Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    No DNS Resolution

    DHCP and DNS
    10
    17
    19721
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lschem last edited by

      I have a new installation of pfSense version 1.0.1 installed from the CD with a WAN public IP of x.x.250.121 and a LAN IP of 192.168.0.1.  I also have IPs on the LAN interface in the x.x.250.x public IP range that I am trying to firewall. Included in these are our authoritative DNS server for our domain/subnet of x.x.250.x.  I am trying to replace an MNF v8.2 firewall with pfSense.  After duplicating the firewall rules as well as I could translate between the two firewall configuration interfaces I tried a test and found that from the LAN side DNS queries would not resolve.  However, pings of IP addresses would pass.

      What should I look for in my configuration to resolve this problem?

      Currently, I have the WAN DNS server set as our internal authoritative DNS at x.x.250.1.  I'm thinking that I should change this to the campus authoritative DNS at x.x.252.1.  I am going to test this idea later today.

      Further I have pfSense configured with virtual IPs for each of our machines that has an x.x.250.x address, with corresponding 1:1 NAT rules for each.  Eventually we would like to remove all public IPs from all of our machines and allow them to communicate via virtual IPs on the pfSense box.

      1 Reply Last reply Reply Quote 0
      • H
        hoba last edited by

        Make sure you have entered DNS-Servers at system>general. If the dns-forwarder is enabled (which is enabled by default on LAN) it should work.

        1 Reply Last reply Reply Quote 0
        • H
          hchady last edited by

          i have the same problem… it was working before but when i upgraded to latest snapshots (27-02 or 08-03) dns doesn't work as expected

          1 Reply Last reply Reply Quote 0
          • S
            sullrich last edited by

            @hchady:

            i have the same problem… it was working before but when i upgraded to latest snapshots (27-02 or 08-03) dns doesn't work as expected

            We have not change anything involving DNS.

            1 Reply Last reply Reply Quote 0
            • R
              regis last edited by

              i've quite the same problem since snapshot 27/02

              my pfsense has a dual wan setup : WAN dhcp fixed private address behind a dsl modem, WAN2 dhcp fixed public address

              everything's working ok until dhcp leases are refreshed, then no dns resolution !

              on a LAN win xp box, if i try a nslookup on e.g. www.google.fr, it answers "query refused"

              if i reboot the pfsense and clear the win xp dns cache (with ipconfig /flushdns), all is working again.

              i updated pfsense to snapshot 08/03 but still the same problem

              I setup my WANs with static addresses and pfsense is running for 3days now, no dns problems…

              1 Reply Last reply Reply Quote 0
              • Y
                yoda715 last edited by

                Try entering manual DNS entries under the 'System>General Setup' menu. Uncheck the box allow DNS entries to be overwritten by dhcp. Report back what you find.

                1 Reply Last reply Reply Quote 0
                • R
                  regis last edited by

                  I forgot to explain my dns setup

                  I already entered two DNS servers in System/General (one for each ISP) and unchecked the box. I too have entered static routes for DNS queries to go out through the ad hoc WAN

                  this setup works perfectly with WAN static adresses and with DHCP addresses until DHCP lease refresh

                  there are no error messages in logs, each time dns cease to work, the lasts entries are about dhcp few seconds ago…

                  1 Reply Last reply Reply Quote 0
                  • C
                    Crosis last edited by

                    @sdale:

                    Try entering manual DNS entries under the 'System>General Setup' menu. Uncheck the box allow DNS entries to be overwritten by dhcp. Report back what you find.

                    I have the same problem as regis(only one ISP, though). Already tried sdale's suggestion.
                    How can I fix this?

                    1 Reply Last reply Reply Quote 0
                    • C
                      Crosis last edited by

                      I really need help with this, the pfsense box is in my house and this problem is driving me crazy.

                      1 Reply Last reply Reply Quote 0
                      • C
                        Crosis last edited by

                        Today I reinstalled with the "1.2-TESTING-SNAPSHOT-07-21-2007" ISO and the problem persists, I dont know what to do now, please help me guys.

                        1 Reply Last reply Reply Quote 0
                        • N
                          nexus010 last edited by

                          Hi.
                          I am experiencing the same/similar problems as the others in this post.
                          I see traffic in and out but web page resolution is hit and miss.
                          It will work for a few seconds then stop.
                          I can ping across the box from the lan to an external site and then it vanishes.
                          I can ping from the diagnostics page to an external site then it vanishes.
                          I have a static IP WAN IP and static DNS servers.

