Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Configuring external DNS requests

    Scheduled Pinned Locked Moved DHCP and DNS
    2 Posts 2 Posters 332 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      aljames
      last edited by

      In the pfSense documentation, I read about 2 methods that can be used to effectively route all LAN external DNS requests to pfSense to resolve. It appears I could use either since I’m using DNS Resolver with forwarding disabled. I’m unsure when one might be preferred over the other?

      1). Firewall rules to block external DNS requests and pass them to pfSense:
      https://docs.netgate.com/pfsense/en/latest/dns/blocking-dns-queries-to-external-resolvers.html

      2). Use a port forward yo redirect all requests to pfSense:
      https://docs.netgate.com/pfsense/en/latest/dns/redirecting-all-dns-requests-to-pfsense.html

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Method 1 is useful if specific LAN clients need to use a specific 3rd-party DNS for whatever reason. You block all external DNS and then create rules to let some LAN clients reach out to some other DNS.

        Method 2 is more generic and less flexible. It redirects all DNS requests to pfSense. For most LANs, this is what you want.

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.