Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Fine tuning PfSense for network with AD

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 4 Posters 484 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Operations
      last edited by

      I am wondering what extra setup / changes to PfSense i need to do to make it work with my AD 100%.

      For example under DNS Resolver/General Settings/Custom Options

      Should i add this line?

      server:
      private-domain: "ad.mydomain.com"

      I have already entered a few Domain Overrides like:

      Ad.mydomain.com => DNS01 IP
      200.168.192.in-addr.arpa => DNS01 IP

      And this question i am finding conflicting answers. Should my AD DNS forwarder point to my PfSense IP or should PfSense DNS point towards AD DNS IP?

      H 1 Reply Last reply Reply Quote 0
      • H
        heper @Operations
        last edited by

        @operations you can tinker with trying to forward dns request from pfsense -> ADdns.

        i find it easier to just fill in my AD-dns in the dhcp-server settings. this way my clients use AD-dns directly

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          You almost always want clients to use AD directly for DNS. Doing anything else will create problems. If you want to do DNS filtering in pfSense you can point AD to that as it's server.

          Steve

          O 1 Reply Last reply Reply Quote 0
          • O
            Operations @stephenw10
            last edited by

            @stephenw10 yes i have my AD DNS as a forwarder pointed at PfSense atm. Just wanted to check this part.

            S 1 Reply Last reply Reply Quote 1
            • S
              SteveITS Galactic Empire @Operations
              last edited by

              @operations said in Fine tuning PfSense for network with AD:

              @stephenw10 yes i have my AD DNS as a forwarder pointed at PfSense atm. Just wanted to check this part.

              Then setting the override will allow pfSense to resolve names in AD DNS (e.g. local SMTP).

              Private is not necessary.

              You can also override the reverse DNS if you have AD DNS set to use/hold the reverse zone. Then it can look up LAN IPs.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.