Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    A simple question... maybe: about resolving to a VIP of pfSense itself

    DHCP and DNS
    3
    8
    385
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • andrewKA
      andrewK
      last edited by

      I'm new to setting up DNS in my local network.

      I'm using BIND (although this seems not to be a BIND issue) to resolve other network appliances on my private net.

      I configured records for resolving the 2 pfSense IP's I have in an HA cluster. I also have a name resolving to the VIP for the HA cluster.

      When using the name for each node in the URL I can get to the login page of each, like expected. However when I use the name I have for the VIP I get a message regarding "Potential DNS Rebind attack detected".

      Does anyone have insight as to why is happening?

      Capture.PNG

      Thanks all,
      A

      chpalmerC 1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer @andrewK
        last edited by chpalmer

        @andrewK

        Go to System/Admin Access under Webconfigurator..

        Go down to the "DNS Rebind Check" and check the box.

        You would have to use the name of your pfsense box that is set on "General Settings" as your DNS name to keep this from happening.

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          You shouldn't disable that option if you can avoid it. You should set your domain as being private: https://docs.netgate.com/pfsense/en/latest/dns/dns-rebinding-protections.html

          Also, you should never manage an HA pair by accessing the CARP VIP address. It's OK for clients to access services like DNS and so on from it, but don't use the GUI by the CARP VIP -- you can't be sure which one you're connecting to.

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • andrewKA
            andrewK
            last edited by

            Ah, OK. Thank you both.

            jimp, what if I have the secondary node's login page color and GUI theme are set differently from the primary node. Are there any other potential problems with using the CARP VIP for administration?

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              It doesn't matter... If the VIP status changed while you were in the GUI you'd end up on the "wrong" box. Don't do it. Just access the individual hostnames.

              Also make sure the other hostname(s) are listed on System > Advanced under "Alternate Hostnames"

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • andrewKA
                andrewK
                last edited by

                I will definitely heed your "best practice" advice, thanks.

                The link you provided spoke of steps using Unbound. I'm using BIND. I don't see any rebind handles in the BIND settings. Any thoughs?

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  I don't think that feature is supported in BIND so it's probably not relevant. Just make the GUI change I mentioned above (to add the alternate hostname(s)) and you should be OK

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • andrewKA
                    andrewK
                    last edited by

                    OK. Great. that works.

                    Thanks again.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.