• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Prevent ISP from adding DNS servers via WAN DHCP

Scheduled Pinned Locked Moved DHCP and DNS
2 Posts 2 Posters 117 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jhg
    last edited by Mar 29, 2025, 12:41 AM

    My ISP is Comcast/Xfinity, and they insert their own DNS servers into my pfSense/unbound's upstream server list. I would like to prevent that, and found under System/General Setup/DNS Server Settings:

    Allow DNS server list to be overridden by DHCP/PPP on WAN or remote OpenVPN server
    If this option is set, pfSense will use DNS servers assigned by a DHCP/PPP server on WAN or a remote OpenVPN server (if Pull DNS option is enabled) for its own purposes (including the DNS Forwarder/DNS Resolver). However, they will not be assigned to DHCP clients.

    Problem is, I'd like to prevent WAN DHCP from adding to my DNS servers, but allow OpenVPN to do so. From the wording here it looks like it's both or neither, at least from the GUI.

    Is it possible to configure this in a more fine-grained way to achieve my objective?

    pfSense CE on Beelink EQ12 (N100 CPU, dual 2.5Gbe Intel NICs)
    Hitron CODA56 - Comcast 2.5Gb cable

    J 1 Reply Last reply Mar 29, 2025, 1:49 AM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @jhg
      last edited by Mar 29, 2025, 1:49 AM

      @jhg not like everyone doesn't know what the comcast dns servers are - they have been the same IPs for years and years. 75.75.75.75 and 75.75.76.76, ipv6 2001:558:feed::1 and ::2

      So don't let dhcp override - and manually set them to hand out to your openvpn in the vpn settings.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received