Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    How to resolve DNS in LAN

    Off-Topic & Non-Support Discussion
    3
    7
    131
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gusto last edited by

      I use apache web server in LAN. On changeip.com I use the free dns service, where I have a registered domain name.
      If I connect to a web server under a domain name from wan, everything works great. If I connect from the LAN, I see a warning

      Potential DNS Rebind attack detected, see http://en.wikipedia.org/wiki/DNS_rebinding
      Try accessing the router by IP address instead of by hostname.
      

      or

      404 Not Found
      nginx
      

      Nastavil som v services - dns resolver - Host Overrides

      I disabled it in System / Advanced / AdminAccess "DNS Rebind Check" then it redirects to the default gateway.
      How do I set DNS to work on my LAN?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann last edited by

        If you’re using the DNS resolver for name resolution add a host override for your public domain pointing to the internal servers IP.

        1 Reply Last reply Reply Quote 0
        • G
          gusto last edited by

          I set up in services - dns resolver - Host Overrides

          1 Reply Last reply Reply Quote 0
          • stephenw10
            stephenw10 Netgate Administrator last edited by

            The client you're testing from is not hitting the override if you're seeing the pfSense webgui. Is ut even using pfSense for DNS at all?

            https://docs.netgate.com/pfsense/en/latest/recipes/port-forwards-from-local-networks.html

            Steve

            1 Reply Last reply Reply Quote 0
            • G
              gusto last edited by

              It was necessary to set
              System / Advanced / Firewall & NAT / NAT Reflection mode for port forwards on Pure NAT
              since then everything works

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @gusto last edited by

                @gusto
                So what @stephenw10 wrote above will be the case. Your client doesn't use pfSense for DNS resolution.
                Maybe its using DoH.

                1 Reply Last reply Reply Quote 0
                • stephenw10
                  stephenw10 Netgate Administrator last edited by

                  Yup, could well be DoH. Are you using Firefox?

                  Split DNS is generally better if you can do it as it doesn't load the firewall unnecessarily.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post