• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall/Aliases add host by FQDN not work

Scheduled Pinned Locked Moved Firewalling
5 Posts 2 Posters 694 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jason04131015
    last edited by jason04131015 Jul 7, 2020, 8:55 AM Jul 7, 2020, 8:52 AM

    Hello,

    I added an alias named "Test" and the type is Host(s).
    Then I add a Rule to let the alias pass.
    1dee3d92-b561-4ebd-a1d7-6a378d6db8e1-image.png

    5ffd6fdc-2390-48bb-8a24-1e5000fc8d55-image.png

    But it worked if alias enter IP, but not work if alias enter FQDN.

    Please help me, thanks.😊

    daa4d3ef-ffe1-4560-bde0-b187509ffc03-image.png

    1 Reply Last reply Reply Quote 0
    • G
      Gertjan
      last edited by Gertjan Jul 7, 2020, 9:30 AM Jul 7, 2020, 8:59 AM

      189d3c10-2b6e-4d0f-a200-b2c050432223-image.png

      That one, and FB, and twitter, CNN, Snapchats, Youtube, etc etc etc, all those that have thousands of IP's 'behind' an URL, you can not use them.
      Their IP can - and do - change every hour, minute, or even a second.

      edit : That said :

      I set up this :
      301cceef-5f02-4104-8b70-b0c9bf3dab30-image.png

      and then I tested my "test1_IP" :

      eba021ed-8715-46ca-a816-505502650fb5-image.png

      works just fine.
      Knowing that the IPv4 and IPv6 is just one of ... many.

      So .... your DNS is 'broken' ? :

      1e3b8c4f-0b06-4538-a4ad-90c39e3cdba3-image.png

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 1
      • J
        jason04131015
        last edited by jason04131015 Jul 8, 2020, 7:30 AM Jul 8, 2020, 7:29 AM

        Hi,@Gertjan
        Thanks for your reply.

        I tried to set like this:
        03bc6cfd-1732-4feb-8c03-b7d7896738ea-image.png
        Type URL "google.com" not work.

        Then set up IP "172.217.160.100" from firewall log entries.
        89117971-fabd-42c2-932c-65699e646406-image.png
        It worked when I type "google.com"

        Then I set back like step 1. It's still work when I type "google.com".
        697a7eb5-c624-4106-b244-10f571d53213-image.png

        Is this DNS broken?
        My DNS is 10.24.10.1 (local DNS).

        Thank you.☺

        G 1 Reply Last reply Jul 8, 2020, 7:50 AM Reply Quote 0
        • G
          Gertjan @jason04131015
          last edited by Jul 8, 2020, 7:50 AM

          @jason04131015 said in Firewall/Aliases add host by FQDN not work:

          Type URL "google.com" not work.

          Typing where ? Your PC ?
          At that moment, your PC had probably cached another IP for Google.com - not the same one pfSense was using.
          As said, google.com has thousands of IP's, not just one.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • J
            jason04131015
            last edited by jason04131015 Jul 8, 2020, 9:13 AM Jul 8, 2020, 8:37 AM

            @Gertjan said in Firewall/Aliases add host by FQDN not work:

            Typing where ? Your PC ?
            At that moment, your PC had probably cached another IP for Google.com - not the same one pfSense was using.
            As said, google.com has thousands of IP's, not just one.

            Hi @Gertjan
            Thanks for your reply.

            Yes.Typing URL on my PC.(IP:10.24.10.2)

            I can ping "google.com".But I cannot display the webpage by entering the URL on the browser.
            How can I check if my dns is broken or not?
            81593775-b13f-48e8-bdba-44f6d9f4943f-image.png

            Thank you.

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received