                          I have set up the DNS servers in the general setup page.
                          I have unchecked the box allows DNS entries to be overwritten by dhcp.
                          DNS Forwarding is enabled.
                          I have no packages installed
                          I have tried 1.2 Beta 1, 1.2 Beta 2 and 1.2 RC 1.
                          I have tried updates and fresh intalls in every case the results are the same.
                          I'm going to try 1.01 today but I see from the previous posts this may not work either.

                          The potentials of this project are huge.
                          Keep up the good work !

                          1 Reply Last reply Reply Quote 0
                          • C
                            Crosis last edited by

                            Still stuck with this problem.
                            I noticed something: When my pfsense box stops working(no dns resolution, unable to ping static ip addresses, cant do anything with my wan) I can see the status of the wan with my IP address, my subnet mask but my ISP gateway is gone. Maybe this will give you a hint of what is my problem.
                            BTW, if I reboot the pfsense box, the internet connection starts working again.

                            1 Reply Last reply Reply Quote 0
                            • N
                              nexus010 last edited by

                              Update from my end.
                              After extensive testing and building.
                              I had 3 seperate boxes built with every flavour of ipcop, monowall and pfsense.
                              I even replaced my production gateway to put it on the new circut, when I saw it failing to resolve web pages I started thinking outside of the box….
                              I came to realise that the static DNS servers that I was given to connect to where out to lunch.
                              It was only when I put in the dns numbers from opnendns.org did I get what I'm paying for.
                              10meg fibre. 10 up and 10 down and with genuine real webpages too.LOL
                              I called the help desk 3 times on this.They said there was no problem on their end.
                              When I ran a trace route to the DNS servers there was long delays not only in resolving but in arriving.
                              I did the trace route to opendns and it was fast no delay all resolved.

                              This is a very cool idea.
                              You can even enable blocking for unsafe sites, put in filters for adult contact and totally free.
                              It restored my sanity and solved my problem.
                              I have been load testing the circut late at night and pfsense has exceeded my hopes.
                              It is so simple to try its worth the test.
                              I hope it resolves some of the other problems you guys are struggling with here.
                              Cheers

                              1 Reply Last reply Reply Quote 0
                              • C
                                Crosis last edited by

                                @nexus010:

                                Update from my end.
                                After extensive testing and building.
                                I had 3 seperate boxes built with every flavour of ipcop, monowall and pfsense.
                                I even replaced my production gateway to put it on the new circut, when I saw it failing to resolve web pages I started thinking outside of the box….
                                I came to realise that the static DNS servers that I was given to connect to where out to lunch.
                                It was only when I put in the dns numbers from opnendns.org did I get what I'm paying for.
                                10meg fibre. 10 up and 10 down and with genuine real webpages too.LOL
                                I called the help desk 3 times on this.They said there was no problem on their end.
                                When I ran a trace route to the DNS servers there was long delays not only in resolving but in arriving.
                                I did the trace route to opendns and it was fast no delay all resolved.

                                This is a very cool idea.
                                You can even enable blocking for unsafe sites, put in filters for adult contact and totally free.
                                It restored my sanity and solved my problem.
                                I have been load testing the circut late at night and pfsense has exceeded my hopes.
                                It is so simple to try its worth the test.
                                I hope it resolves some of the other problems you guys are struggling with here.
                                Cheers

                                Sadly, Im from Argentina. Using opendns for dns resolution severely lags my web browsing. This sucks…

                                1 Reply Last reply Reply Quote 0
                                • C
                                  Crosis last edited by

                                  Everything is working fine now. Looks like the problem was my ISP's DNS server. =/

                                  1 Reply Last reply Reply Quote 0
                                  • I
                                    ipnet last edited by

                                    Hello Crosis, I am also from Arg. and I have the same problem. Didi you get to solve this issue? ???

                                    Regards.

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      Perry last edited by

                                      Everything is working fine now. Looks like the problem was my ISP's DNS server. =/

                                      I can ping those
                                      @http://wiki.telecomsucks.com/Lista_de_Servidores_DNS:

                                      *  IPlan: 200.69.193.1 (dns1.iplanisp.com)

                                      * IPlan: 200.69.193.2 (dns1.iplanisp.com.ar)

                                      /Perry
                                      doc.pfsense.org

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post