DNS Rule Apparently not working

  • Am I missing something here. I have a rule, the first on the list (GUI), set to all TCP from LAN NET to ANY on port 53 (DNS).

    Even with this rule in place the firewall logs show any DNS requests as DENIED.

    After further investigation the filter logs show that Rule 50, which is the DENY ALL rule, is being invoked.

    am I doing something wrong??

  • Nevermind. It was my lack of understand how DNS packets get routed.

    I was using only TCP and DNS should be UDP

  • Depending on the implementation it might be udp and tcp. I would make the rule use protocol udp+tcp.

