• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS Forwarder but with local leases from DHCP server. How?

Scheduled Pinned Locked Moved DHCP and DNS
13 Posts 4 Posters 5.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    gspadari
    last edited by Jul 31, 2013, 3:45 PM

    Hello,

    I've setup a pfsense box with DHCP Server enable on LAN and DNS Forwarder enable to my Windows AD DNS.
    A PC client has the DNS servers configured as the pfsense IP.
    Every entry in the Windows AD DNS is resolved correctly from client computers.
    But if I try to ping a computer whose lease is in the DHCP pfsense box, the ping can't resolve the name.
    I've tried setting the "Resolve DHCP mappings first" option, with no luck.

    Is it possible to accomplish what I was trying to do? (I mean, a DNS query ask first in the DHCP pfsense leases, if it is not there, then use the DNS forwarders).

    Thanks!

    1 Reply Last reply Reply Quote 0
    • D
      doktornotor Banned
      last edited by Jul 31, 2013, 3:56 PM

      Uhm… If you are running AD-integrated DNS, you should run DHCP on those Windows machines and let it register the leases in DNS. Also, any of AD-joined machines MUST point to the AD DNS servers and nothing else. Forget about pointing them to the forwarder.

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Jul 31, 2013, 4:28 PM

        ^ as stated if a box is member of AD, it should point to your AD dns.. Your AD dns then can lookup other things you want to lookup via either forwarder or root directly.

        And if your running AD, its best to run your dhcp on your AD as well, if need be you can setup a dhcp relay on your pfsense to forward to your AD dhcp.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • P
          phil.davis
          last edited by Jul 31, 2013, 5:28 PM

          I have DHCP from pfSense, but it gives out the AD DNS. That works fine - so you can have DHCP on pfSense and the DNS on the Windows AD Server.

          As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
          If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by Jul 31, 2013, 5:41 PM

            @phil.davis:

            I have DHCP from pfSense, but it gives out the AD DNS. That works fine - so you can have DHCP on pfSense and the DNS on the Windows AD Server.

            Cannot really see how you get secure DDNS updates working with similar configuration on pfsense….

            1 Reply Last reply Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator
              last edited by Jul 31, 2013, 5:48 PM

              You can hand out the AD dns from your dhcp server on pfsense sure – but what is the point??  You clearly have a box that can run dhcp.. And even has to be authed in AD to do so, etc..  What are the advantages of running dhcp on pfsense other than in your AD setup??

              I just don't see a reason to do it.  Can you give advantages you see or reasons you run dhcp on pfsense vs your AD infrastructure that your running anyway.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by Jul 31, 2013, 5:53 PM

                @johnpoz:

                You can hand out the AD dns from your dhcp server on pfsense sure – but what is the point?? 
                I just don't see a reason to do it.

                Pretty much… I've done bind with AD DHCP. It was a geniune PITA. I've done ISC DHCPd with AD DNS. It was tripple PITA to get working with secure DNS updates. (The latter is IMHO impossible with pfSense out of the box since there's no kerberos shipped at all.)

                1 Reply Last reply Reply Quote 0
                • G
                  gspadari
                  last edited by Aug 1, 2013, 5:57 PM

                  :o Wow!!!… I really appreciate all the help you gave me.

                  I was misunderstanding the Forwarders option. I thought the Forwarder was responsible for informing the Name-IP to the real DNS, and not the client itself.

                  I like to have pfSense as DHCP because of the CARP ability.

                  Finally: I'll let DNS on AD, and every client box will point to AD DNS. Then, those DNS will use as forwarders the pfSense who will talk to the root hints.

                  Thank you everybody.

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Aug 1, 2013, 6:12 PM Aug 1, 2013, 6:09 PM

                    "I like to have pfSense as DHCP because of the CARP ability."

                    And what does that solve if your DC that does dns is down?  Before you could do dhcp in a cluster to provide HA, or you could setup a split scope..  But the 2012 server provides real dhcp failover..

                    Any of the above options allow for HA in dhcp in microsoft..  So no need for carp for dhcp ha.

                    btw: the forwarder service in pfsense does not talk to root hints, it talks to whatever dns you have setup.. which might talk to root hints, or might also forward to something else..  Are you running unbound or tinydns on your pfsense box?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • G
                      gspadari
                      last edited by Aug 2, 2013, 2:37 AM

                      Well… I've 2 AD-DNS. If one goes down, I trust that the other will serve as well.
                      I'm trying to reduce the number of Win srvrs, so I'm not seeing the 2012 as an option.
                      Thanks about the root hints. I thought it was different.
                      I'm using the default that come with pfSense... it is "dnsmasq", right?

                      Thanks again.

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator
                        last edited by Aug 3, 2013, 11:15 AM

                        "I'm trying to reduce the number of Win srvrs, so I'm not seeing the 2012 as an option."

                        What??? That makes no sense at all – what does wins have to do with moving to 2012 which supports failover dhcp, or for that matter using dhcp in a cluster of your current version or just using split dhcp..  If what your worried about is HA for your dhcp..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • G
                          gspadari
                          last edited by Aug 3, 2013, 2:49 PM Aug 3, 2013, 2:46 PM

                          Did you interpret "WINS Server"? I mean, "Windows Servers" or "Windows Services", not "WINS Server".  :P

                          1 Reply Last reply Reply Quote 0
                          • J
                            johnpoz LAYER 8 Global Moderator
                            last edited by Aug 6, 2013, 12:15 PM

                            "I've 2 AD-DNS"

                            I assume those are Windows – upgrade those to 2012, there you go failover dhcp without increase in your number of windows servers.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            1 out of 13
                            • First post
                              1/13
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received