• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Netgate 4200 - connection problems / DNS Resolver

Scheduled Pinned Locked Moved Official Netgate® Hardware
8 Posts 4 Posters 288 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    johndoe102
    last edited by johndoe102 Mar 29, 2025, 8:09 PM Mar 29, 2025, 8:07 PM

    Hello here,
    the title is a bit misleading, but I really didn't find a better one.

    To be honest , slowly I am tired of using this device (Netgate 4200). I had previously Netgate 2100 and I had no issues at all. I also cannot say if it is hardware or software, that is causing so many problems I have.

    Here is the problem (not the only one with this device/software).

    Very often (not each time) I cannot go outside to the public internet.

    So I am switching my PC on and trying to call any of the web sides in the web browser, but I cannot. I can reach pfsense GUI , but no DNS resolution works either from my PC nor directly from pfsense. So e.g. "ping google.com" doesn't work neither from my PC nor from pfsense box. Every time this problems occur, I need to restart either "unbound DNS Resolver" from the pfsense dashboard or my PC... then it works.

    Here is my setup:

    1. My PC is directly connected to igc1 (this LAN2 with local IP 192.168.2.2) - I assume some of you will write , that I should place a switch in between and connect my PC thru the switch and not directly to the pfsense, but hey, this is also a switch on Netgate device , so why I cannot do this ?
    2. I am using quad9 as DNS - everything is setup as described on quad9 page -> https://docs.quad9.net/Setup_Guides/Open-Source_Routers/pfSense_%28Encrypted%29/

    I am also attaching the pfsense.log. As you can see from the log I switched my PC at Mar 29 20:15:48 on.

    best regards
    Tom

    pfsense_general_log.txt

    S 1 Reply Last reply Mar 29, 2025, 8:44 PM Reply Quote 0
    • J
      JonathanLee
      last edited by JonathanLee Mar 29, 2025, 8:25 PM Mar 29, 2025, 8:23 PM

      What are your DNS port rules in terms of interface ACLs ?

      Did you create a NAT rule for DNS?

      Can you screenshot your rules for the interface that has issues?

      What packages are you using?

      Do you see the DNS listed when you look at status?

      Make sure to upvote

      J 1 Reply Last reply Mar 29, 2025, 11:41 PM Reply Quote 0
      • S
        SteveITS Galactic Empire @johndoe102
        last edited by Mar 29, 2025, 8:44 PM

        @johndoe102 The 4200 doesn’t have a switch built in. Powering off your PC will cause pfSense to detect the interface disconnect/reconnect and restart packages/services.

        Do you have DNSSEC disabled since you are forwarding? It’s in the doc, but often missed.

        Are you registering hostnames in DHVP? That restarts ISC DHCP server at each lease renewal.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        J 1 Reply Last reply Mar 29, 2025, 11:11 PM Reply Quote 0
        • J
          johndoe102 @SteveITS
          last edited by Mar 29, 2025, 11:11 PM

          @SteveITS

          Do you have DNSSEC disabled since you are forwarding? It’s in the doc, but often missed. -> Yes I do.
          Screenshot from 2025-03-30 00-04-06.png

          Are you registering hostnames in DHVP?. -> I am not aware about DHVP ... I am not using it. I didn't setup it ... at least not me. If there is something setup out-of-the-box then I am not aware about that.

          The only thing I do is , that for all clients in my home network I am using static IPs based on MAC and for all clients I do create ARP table static entries.
          Screenshot from 2025-03-30 00-11-07.png

          best regards
          Tom

          S 1 Reply Last reply Mar 29, 2025, 11:54 PM Reply Quote 0
          • J
            johndoe102 @JonathanLee
            last edited by johndoe102 Mar 29, 2025, 11:43 PM Mar 29, 2025, 11:41 PM

            @JonathanLee
            Hello,

            Did you create a NAT rule for DNS? -> No.

            Can you screenshot your rules for the interface that has issues?
            Screenshot from 2025-03-30 00-19-21.png

            Screenshot from 2025-03-30 00-16-26.png

            Screenshot from 2025-03-30 00-14-37.png

            What packages are you using?
            Screenshot from 2025-03-30 00-38-59.png

            Screenshot from 2025-03-30 00-36-07.png

            Screenshot from 2025-03-30 00-35-29.png

            P 2 Replies Last reply Mar 30, 2025, 5:30 AM Reply Quote 0
            • S
              SteveITS Galactic Empire @johndoe102
              last edited by Mar 29, 2025, 11:54 PM

              @johndoe102 DHCP, typo

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • P
                patient0 @johndoe102
                last edited by Mar 30, 2025, 5:30 AM

                @johndoe102 I know it is boring but please add a switch between pfSense and your PC on LAN2 (the 4200 does not have a built-in switch, in contrast to the 2100).

                The log shows LAN2/opt2/igc1 going up/down a few times in half a minute or so. That triggers a whole lot of scripts each time, wan restart is one of them. Removes and adds the gateway and so on.

                1 Reply Last reply Reply Quote 0
                • P
                  patient0 @johndoe102
                  last edited by Mar 30, 2025, 5:35 AM

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received