Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IoT devices spamming log with outbound queries...

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 491 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      furom
      last edited by furom

      Hi,

      I have a IoT net which I'd like should use pfSense for DNS. My current DNS rule does cause devices to spam the log with outbound query attempts. Why does that happen when I have only allowed DNS to a local IoT address? Please help me see what I do wrong. Thanks

      IoT rule:
      Allow
      Prot: IPv4 TCP/UDP
      Source: IoT Net
      Destination: IoT address
      Port: 53 (DNS)

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @furom
        last edited by

        @furom
        Some IoT devices have hard-coded DNS settings an ignore the DHCP DNS.

        But you can simply drag them to your DNS by a NAT port forwarding rule.
        I did this with DNS and NTP on my pfSense:
        0462d43f-a14e-470b-8909-6b11cab83504-grafik.png

        "Internal" is an interface group including my internal interface here.
        These rules redirect any DNS and NTP traffic to the pfSense LAN IP.
        I have set an associated firewall rule in the NAT setting, but you may also simply select "pass".

        pfSense is responding using the origin destination IP the devices sent the requests to. So the devices don't know any of the redirection and are very relaxed. 😊

        F 1 Reply Last reply Reply Quote 1
        • F
          furom @viragomann
          last edited by

          @viragomann Brilliant, I will try this, thanks :)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.