Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    DNS Forwarder: forward not working for dns request

    Scheduled Pinned Locked Moved DHCP and DNS
    5 Posts 2 Posters 1.2k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • chris1284C Offline
      chris1284
      last edited by chris1284

      Hi,
      i have technitium cluster with 2 dns + dhcp servers. the dns resolver at pfsense is disbaled, the dhcp service is disabled. in

      SystemGeneral Setup -> System: domain is set to home.arpa
      SystemGeneral Setup -> DNS Server: 192.168.2.3 & 192.168.2.7 is set

      the dns forwarder is enabled, service started.
      9828e34a-859f-4be2-8ff4-ea939a1cde4f-grafik.png

      WG0 is my wireguard interface with 10.0.9.1/24

      domain overrides is set: d0175011-ec7a-4cb2-9230-44d61fc6a5fa-grafik.png

      my problem is on my wireguard tunnels, that nslookuphostname or hostname.home.arpa is not forwarded. internal everything is working, because idhcp sets the dns server and the search suffic to home.apra. in wireguard clients i have fix ips and set the DNS like this:

      [Interface]
      PrivateKey =blablub=
      Address = 10.0.9.5/32
      DNS = 10.0.9.1, home.arpa
      

      nslookup on a wireguard client with hostname only:

      nslookup nas00
      Server:  UnKnown
      Address:  10.0.9.1
      
      *** nas00 wurde von UnKnown nicht gefunden: Server failed.
      

      with hostname + domain

      nslookup nas00.home.arpa
      Server:  UnKnown
      Address:  10.0.9.1
      
      *** nas00.home.arpa wurde von UnKnown nicht gefunden: Server failed.
      

      what can i do, to configure the forwarder to forward every dns reqeust at 10.0.9.1 to 192.168.2.3?
      for the ****.org domain it is working (i have some interl host overrides).

      thx

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @chris1284
        last edited by

        @chris1284 is the answer a private IP?
        https://docs.netgate.com/pfsense/en/latest/services/dns/rebinding.html#dns-resolver

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        chris1284C 1 Reply Last reply Reply Quote 0
        • chris1284C Offline
          chris1284 @SteveITS
          last edited by chris1284

          @SteveITS yes, the answer should be an adress from 192.168.2.0/24. the rebind-domain-ok option is set for home.arpa. the domain override lists includes also both domain. for the ***.org it is working. for home.arpa not

          SteveITSS 1 Reply Last reply Reply Quote 0
          • SteveITSS Offline
            SteveITS Rebel Alliance @chris1284
            last edited by

            @chris1284 Well I’ve used Resolver and it works there. You might try that and set it to forward. It basically replaced Forwarder years ago.

            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Only install packages for your version of pfSense.
            Upvote 👍 helpful posts!

            chris1284C 1 Reply Last reply Reply Quote 0
            • chris1284C Offline
              chris1284 @SteveITS
              last edited by chris1284

              @SteveITS thx, with dns resolver it worked directly

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
              Privacy Policy · Cookie Policy