Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    CoreDNS stops resolving DNS after every reboot on pfSense Plus 26.07, including WireGuard remote access

    Scheduled Pinned Locked Moved DHCP and DNS
    2 Posts 2 Posters 102 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rwray
      last edited by

      I am using a Netgate 4200 running pfSense Plus 26.07 and have found what appears to be a reproducible CoreDNS startup issue. I also noticed a related DNS problem with my WireGuard remote-access VPN after enabling CoreDNS.

      My DNS setup was:

      • CoreDNS enabled and listening on port 53
      • Unbound DNS Resolver listening on port 5353
      • CoreDNS forwarding queries to Unbound
      • Multiple local VLANs
      • WireGuard remote-access VPN
      • WireGuard clients use the pfSense WireGuard address 10.2.3.1 as their DNS server

      Problem 1 – DNS fails after every pfSense reboot

      After rebooting pfSense:

      • Internet connectivity by IP still works
      • I can ping 8.8.8.8
      • DNS resolution fails, for example google.com does not resolve
      • The issue affects normal LAN clients
      • CoreDNS still appears to be enabled in the configuration

      If I then:

      1. Disable CoreDNS
      2. Apply the change
      3. Enable CoreDNS again
      4. Apply the change

      DNS immediately starts working again.

      This behaviour is reproducible after every reboot.

      Problem 2 – WireGuard remote-access DNS

      I also experienced a DNS issue with my WireGuard remote-access connection.

      The WireGuard tunnel itself was working correctly:

      • WireGuard connected successfully and showed a recent handshake
      • I could access/ping local network IP addresses
      • I could ping 8.8.8.8
      • However, I could not resolve or ping google.com
      • The WireGuard client DNS server was set to 10.2.3.1, which is the pfSense WireGuard tunnel address

      So the VPN routing and Internet access were working, but DNS through pfSense was not.

      After disabling CoreDNS completely and changing Unbound from port 5353 back to port 53, the WireGuard DNS problem also disappeared.

      The WireGuard client can now:

      • Access local IP addresses
      • Ping 8.8.8.8
      • Resolve and ping google.com
      • Use 10.2.3.1 as its DNS server normally

      Workaround

      I have currently disabled CoreDNS completely and changed Unbound from port 5353 back to port 53.

      With this configuration:

      • DNS works normally after reboot
      • LAN clients resolve DNS normally
      • WireGuard remote-access clients resolve DNS normally
      • 8.8.8.8 and google.com both work through WireGuard

      This suggests that the WireGuard routing, firewall rules and outbound NAT are working correctly, and the problem appears to be related specifically to CoreDNS.

      Has anyone else seen either of these behaviours on pfSense Plus 26.07?

      The reboot issue looks as though CoreDNS may not be initialising or binding correctly during startup, because simply disabling and re-enabling CoreDNS after boot fixes DNS immediately.

      1 Reply Last reply Reply Quote 0
      • rdsmith24R Offline
        rdsmith24
        last edited by

        I have exactly the same issue with CoreDNS not coming back on after a re-boot. Tried three different machines all loaded with fresh installs with minimal packages during testing.

        Can't put my finger on exactly what is causing it but I see the issue being brought up by others.

        Switched CoreDNS off till next revision of pfSense.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
        Privacy Policy · Cookie Policy