Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Firewall Rules not working?

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 461 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O Offline
      OldSkool
      last edited by

      Hi all, new to pfSense and setting it up for the first time for my home network. Really love it so far and have it connected to my existing gateway router while I complete the set up.

      The problem: I have an end point connected to pfSense. I've created two recommended firewall rules (rows 3 & 4) to block DNS requests to outside servers (see image).

      DNSFirewallRules.JPG

      But when the rules are activated it blocks all DNS requests. I have flipped the two rules and tried both ways - Block rule above and Block rule below, same result. When I turn the Block/Reject rule off it works, when I turn it on all DNS requests are blocked.

      DNS02.JPG

      DNS seems to routing correctly:

      DNS01.JPG

      I'm probably missing something very simple here so please be gentle :-) I've been staring at it for too long I think.
      Any advice would be greatly appreciated. Thanks.

      Here is an additional screen of my Resolver setup:

      DNSResolver.JPG

      N 1 Reply Last reply Reply Quote 0
      • N Offline
        netblues @OldSkool
        last edited by

        @OldSkool dns is primarily udp, so you have to also allow it

        O 1 Reply Last reply Reply Quote 1
        • O Offline
          OldSkool @netblues
          last edited by

          @netblues Thanks. Like I said looking at it too long and didn’t even see that I had missed UDP on the allow rule. Staring me in the face. Thanks again.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.