• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Blocking DNS queries to external resolvers

Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
2 Posts 2 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    edwinonia
    last edited by May 8, 2013, 5:13 AM

    Mam/Sir,
    Very sorry to bother you all Im very desperate to resolve the issue on my pfsense box. Below are the links:

    http://doc.pfsense.org/index.php/Blocking_DNS_queries_to_external_resolvers

    Below the solution they mentioned that "You could also allow certain local PCs to use other DNS server by placing a pass rule for them above the block rule." but I cannot understand how to do that. What I want is I want to allow other pc to connect to other DNS server like google DNS 8.8.8.8 and 8.8.4.4. Please help me how to create a rule for that. Im trying to create a rule but still have no luck my internet will become disconnected if im going to insert other DNS IP.

    edwin

    1 Reply Last reply Reply Quote 0
    • P
      phil.davis
      last edited by May 8, 2013, 6:19 AM

      Those instructions look good. To let some systems "out" to use another external DNS server/s:

      1. Add an alias "ExternalDNSallowed" (or some such name). Add all the LAN IP addresses of systems that are allowed to use an external DNS directly.
      2. Add an alias "PermittedDNSservers" (or some such name). Add the IP addresses of external DNS servers you allow to be used (e.g. 8.8.8.8 and 8.8.4.4)
      3. Add a firewall rule on LAN permitting IPv4, TCP+UDP, source "ExternalDNSallowed", destination "PermittedDNSservers", port 53.
      4. Move the rule up before the wildcard rule that blocks everything to port 53.

      As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
      If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received