<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Despite WAN-blocking firewall rule, machine can still resolve hostnames? [FIXED]]]></title><description><![CDATA[<p dir="auto">Hello all,</p>
<p dir="auto">Despite the following firewall rule which SHOULD block all WAN access to this IP, it's still able to resolve hostnames to IPs.  Surely DNS traffic is included in this rule which is set up to block all protocols, ports and destinations from one IP on the LAN.</p>
<pre><code>
Proto    Source         Dest    Port     G/W    Sched
 *  	 192.168.2.1  	 *  	 *  	 *  	 *
</code></pre>
<p dir="auto">Wite this rule in place, the machine can not ping any IPs, load websites etc, but it CAN resolve a hostname to an IP…</p>
<p dir="auto">E.g:</p>
<pre><code>
C:\Documents and Settings\Dave&gt;ping -t google.fr

Pinging google.fr [216.239.59.104] with 32 bytes of data:

Request timed out.
Request timed out.

Ping statistics for 216.239.59.104:
    Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
</code></pre>
<p dir="auto">Why is this? (The address is definately not cached anywhere…)</p>
<p dir="auto">Cheers,<br />
Dave<br />
<img src="/public/_imported_attachments_/1/pfsense.jpg" alt="pfsense.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pfsense.jpg_thumb" alt="pfsense.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/5256/despite-wan-blocking-firewall-rule-machine-can-still-resolve-hostnames-fixed</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 02:49:50 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/5256.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 21 Jul 2007 20:53:34 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Despite WAN-blocking firewall rule, machine can still resolve hostnames? [FIXED] on Sat, 21 Jul 2007 21:10:24 GMT]]></title><description><![CDATA[<p dir="auto">Ahh it was something simple then, thanks :D</p>
<p dir="auto">Cheers again,<br />
Dave</p>
<p dir="auto">PS. Thanks for the prompt and knowledgable replies you lot =)</p>
]]></description><link>https://forum.netgate.com/post/157859</link><guid isPermaLink="true">https://forum.netgate.com/post/157859</guid><dc:creator><![CDATA[UBBERdave]]></dc:creator><pubDate>Sat, 21 Jul 2007 21:10:24 GMT</pubDate></item><item><title><![CDATA[Reply to Despite WAN-blocking firewall rule, machine can still resolve hostnames? [FIXED] on Sat, 21 Jul 2007 20:59:33 GMT]]></title><description><![CDATA[<p dir="auto">Turn off the DNS Forwarder.</p>
]]></description><link>https://forum.netgate.com/post/157858</link><guid isPermaLink="true">https://forum.netgate.com/post/157858</guid><dc:creator><![CDATA[sullrich]]></dc:creator><pubDate>Sat, 21 Jul 2007 20:59:33 GMT</pubDate></item></channel></rss>