Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Firewall/Aliases add host by FQDN not work

    Firewalling
    2
    5
    305
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jason04131015 last edited by jason04131015

      Hello,

      I added an alias named "Test" and the type is Host(s).
      Then I add a Rule to let the alias pass.
      1dee3d92-b561-4ebd-a1d7-6a378d6db8e1-image.png

      5ffd6fdc-2390-48bb-8a24-1e5000fc8d55-image.png

      But it worked if alias enter IP, but not work if alias enter FQDN.

      Please help me, thanks.😊

      daa4d3ef-ffe1-4560-bde0-b187509ffc03-image.png

      1 Reply Last reply Reply Quote 0
      • Gertjan
        Gertjan last edited by Gertjan

        189d3c10-2b6e-4d0f-a200-b2c050432223-image.png

        That one, and FB, and twitter, CNN, Snapchats, Youtube, etc etc etc, all those that have thousands of IP's 'behind' an URL, you can not use them.
        Their IP can - and do - change every hour, minute, or even a second.

        edit : That said :

        I set up this :
        301cceef-5f02-4104-8b70-b0c9bf3dab30-image.png

        and then I tested my "test1_IP" :

        eba021ed-8715-46ca-a816-505502650fb5-image.png

        works just fine.
        Knowing that the IPv4 and IPv6 is just one of ... many.

        So .... your DNS is 'broken' ? :

        1e3b8c4f-0b06-4538-a4ad-90c39e3cdba3-image.png

        No "help me" PM's please. Use the forum.

        1 Reply Last reply Reply Quote 1
        • J
          jason04131015 last edited by jason04131015

          Hi,@Gertjan
          Thanks for your reply.

          I tried to set like this:
          03bc6cfd-1732-4feb-8c03-b7d7896738ea-image.png
          Type URL "google.com" not work.

          Then set up IP "172.217.160.100" from firewall log entries.
          89117971-fabd-42c2-932c-65699e646406-image.png
          It worked when I type "google.com"

          Then I set back like step 1. It's still work when I type "google.com".
          697a7eb5-c624-4106-b244-10f571d53213-image.png

          Is this DNS broken?
          My DNS is 10.24.10.1 (local DNS).

          Thank you.☺

          Gertjan 1 Reply Last reply Reply Quote 0
          • Gertjan
            Gertjan @jason04131015 last edited by

            @jason04131015 said in Firewall/Aliases add host by FQDN not work:

            Type URL "google.com" not work.

            Typing where ? Your PC ?
            At that moment, your PC had probably cached another IP for Google.com - not the same one pfSense was using.
            As said, google.com has thousands of IP's, not just one.

            No "help me" PM's please. Use the forum.

            1 Reply Last reply Reply Quote 0
            • J
              jason04131015 last edited by jason04131015

              @Gertjan said in Firewall/Aliases add host by FQDN not work:

              Typing where ? Your PC ?
              At that moment, your PC had probably cached another IP for Google.com - not the same one pfSense was using.
              As said, google.com has thousands of IP's, not just one.

              Hi @Gertjan
              Thanks for your reply.

              Yes.Typing URL on my PC.(IP:10.24.10.2)

              I can ping "google.com".But I cannot display the webpage by entering the URL on the browser.
              How can I check if my dns is broken or not?
              81593775-b13f-48e8-bdba-44f6d9f4943f-image.png

              Thank you.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post