<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Is it possible to not resolve ipv6 certain dns domains?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I'm in a kind of a pickle.<br />
A customer wants to give us access to their Atera instance.<br />
They have ip filtering enabled and whitelisted our external ipv4 address.<br />
When we try to connect we get rejected since atera resolves as ipv6 and we use ipv6 to reach atera.<br />
Atera, in their infinite wisdom, does not support whitelisting ipv6 adresses.</p>
<p dir="auto">SO, is there a way to make pfsense only resolve ipv4 for certain domains?<br />
Alternatively can i make a policy route that forces ipv4 for certain domains?</p>
<p dir="auto">Regards, Lars</p>
]]></description><link>https://forum.netgate.com/topic/190224/is-it-possible-to-not-resolve-ipv6-certain-dns-domains</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 12:24:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/190224.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 23 Sep 2024 13:25:58 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Mon, 14 Oct 2024 07:27:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a></p>
<p dir="auto">This does it!</p>
<p dir="auto">Thank you all, you are may today's champions! <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f396.png?v=d00e50224fa" class="not-responsive emoji emoji-android emoji--medal" style="height:23px;width:auto;vertical-align:middle" title="🎖" alt="🎖" /></p>
]]></description><link>https://forum.netgate.com/post/1187914</link><guid isPermaLink="true">https://forum.netgate.com/post/1187914</guid><dc:creator><![CDATA[-flo- 0]]></dc:creator><pubDate>Mon, 14 Oct 2024 07:27:36 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Mon, 14 Oct 2024 07:20:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/flo-0">@<bdi>flo-0</bdi></a></p>
<p dir="auto"><img src="/assets/uploads/files/1728890408614-9356b8da-fdc8-4d34-97c4-bc946146c1bc-image.png" alt="9356b8da-fdc8-4d34-97c4-bc946146c1bc-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Switch from the old 'unbound' mode (see image) to the new Python mode.</p>
]]></description><link>https://forum.netgate.com/post/1187912</link><guid isPermaLink="true">https://forum.netgate.com/post/1187912</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 14 Oct 2024 07:20:44 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Mon, 14 Oct 2024 07:17:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lazer13">@<bdi>Lazer13</bdi></a></p>
<p dir="auto">Thank you for trying to help. I'm feeling kinda dumb right now.</p>
<p dir="auto">I select Firewall - pfBlockerNG. I now see a menu line with items General, IP, DNSBL, etc. There I select DNSBL and get a configuration screen. Neither in this nor in any of its three subscreens there is an item "AAAA". I even searched for the string.</p>
<p dir="auto">Maybe there is a problem with my configuration? I let the wizard create a default configuration after I installed pfBlockerNG yesterday. After this in the services widget the entry pfb_filter is shown as running, whereas the entry pfb_dnsbl is not. I cannot start this service from the widget.</p>
<p dir="auto">I must be missing something totally obvious. <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f622.png?v=d00e50224fa" class="not-responsive emoji emoji-android emoji--cry" style="height:23px;width:auto;vertical-align:middle" title="😢" alt="😢" /></p>
]]></description><link>https://forum.netgate.com/post/1187911</link><guid isPermaLink="true">https://forum.netgate.com/post/1187911</guid><dc:creator><![CDATA[-flo- 0]]></dc:creator><pubDate>Mon, 14 Oct 2024 07:17:18 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Mon, 14 Oct 2024 06:33:39 GMT]]></title><description><![CDATA[<p dir="auto">It's only easy once you know. :)</p>
<p dir="auto">Go into DNSBL and enable "no AAAA".<br />
When you enable it you get a new section called Python no AAAA List.<br />
Domains you put there will only resolve IPv4.</p>
]]></description><link>https://forum.netgate.com/post/1187906</link><guid isPermaLink="true">https://forum.netgate.com/post/1187906</guid><dc:creator><![CDATA[Lazer13]]></dc:creator><pubDate>Mon, 14 Oct 2024 06:33:39 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Sun, 13 Oct 2024 19:06:20 GMT]]></title><description><![CDATA[<p dir="auto">Sorry, this is probably a dumb question, but where exactly do I find these settings? I installed pfblockerng but didn't find anything like this in the settings ...</p>
]]></description><link>https://forum.netgate.com/post/1187886</link><guid isPermaLink="true">https://forum.netgate.com/post/1187886</guid><dc:creator><![CDATA[-flo- 0]]></dc:creator><pubDate>Sun, 13 Oct 2024 19:06:20 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Wed, 25 Sep 2024 09:03:39 GMT]]></title><description><![CDATA[<p dir="auto">It works flawlessly. Very nice.<br />
Unfortunately I still get error trying to login to atera but now I know ipv6 is not to blame :)</p>
]]></description><link>https://forum.netgate.com/post/1185874</link><guid isPermaLink="true">https://forum.netgate.com/post/1185874</guid><dc:creator><![CDATA[Lazer13]]></dc:creator><pubDate>Wed, 25 Sep 2024 09:03:39 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Wed, 25 Sep 2024 08:56:21 GMT]]></title><description><![CDATA[<p dir="auto">Awesome, thanks!<br />
Didn't notice that feature of pfblocker before. Will try it :)</p>
]]></description><link>https://forum.netgate.com/post/1185873</link><guid isPermaLink="true">https://forum.netgate.com/post/1185873</guid><dc:creator><![CDATA[Lazer13]]></dc:creator><pubDate>Wed, 25 Sep 2024 08:56:21 GMT</pubDate></item><item><title><![CDATA[Reply to Is it possible to not resolve ipv6 certain dns domains? on Mon, 23 Sep 2024 14:50:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lazer13">@<bdi>Lazer13</bdi></a> said in <a href="/post/1185576">Is it possible to not resolve ipv6 certain dns domains?</a>:</p>
<blockquote>
<p dir="auto">SO, is there a way to make pfsense only resolve ipv4 for certain domains?</p>
</blockquote>
<p dir="auto">and block AAAA request ?<br />
pfSense, aka the resolver will do its job as asked.<br />
<s>You could probably do something with domain overrides</s> <em>or</em> install pfBlockerng and use this option :</p>
<p dir="auto"><img src="/assets/uploads/files/1727102845427-5abed146-b4aa-402c-9912-2143ef91108e-image.png" alt="5abed146-b4aa-402c-9912-2143ef91108e-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">as it was included just for that : block AAAA requests of all domain names listed.</p>
<p dir="auto"><strong>edit</strong> : Non, forget about host overrides.<br />
You probably have to pick the correct unbound's config settings, see <a href="https://nlnetlabs.nl/documentation/unbound/unbound.conf/" target="_blank" rel="noopener noreferrer nofollow ugc">https://nlnetlabs.nl/documentation/unbound/unbound.conf/</a> )</p>
]]></description><link>https://forum.netgate.com/post/1185592</link><guid isPermaLink="true">https://forum.netgate.com/post/1185592</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 23 Sep 2024 14:50:40 GMT</pubDate></item></channel></rss>