Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    flush dns after wan ip change

    Scheduled Pinned Locked Moved DHCP and DNS
    14 Posts 5 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gregor4711
      last edited by

      I have pfsense 2.4.4-RELEASE (amd64) built on Thu Sep 20 09:03:12 EDT 2018
      FreeBSD 11.2-RELEASE-p3, which works great and really happy with it.

      But I discover in my setup one issue, the dns cache would not updated after a new WAN IP was provided by internet provider from pfsense.

      I can do a manual restart over the gui (which solf the problem), but I would like to have the flush of dns after a WAN IP change automatically.

      It is possible to write a script or using existing script to let do the dns restart automatically by pfsence after WAN IP change was detected?

      V 1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        First Update to the latest 2.4.4-p2 Release an check again.
        There is some DNS Stuff fixed in 2.4.4-p1...

        -Rico

        1 Reply Last reply Reply Quote 0
        • G
          gregor4711
          last edited by

          now up to 2.4.4-RELEASE-p2 (amd64)
          built on Wed Dec 12 07:40:18 EST 2018
          FreeBSD 11.2-RELEASE-p6

          but same same.

          Is there any setup / checkbox to flush ore reset DNS Resolver / DNS Server to use the new ip from my website and not the old cached?

          1 Reply Last reply Reply Quote 0
          • V
            viragomann @gregor4711
            last edited by

            @gregor4711 said in flush dns after wan ip change:

            But I discover in my setup one issue, the dns cache would not updated after a new WAN IP was provided by internet provider from pfsense.

            Why should it do that?

            A WAN IP change can trigger an DynDNS update. But why should it flush the resolver cache?

            1 Reply Last reply Reply Quote 0
            • G
              gregor4711
              last edited by

              I have an owncloud and mail server behind pfsense FW.
              It is connected to an dyndns service since. My ISP change all 24h the IP, which is my WAN IP.

              1. after the change of IP from ISP, the update of official DNS is proceed within less than 30 sec.
              2. If I call my email server from outside (via mobile etc.) the mail server is up and working.
              3. If I call from inside (behind pfsense ) the domain name is not more aviable since it route to the old ip.
              4. If I flush pfsense dns resolver & DNS Server manually all is fine again:)
              5. Therefore I would like to have automatic restart of DNS resolver an DNS server in pfsense after wan IP change
              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                A better solution would be to setup DNS overrides for your hostnames.

                1 Reply Last reply Reply Quote 0
                • G
                  gregor4711
                  last edited by

                  How this can work, wegen the IP is changed all 24 hours?

                  1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan
                    last edited by

                    The DNS host override declares the IP of your mail host.
                    On the Internet , your DDNS service will resolver your domain to your WAN IP.
                    Locally, a host override (same URL) will resolve to a local LAN IP (and that one never changes).

                    Using host overrides, you do not use the WAN IP, but the LAN IP.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • G
                      gregor4711
                      last edited by

                      Gertjan, many thanks for your exelent explanation of how it works.
                      I'll try next days and will come back with the result

                      1 Reply Last reply Reply Quote 0
                      • V
                        viragomann
                        last edited by

                        Of course, this requires that your clients use an internal DNS service like the Resolver of pfSense.
                        So in the Resolver settings go down to host overrides and add your hosts by entering its FQDN and its local IP.

                        1 Reply Last reply Reply Quote 0
                        • G
                          gregor4711
                          last edited by

                          ok, now I got it. That means, the resolver will not ask the outside dns, but will deliver lokal IP when client ask for the dns www.xxxxx.yy, right?

                          What is with the cert? It is linked to dns (https://www.xxxxx.yy) name but not do local ip, will it still work, if the resolver provide lokal ip?

                          1 Reply Last reply Reply Quote 0
                          • GrimsonG
                            Grimson Banned
                            last edited by

                            https://www.netgate.com/docs/pfsense/nat/accessing-port-forwards-from-local-networks.html#method-2-split-dns yes certs issued for a domain name don't care about the IP address.

                            1 Reply Last reply Reply Quote 0
                            • GertjanG
                              Gertjan
                              last edited by

                              Exact.
                              Certs are host + domain based. The IP is a don't care.

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              1 Reply Last reply Reply Quote 0
                              • G
                                gregor4711
                                last edited by

                                Thank you all for you valuable support, I'll try and come back later (maby with new questions :))

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.