About blocking DNS 53 on WAN interface
-
I use and force my DNS request to quad9 using DoT.
To make sure of that, I followed the NAT recipe and added a block rule on port 53 of the wan interface. Only 853 is allowed.When I reboot my pfSense, I can see that it attempted to contact every DNS root servers on UDP 53, which was blocked.
Can this cause a problem? I don't see any but...
-
Well!
This is unexpected: no answer to this?!?
I'm starting to be concerned... -
@marchand-guy said in About blocking DNS 53 on WAN interface:
Well!
This is unexpected: no answer to this?!?
I'm starting to be concerned...Don’t be. It’s quite normal behaviour. UNBOUND resolver will still attempt to populate it’s root server hints via normal DNS queries (it’s what it is designed for) even though it is in forwarding mode to Quad9 via DoT.
-
@marchand-guy This recipe?
https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.htmlA rule on WAN would block incoming connections from the Internet. Which are blocked by default because WAN has no allow rules out of the box.
-
@steveits said in About blocking DNS 53 on WAN interface:
A rule on WAN would block incoming connections from the Internet.
True - unless he was doing a floating rule on wan interface in the outbound direction, which is what I think he was doing.
A redirection of 53 traffic coming in on your lan side interface might be better. This should prevent any client from using anything other than your dns. And would still allow pfsense to go out on normal 53 for what it might need, for example if your unbound is down, pfsense could still resolve using what you setup is forwarders in just normal dns 53 mode. Clients would be down - but pfsense would still have dns, so your webgui shouldn't stall on you, and you could check for updates and packages, etc.
-
@johnpoz said in About blocking DNS 53 on WAN interface:
unless he was doing a floating rule on wan interface in the outbound direction, which is what I think he was doing.
Exactly what I am doing.
Everything out on WAN using dest port udp 53 is blocked.