Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver for networks NOT behind the firewall - NOT WORKING

    Scheduled Pinned Locked Moved DHCP and DNS
    4 Posts 2 Posters 247 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Ethereal
      last edited by

      Hi guys,

      So I'm hoping I'm not spamming the wrong section as my setup is a bit different and not that common.
      My setup:
      I'm using the pfsense as firewall for a new networks that are configured on a Cisco Catalyst switch.
      Between Catalyst and pfsesne I'm running OSPF. DHCP for these networks is the Catalyst switch. DNS servers are pushed through DHCP and are 8.8.8.8 and 8.8.4.4

      The problem
      I configured pfblockerng and DNSBL (requires DNS Resolver) but DNS Blocker is not working for my networks behind the Catalyst switch.
      What I tried was to bring up another network directly on the firewall, with dhcp on the firewall itself - 10.155.55.0/24 with 10.155.55.1 gw/dns.
      DNSBlocker works for this network. However if I configure the networks behind the Catalyst with 10.155.55.1 as DNS server, DNS is not working.
      Network connectivity is allowed between these networks and 10.155.55.0/24 and nothing is blocked.

      Any idea what's going on?

      Thank you

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @Ethereal
        last edited by bingo600

        @Ethereal

        I don't use pfBlocker.
        But if pfBlocker is using unbound as dns server, you have to "allow/add foreign nets" to the unbound ACL (access lists), else it will not respond to queries from those ip's.

        0ece7304-5196-4e84-b770-6a4d0d037c99-image.png

        ps: This will be true for all "Non pfSense interface nets" , including VPN client nets (pools).

        /Bingo

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        E 1 Reply Last reply Reply Quote 1
        • E
          Ethereal @bingo600
          last edited by

          @bingo600 you the man.
          I spent a few hours yesterday trying to figure out what's going on.
          Thanks a lot! Problem Solved!

          bingo600B 1 Reply Last reply Reply Quote 1
          • bingo600B
            bingo600 @Ethereal
            last edited by

            @Ethereal

            I just gave a thumbs up ... As you need 5 (I think) , in order to be able to post wo. restrictions.
            Maybe some others could do the same , until you reach 5.

            /Bingo

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.