• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfSense resolver stops working

DHCP and DNS
7
66
15.4k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    maverickws
    last edited by Jul 29, 2022, 1:31 PM

    I figure doing the IPv6 lookup makes sense on the local network considering local IPv6 is enabled.
    let's say web-server1 and db-server1 are using the ipv6 link locally. they still need to ask the resolver who that host is, and it will return the A and AAAA records. Since IPv6 takes precedence, it makes sense locally.

    Now what really is the issue here is that unbound is unable to differ from local link connectivity and wide-network connectivity, so I'm assuming it tries to query the root servers with IPv6, where no IPv6 connection to that destination is available.

    In the end I bet if looked closely those issues will all be related to this (as local ipv6 connectivity is enabled by default iirc) where users don't have IPv6 wan.

    What would be interesting to understand as well is why has this behaviour changed from previous versions of unbound to the current state. Clearly some sort of logic was present before preventing this from happening, where now is gone.

    J 1 Reply Last reply Jul 29, 2022, 2:23 PM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @maverickws
      last edited by Jul 29, 2022, 2:23 PM

      @maverickws yeah I guess

      But come on, these streaming boxes don't normally do anything locally. If you do not have a GUA Ipv6 address, why waste cycles asking for AAAA

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      M 1 Reply Last reply Jul 29, 2022, 2:35 PM Reply Quote 0
      • M
        maverickws @johnpoz
        last edited by Jul 29, 2022, 2:35 PM

        @johnpoz but in my case they aren't streaming boxes. They're application servers, database servers and alike. the webserver/dbserver was an accurate example of local connections here. We never connect to the web server using IPv6, but the web server does connect to services internally using ipv6. or used to, I guess.

        J 1 Reply Last reply Jul 29, 2022, 3:00 PM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @maverickws
          last edited by johnpoz Jul 29, 2022, 3:02 PM Jul 29, 2022, 3:00 PM

          @maverickws sorry I might of gotten a bit off topic, I was just bitching about IPv6 dns clients in general...

          To me if you don't have a GUA, or at least ULA - there is zero point to asking for AAAA, sure ok maybe you have link local, but link local addresses don't belong in DNS..

          https://www.ietf.org/rfc/rfc4472.txt
          Operational Considerations and Issues with IPv6 DNS

          Section 2.1

          Link-local addresses should never be published in DNS (whether in
          forward or reverse tree), because they have only local (to the
          connected link) significance [WIP-DC2005].

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 1
          • L
            lohphat @maverickws
            last edited by lohphat Jul 30, 2022, 6:50 AM Jul 29, 2022, 5:04 PM

            @maverickws said in pfSense resolver stops working:

            I don't think it's memory related (could be wrong ofc) but I've never seen the pfSense be nowhere near it's limits either of memory or CPU.

            It's related to memory allocation unbound uses internally for its local data, not the entire memory on the appliance running out.

            See earlier post regarding unbound release 1.16.0 github notes

            SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_1)

            1 Reply Last reply Reply Quote 0
            • M
              maverickws
              last edited by Aug 9, 2022, 7:24 PM

              Hi guys I have an update on this, will update if it goes the other way:

              I was doing some changes on my home pfsense (where I have pfblockerng etc) and all of the sudden dns went a-wire.
              Ended up having to add the do-ip6: no option but that really wasn't making sense as I had updated in ages and haven't had issues so far. PLUS I have IPv6 here working well.

              So in the end I remembered I had enabled the Experimental Bit 0x20 Support option.
              Disabled it, haven't had issues since. A couple of hours.
              So I'm wondering how's your setups and what conflict could it be.

              J 1 Reply Last reply Aug 9, 2022, 7:27 PM Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator @maverickws
                last edited by Aug 9, 2022, 7:27 PM

                @maverickws Have had that enabled for YEARS.. zero issues with it.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                M 1 Reply Last reply Aug 9, 2022, 8:12 PM Reply Quote 0
                • M
                  maverickws @johnpoz
                  last edited by Aug 9, 2022, 8:12 PM

                  @johnpoz

                  i know i have it enabled at the pfsense on service and honestly thought it was so as well with the home pfsense. crossed my eyes on it, saw it was disabled, never gave it a thought, enabled. so far all ok since i disabled it again, let's see

                  E 1 Reply Last reply Oct 27, 2023, 12:34 AM Reply Quote 0
                  • E
                    Erutan409 @maverickws
                    last edited by Oct 27, 2023, 12:34 AM

                    @maverickws Did that end up fixing your issue?

                    M 2 Replies Last reply Nov 7, 2023, 1:38 PM Reply Quote 0
                    • M
                      maverickws @Erutan409
                      last edited by Nov 7, 2023, 1:38 PM

                      @Erutan409
                      Hi there,

                      From what I remember it solved my issue then, but I'm having another issue now I'll be making another topic for it.

                      1 Reply Last reply Reply Quote 0
                      • M
                        maverickws @Erutan409
                        last edited by Nov 8, 2023, 10:42 AM

                        @Erutan409 See if this means anything to you please

                        https://forum.netgate.com/topic/183918/unbound-resolver-failed-to-resolve-host

                        E 1 Reply Last reply Nov 8, 2023, 11:23 AM Reply Quote 0
                        • E
                          Erutan409 @maverickws
                          last edited by Nov 8, 2023, 11:23 AM

                          @maverickws Yeah, it also seems to be happening more frequently with me, too, all of a sudden.

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.