Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS over Port 853 and 53

    Scheduled Pinned Locked Moved DHCP and DNS
    5 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • manjotscM
      manjotsc
      last edited by

      I setup dns over TLS/SSL on pfsense, but I have a windows dns server running on port 53, I would like to keep dns over tls and normal dns on port 53, I want to setup pfsense to listen on local DNS also.

      Screenshot_2020-06-22 pfSense manjot net - Services DNS Resolver General Settings.png

      Vendor: HP
      Version: P01 Ver. 02.50
      Release Date: Wed Jul 17 2024
      Boot Method: UEFI
      24.11-RELEASE (amd64)
      FreeBSD 15.0-CURRENT
      CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
      Current: 3606 MHz, Max: 3400 MHz
      4 CPUs : 1 package(s) x 4 core(s)

      1 Reply Last reply Reply Quote 0
      • R
        riften
        last edited by

        Hello manjotsc. The way I have set it up is, through Windows server dhcp (server 2016 in my case) I pass my two domain controller IPs as the clients DNS. My clients and servers cannot connect to the internet on port 53, the port is not open from LAN or the server vlan. The domain controllers DNS forwards to the default gateway (PFSense), which then takes over using the DNS servers I set in SYSTEM/GENERAL SETUP. The response comes back to my domain controllers which pass the resolved addresses to all the clients. DOT is configured in PFSense and as everything runs through that, my internet DNS is encrypted.

        manjotscM 1 Reply Last reply Reply Quote 1
        • manjotscM
          manjotsc @riften
          last edited by

          @riften I am not that good with these, is it possible if you can show screenshot of something. I am bit confused.

          Thanks,
          Really appreciated.

          Vendor: HP
          Version: P01 Ver. 02.50
          Release Date: Wed Jul 17 2024
          Boot Method: UEFI
          24.11-RELEASE (amd64)
          FreeBSD 15.0-CURRENT
          CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
          Current: 3606 MHz, Max: 3400 MHz
          4 CPUs : 1 package(s) x 4 core(s)

          R 1 Reply Last reply Reply Quote 0
          • R
            riften @manjotsc
            last edited by

            @manjotsc- If you are using Windows server DNS, are you also using Windows server DHCP? If using PFSense DHCP, you need to make sure that on the SERVICES/DHCP SERVER/LAN page, that you have filled out the IP(s) of your DNS server(s), under SERVERS. Also the Default Gateway. If you have a domain internally and not just a DNS stand-alone server, fill out the DOMAIN NAME and DOMAIN SEARCH LIST with the domain name, under OTHER OPTIONS. I don't use PFSense DHCP, I use Server 2016 DHCP and DNS.
            If you are using Windows Server DHCP, you would need to use either SERVER OPTIONS or SCOPE OPTIONS to make DHCP hand out your DNS server IP as the DNS all the clients use. You can use SERVER OPTIONS for any option that applies to all scopes, and SCOPE OPTIONS for any setting that is scope specific only. Right-click on a blank area on the right side under SCOPE OPTIONS and set the needed options (DNS SERVER and ROUTER at least). Sorry I don't have a way to upload images.
            Either way, once you have DHCP handing out your internal DNS server and default gateway (router) options to all the clients, you then have to set your DNS server to forward all DNS requests it can't resolve directly, to the PFSense router. In the DNS console, right click on the server name, and choose PROPERTIES. Click FORWARDERS. Here you specify the LAN side ip address of the PFSense router. That's it.

            manjotscM 1 Reply Last reply Reply Quote 1
            • manjotscM
              manjotsc @riften
              last edited by

              @riften Thanks

              Vendor: HP
              Version: P01 Ver. 02.50
              Release Date: Wed Jul 17 2024
              Boot Method: UEFI
              24.11-RELEASE (amd64)
              FreeBSD 15.0-CURRENT
              CPU Type: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
              Current: 3606 MHz, Max: 3400 MHz
              4 CPUs : 1 package(s) x 4 core(s)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.