Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS with iOS

    Scheduled Pinned Locked Moved General pfSense Questions
    22 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thorer01
      last edited by

      I am a little stumped and looking for some ideas. I was seeing some really slow DNS times on my iOS devices, iphones and ipads in my network. In the order of hundreds of milliseconds. I was troubleshooting this by using the he.net app on the devices. Then i noticed that in the search bar where you specify which dns you want to query mine was showing a weird entry. I checked the same weird entry, spaces, not all servers listed was occurring across all of my devices, which led me to check the settings on my router.

      Everything looked normal on my router. When I changed my iOS device network dns settings from automatic to manual, everything was great. The servers showed normal in the list in the he.net app and the dns speed was back to normal (20-40msec).

      I think i have narrowed it down to either something hinky with pfsense (unlikely) or an issue with iOS doing something dumb (likely).

      Anyone tracking what i have going on? Seen something similar?

      I have uploaded my screenshots of my configs here.

      https://imgur.com/a/5JBaxhH

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        And what are those IPs?

        Why are you handing out 2.. out of the box pfsense will just hand out its IP for dns.. On that interface dhcpd is running on.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        T 1 Reply Last reply Reply Quote 0
        • T
          thorer01 @johnpoz
          last edited by

          @johnpoz I use pi-hole for dns ad filtering, I have two for redundancy sake, each ns has a v4 and a v6 address. A client should be receiving 4 ns. 2 v4 address via DHCP, and 2 v6 via the router advertisement.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Ok.. So if your clients are pointing to pihole for dns, where does pihole point to?

            and

            which dns you want to query mine was showing a weird entry.

            What was your client pointing too?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            T 1 Reply Last reply Reply Quote 0
            • T
              thorer01 @johnpoz
              last edited by

              @johnpoz the upstream for the piholes are the pfsense router.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Ok... I have a sim setup.. where pfsense then resolves.

                So now that your clients are pointing to your pihole your working fine???

                which dns you want to query mine was showing a weird entry.

                What was this weird entry??

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • T
                  thorer01
                  last edited by

                  look in the 3rd image i posted of the he.net app. You can see for nameserver entry it lists
                  (defaults: , ,10.0.0.9)
                  correct it looks like (default: 10.0.0.9, 10.0.0.10,)

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    Are other dhcp clients getting it correctly? Sniff the dhcp offer, does it list them both correctly..

                    I run ios on my phone, my wifes phone and tablet... Never seen any issues.. I do the same thing hand dhcp clients my pihole IP..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • T
                      thorer01
                      last edited by

                      yes the dhcp offer and the router advertisement show the correct dns servers.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        well than - look to your clients...

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • T
                          thorer01
                          last edited by

                          yeah i am, i was just hoping someone had seen this before. The people in this forum are a lot smarter than most.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Nope never seen such a thing... Been using iphone and ipad with pfsense for like ever..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Mmm, that does seem odd. Do the affected clients always show that? It could just be a display issue with the app.

                              I've not seen anything like that either.

                              Steve

                              T 1 Reply Last reply Reply Quote 0
                              • T
                                thorer01 @stephenw10
                                last edited by

                                @stephenw10 I also thought it could just be a display issue. But performance was bad when i set dns to automatic, and when i set it to manual, the performance was good and the display was correct.

                                Its seems like ios is getting/parsing and blank entry for dns, that eventually times out and it moves on to the next server in the list which is successful.

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by johnpoz

                                  What version of ios are you running?

                                  What happens if you set your dhcp server to just 1 IP?

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    thorer01
                                    last edited by

                                    12.2

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      And you have multiple devices doing this?

                                      What does it look like under automatic? Do you have blank lines... Not the HE display, the normal wifi little i button when your connected.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        thorer01
                                        last edited by

                                        Thats the 4th screen shot i posted, under automatic it look completely normal

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          What if you just turn off IPv6... You sure HE not just able to show the really long IPv6 addresses..

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            thorer01
                                            last edited by

                                            sure i can try.

                                            But that wouldnt explain why it takes me less than a second eyeballing to to get a dns entry when it is set to manual in ios. and i just counted 8 seconds when it was set to automatic. Same domain each time that would be cached by the upstream.

                                            Either way this is clearly not a pfsense issue but an iOS.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.