sat, 19 Jan 2019 14:52:40 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Sat, 19 Jan 2019 11:51:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/naskar">@<bdi>naskar</bdi></a><br />
Yes, Cloudflare was the other DNS we tested with and it had no issues like Quad 9. It seems to play better. Just note that the Cloudflare help site https://1.1.1.1/help does not support DNSSEC and will fail the DoT test if you have DNSSEC turned on.</p>
]]></description><link>https://forum.netgate.com/post/818530</link><guid isPermaLink="true">https://forum.netgate.com/post/818530</guid><dc:creator><![CDATA[Xentrk]]></dc:creator><pubDate>Sat, 19 Jan 2019 11:51:20 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Fri, 18 Jan 2019 20:55:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/xentrk">@<bdi>xentrk</bdi></a> said in <a href="/post/818305">Intermittently losing DNS</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/naskar">@<bdi>naskar</bdi></a></p>
<p dir="auto">Quad9 appears to have issue resolving when using DNSSEC from recent testing I and others have done recently. Sometimes a refresh or two is required to load the page.</p>
</blockquote>
<p dir="auto">Would I be better off switching to Cloudflare’s DNS service?</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a> said in <a href="/post/818323">Intermittently losing DNS</a>:</p>
<blockquote>
<p dir="auto">A correct time is very important for DNSSEC.<br />
Can you have DNSSEC and Use SSL/TLS for outgoing DNS Queries to forwarding servers?</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/818469</link><guid isPermaLink="true">https://forum.netgate.com/post/818469</guid><dc:creator><![CDATA[NasKar]]></dc:creator><pubDate>Fri, 18 Jan 2019 20:55:23 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Fri, 18 Jan 2019 07:47:33 GMT]]></title><description><![CDATA[<p dir="auto">A correct time is very important for DNSSEC.</p>
]]></description><link>https://forum.netgate.com/post/818323</link><guid isPermaLink="true">https://forum.netgate.com/post/818323</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Fri, 18 Jan 2019 07:47:33 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Fri, 18 Jan 2019 04:06:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/naskar">@<bdi>naskar</bdi></a></p>
<p dir="auto">Quad9 appears to have issue resolving when using DNSSEC from recent testing I and others have done recently. Sometimes a refresh or two is required to load the page.</p>
]]></description><link>https://forum.netgate.com/post/818305</link><guid isPermaLink="true">https://forum.netgate.com/post/818305</guid><dc:creator><![CDATA[Xentrk]]></dc:creator><pubDate>Fri, 18 Jan 2019 04:06:35 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Mon, 31 Dec 2018 23:08:45 GMT]]></title><description><![CDATA[<p dir="auto">Could a problem with the ntp server cause dns issues?<br />
I reset my system clock to the correct time and changed the NTP server to the WAN interface.<br />
So far DNS is working.<br />
Is the best way to check looking at the DNS resolver log and seeing entries with "A IN NOERROR 0.057908 0 58" in it?</p>
]]></description><link>https://forum.netgate.com/post/814491</link><guid isPermaLink="true">https://forum.netgate.com/post/814491</guid><dc:creator><![CDATA[NasKar]]></dc:creator><pubDate>Mon, 31 Dec 2018 23:08:45 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Tue, 18 Dec 2018 01:40:51 GMT]]></title><description><![CDATA[<p dir="auto">I'm not sure but I think the intermittent loss of DNS was due to running out of memory.  After I removed snort which was eating up my memory the intermittent nature resolved.  Does that sound like that issue would cause that problem?</p>
<p dir="auto">My DNS stops working when I enable Quad9 DNS servers over TLS.  Here are my settings.</p>
<p dir="auto"><img src="/assets/uploads/files/1545097011362-tls-00-resized.jpg" alt="0_1545097011864_TLS-00.jpg" class=" img-fluid img-markdown" /><br />
Firewall/rules/LAN<br />
<img src="/assets/uploads/files/1545097019311-tls-01-resized.jpg" alt="0_1545097019903_TLS-01.jpg" class=" img-fluid img-markdown" /><br />
System/General Setup/DNS Server Settings<br />
<img src="/assets/uploads/files/1545097024907-tls-02-resized.jpg" alt="0_1545097025507_TLS-02.jpg" class=" img-fluid img-markdown" /><br />
Error in web browser<br />
<img src="/assets/uploads/files/1545097030677-tls-03.jpg" alt="0_1545097031263_TLS-03.jpg" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/811860</link><guid isPermaLink="true">https://forum.netgate.com/post/811860</guid><dc:creator><![CDATA[NasKar]]></dc:creator><pubDate>Tue, 18 Dec 2018 01:40:51 GMT</pubDate></item><item><title><![CDATA[Reply to Intermittently losing DNS on Mon, 17 Dec 2018 15:12:29 GMT]]></title><description><![CDATA[<p dir="auto">I've noticed that sometimes some of the public servers intermittently fail when using DNS over TLS or DNSSEC.</p>
]]></description><link>https://forum.netgate.com/post/811668</link><guid isPermaLink="true">https://forum.netgate.com/post/811668</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Mon, 17 Dec 2018 15:12:29 GMT</pubDate></item></channel></rss>