• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS Resolver not working for Link-Local addresses

Scheduled Pinned Locked Moved IPv6
9 Posts 3 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    son1c
    last edited by son1c May 28, 2022, 9:31 AM May 28, 2022, 9:16 AM

    Hi,

    I use Pfsense 22.01 Home Edition and the DNS Resolver over the link-local address which doesn't work.
    The IPv4 addresses and the global-unicast address work fine.

    The Network Interfaces setting in the DNS Resolver tab is set to all and there are no firewall rules set who will block the requests.

    Cu
    son1c

    J J 2 Replies Last reply May 28, 2022, 8:06 PM Reply Quote 0
    • J
      JKnott @son1c
      last edited by May 28, 2022, 8:06 PM

      @son1c

      Given you don't normally use link local addresses for carrying app data etc. why do you want them in DNS?

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator @son1c
        last edited by johnpoz May 28, 2022, 8:33 PM May 28, 2022, 8:29 PM

        @son1c said in DNS Resolver not working for Link-Local addresses:

        there are no firewall rules set who will block the requests.

        Did you change source from say lan net to any? By default the IPv6 lan net any rule for internet would not allow link-local..

        Also I do not believe the automatic access list for unbound would include link-local..

        I also not sure why anyone would want to do this - but it does work.. So I enabled a IPv6 any rule for source vs just lan net.

        So I can ping pfsense link-local address.

        ping.jpg

        But you can see got back refused for dns query.

        rfused.jpg

        I then edited the access list to allow for link local address..

        accesslist1.jpg

        And now I can query the linklocal address

        dnsquery.jpg

        But just at a loss to actual use case for this to be honest.. But it works if you allow for it.

        But default lan net IPv6 would not include linklocal network, nor would the default access lists in unbound.. I have always used my own access lists, but if lan net doesn't include the link local space, I doubt the auto access lists would..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 1
        • S
          son1c
          last edited by May 29, 2022, 12:04 PM

          Thank you for your help!

          I use a DNS Filter, so my goal was to forward the DNS querys to the pfsense.
          This should be no problem but my internet connection is over DSL, so every time the modem reconnects I get new ipv6 prefixes from my provider. That's why I need a static IP address to forward.

          J J 2 Replies Last reply May 29, 2022, 12:20 PM Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @son1c
            last edited by May 29, 2022, 12:20 PM

            @son1c why would you not just forward to your IPv4 address - does that change as well?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            S 1 Reply Last reply May 29, 2022, 2:42 PM Reply Quote 0
            • J
              JKnott @son1c
              last edited by May 29, 2022, 12:49 PM

              @son1c said in DNS Resolver not working for Link-Local addresses:

              This should be no problem but my internet connection is over DSL, so every time the modem reconnects I get new ipv6 prefixes from my provider. That's why I need a static IP address to forward.

              You can use Unique Local Addresses. I use them here, even though my prefix doesn't change.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              S 1 Reply Last reply May 29, 2022, 2:46 PM Reply Quote 1
              • S
                son1c @johnpoz
                last edited by May 29, 2022, 2:42 PM

                @johnpoz no, i just want try a ipv6 only setup

                J 1 Reply Last reply May 29, 2022, 2:45 PM Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @son1c
                  last edited by May 29, 2022, 2:45 PM

                  @son1c said in DNS Resolver not working for Link-Local addresses:

                  no, i just want try a ipv6 only setup

                  Well good luck with that - you understand your not going to be able to get to MOST of the internet ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 1
                  • S
                    son1c @JKnott
                    last edited by May 29, 2022, 2:46 PM

                    @jknott I see, i need to take a closer look to the virtual IP settings

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received