Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG with Windows Server DHCP and DNS

    DHCP and DNS
    2
    6
    537
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SAMitguy
      last edited by

      Hello, I am trying to use pfBlockerNG as a content filter for my domain. I have a dedicated local server running as DHCP and DNS. The pfsense is not running a DHCP server and the DNS resolver is on. On the windows side, the DNS server is forwarding to the local address (lets call it 10.0.1.2) as well as the ISP DNS servers. Even after setting up pfBlockerNG with different tutorials, it does not work. I suspect it is because it tries to use pfSense as a DNS server while it is windows that is running the DNS server. Any help would be much appreciated.

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @SAMitguy
        last edited by

        @samitguy Windows can forward to any DNS. Don't also forward to the ISP though, since that would bypass pfSense. Also there is a checkbox somewhere in the Windows DNS settings to use root servers if it doesn't get a response from the forwarded server.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        S 1 Reply Last reply Reply Quote 0
        • S
          SAMitguy @SteveITS
          last edited by

          @steveits ok thank you. Is there a way to tell pfSense to use the windows DNS and DHCP servers so that pfBlockerNG works?

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @SAMitguy
            last edited by

            @samitguy Not sure I understand. What DNS are the PCs on the network using?

            pfSense can be configured to forward queries to a specific DNS server. Either via "Domain Overrides" (useful for a Windows domain network) or via the "DNS Query Forwarding" checkbox which forwards all queries. PCs using pfSense for DNS would have queries forwarded on as configured. However none of this is relevant to "so that pfBlockerNG works"....

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            S 1 Reply Last reply Reply Quote 0
            • S
              SAMitguy @SteveITS
              last edited by

              @steveits The PCs are using the Windows DNS server.

              What I would like to happen is for pfBlockerNG to act as a content filter with the Windows DNS server handling DNS and Windows DHCP server handling DHCP. pfSense should only act as a router and a host for pfBlockerNG.

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @SAMitguy
                last edited by

                @samitguy On your Windows DNS server(s) forward all queries to your pfSense.

                You may need to empty the DNS cache on the server(s) and any devices. ipconfig /flushdns on the PCs, or dnscmd /clearcache for the DNS Server cache.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.