Viewing redirected DNS destinations
-
I've successfully set up a NAT+firewall rule on my pfsense box which traps "rouge" DNS requests from hosts on my network and pushes these requests to my DNS server.
Looking at the firewall logs, I am surprised by how many of the hosts on my network are making such requests. While I can see which hosts are making the requests, I can't see the details of the actual request that they are making. Is it possible to see that somewhere? I'd like to see which external DNS server is being queried by each "rogue" host on my network.