Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG and DNS

    Scheduled Pinned Locked Moved pfBlockerNG
    3 Posts 2 Posters 725 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      ThomasDr
      last edited by

      hello,

      I have pfBlockerNG installed and only once the configuration has taken over by wizard. So far I have used the DNS forwarder but have read that I need a DNS resolver for DNSBL. How must the DNS configuration look, I can use both forwarder and resolver or only resolver. I get from my provider a dynamic IP with DNS data and still have the 8.8.8.8 as an alternative DNS resolver. What's the best way?

      regards
      ThomasD

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @ThomasDr
        last edited by

        @ThomasDr said in pfBlockerNG and DNS:

        So far I have used the DNS forwarder but have read that I need a DNS resolver for DNSBL.

        0504584d-e95c-4110-99e0-9cce35990b5c-image.png

        @ThomasDr said in pfBlockerNG and DNS:

        How must the DNS configuration look,

        The default settings are perfect.

        @ThomasDr said in pfBlockerNG and DNS:

        I can use both forwarder and resolver or only resolver.

        Not possible.
        It the Resolver ... or the Forwarder.

        @ThomasDr said in pfBlockerNG and DNS:

        I get from my provider a dynamic IP with DNS data and still have the 8.8.8.8 as an alternative DNS resolver.

        We (nearly) all do.
        The Resolver doesn't use (and need) them.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • T
          ThomasDr
          last edited by

          Hello,

          ok, I disable the DNS forwarder and activate the DNS Resolver.
          For use the Unbound DNS Resolver I add a NAT redirect rule from here:
          Netgate Docs redirecting-all-dns-requests-to-pfsense

          My question, the NAT redirect rule create a LAN rule too, this rule is automatic below the pfblockerNG IP rules, must I move it above, after the Anti-Lockout Rule?

          Do I need the Blocking DNS Queries to External Resolvers rule too?

          regards
          ThomasD

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.