Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Windows Server DNS & pfSense DNS Issue

    Scheduled Pinned Locked Moved DHCP and DNS
    dnsdns resolverwindows serversubnet
    9 Posts 2 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by A Former User

      Howdy,

      I just finished setting up different subnets in my network from some help of great folks here at the community. But now i'm having some weird unintended issues today which I believe is DNS related, such as:

      NOTE: all of these issues are occuring on the LAN_Workstations 10.1.11.0/24 subnet

      • I am randomly able to access my VCenter web GUI on 10.1.11.0/24. Sometimes it works then sometimes it will stop working. Update: It seems every time I restart my PC, I can't connect to my vcenter gui with web browser error: This site can’t be reached. Server IP address could not be found.
        Try running Windows Network Diagnostics.
        DNS_PROBE_FINISHED_NXDOMAIN

      But then after a while it lets me access the web gui again without me doing anything.

      • I was randomly able to connect to my domain controllers (on same subnet) but randomly get kicked off. Then I wouldn't be able to remote back into them. But if I remoted back to them with an IP address it would work. Then after a while, I could remote back in with the server name. Sometimes when I reboot my workstation, it has a delayed connection to my Domain controller/File server.

      • Cannot access ESXI host ever on 10.1.11.0/24

      • Unable to access switch on 10.1.13.0/24 subnet (I can now access this switch from another subnet, it took like an hour for me to gain access though)

      • Initial wifi logon/connection is delayed (it was instant before)

      I drew my network setup out with all the details to help simplify things, I hope it is clear but if not please ask my anything!

      3c5bf9d5-05aa-4cb9-af80-305b913bb9a7-image.png

      Here are my firewall rules, but I don't think this is causing my issue:

      9be4b2cd-d6b6-4ae5-b2cf-e56e2806de3f-image.png

      58183a1d-94e4-40a6-b02f-a6982589afb2-image.png

      903aa4be-7b55-4261-823b-c8c45bd740b8-image.png

      8f857722-e48a-4850-9bd1-8d8b25288cbe-image.png

      a33a7a79-852d-445d-a7f7-915b9af486e2-image.png

      5e93dcf1-ce5b-4203-a02c-76333c05351a-image.png

      I'm kind of getting confused as what to use as DNS servers, because of having my pfsense as a DNS resolver while also having my internal windows server DNS servers.

      Does my DNS settings look okay, or am I messing it up?

      Thank you kindly for any help.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        If it were me I would point everything - even pfSense - at the two windows domain controllers for DNS and not even run the DNS resolver on the firewall.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by A Former User

          @Derelict

          Hey Derelict,

          I can give it a shot, I have a feeling it's not going to play nice with me though :D

          Do you know if doing this method lessens my security in any way? I have a package called pfBlockerNG, do you know if this method would bypass this security package or any other security in pfSense?

          Thank you!

          1 Reply Last reply Reply Quote 0
          • ?
            A Former User @Derelict
            last edited by A Former User

            @Derelict nvm! I think i found answer in another post. It does not, I just need to make the AD DNS forwarder to point to my pfsense box 10.1.10.1. But then for my pfsense, do I make the dns server an external dns instead of my AD DNS servers? like 1.1.1.1?

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              IDK why you would invest in the Microsoft solution and not just use it.

              Point everything at the DCs for DNS and forget about it.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              ? 2 Replies Last reply Reply Quote 0
              • ?
                A Former User @Derelict
                last edited by

                @Derelict Okay, I will try doing that :(

                1 Reply Last reply Reply Quote 0
                • ?
                  A Former User @Derelict
                  last edited by

                  @Derelict
                  Morning,

                  I tried disabling the DNS resolver in pfSense and only added my two DCs as DNS servers under System -> General Setup but then my internet stops working. Do you know if there is anything else that I may need to configure to make internet work?

                  Thank you!

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Yeah. All of your devices need to have the DCs set as their DNS servers (probably set using the DHCP server which should probably also be the DCs) and rules need to be in place to pass TCP/UDP port 53 to them.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    ? 1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @Derelict
                      last edited by

                      @Derelict Okie, i'll give it a try!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.