• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Using avahi to resolve hosts

Scheduled Pinned Locked Moved pfSense Packages
8 Posts 3 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    clauder
    last edited by Mar 30, 2023, 10:56 PM

    It appears that using avahi on pfsense does not support the ability to resolve local hosts. Using the command line gets this error wiht avahi-browse or avahi-resolve.

    Failed to create client object: Daemon not running

    For security reasons, it is highly desirable to disable IPv4 and IPv6 global addressing on untrustworthy IoT device and use some form of proxing to access them using the IPv6 link scope addresses. But this requires avahi to resolve these IP addresse.

    J 1 Reply Last reply Mar 30, 2023, 10:59 PM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @clauder
      last edited by Mar 30, 2023, 10:59 PM

      @clauder said in Using avahi to resolve hosts:

      But this requires avahi to resolve these IP addresse.

      huh? I resolve all my local devices by name, they do not have global IPv4 address they are all on rfc1918 and sure not using avahi, so not sure exactly what your asking?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      C 1 Reply Last reply Mar 30, 2023, 11:04 PM Reply Quote 0
      • C
        clauder @johnpoz
        last edited by clauder Mar 30, 2023, 11:05 PM Mar 30, 2023, 11:04 PM

        @johnpoz Actually, those private addresses still allow a device to reach the internet via a NAT service and leak anything a malicious actor wants. Using IPv6 link scope actually curtails that. It is one notch higher in term of security.

        J 1 Reply Last reply Mar 30, 2023, 11:07 PM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @clauder
          last edited by Mar 30, 2023, 11:07 PM

          @clauder A simple firewall rule, you know since running a firewall ;) does that as well hehehe

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          C 1 Reply Last reply Mar 30, 2023, 11:36 PM Reply Quote 0
          • C
            clauder @johnpoz
            last edited by Mar 30, 2023, 11:36 PM

            @johnpoz Of course. I am just doing an analysis for an architecture that does not rely on removing capability (via a firewall rule here). In ultra secure setup, it is always better to have nothing and add the vry few things you need.

            A firewall rule can disappear without notice!!!!

            J D 2 Replies Last reply Mar 31, 2023, 2:32 AM Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator @clauder
              last edited by Mar 31, 2023, 2:32 AM

              @clauder said in Using avahi to resolve hosts:

              A firewall rule can disappear without notice!!!!

              The default is deny, so how is it the default deny just disappears? Someone would have to on purpose create an allow..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • D
                dennypage @clauder
                last edited by Apr 2, 2023, 6:39 AM

                @clauder I think the possibility that a security issue is introduced by adding a component such as Avahi to the mix is far greater than the possibility of a firewall rule randomly disappearing.

                J 1 Reply Last reply Apr 2, 2023, 9:50 AM Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @dennypage
                  last edited by Apr 2, 2023, 9:50 AM

                  @dennypage avahi just doesn't work - there are multiple steps required to get it working with firewall rules, and all that would be would be discovery. It wouldn't allow access.. its mdns..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received