• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS Forwarder but with local leases from DHCP server. How?

Scheduled Pinned Locked Moved DHCP and DNS
13 Posts 4 Posters 5.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    doktornotor Banned
    last edited by Jul 31, 2013, 3:56 PM

    Uhm… If you are running AD-integrated DNS, you should run DHCP on those Windows machines and let it register the leases in DNS. Also, any of AD-joined machines MUST point to the AD DNS servers and nothing else. Forget about pointing them to the forwarder.

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Jul 31, 2013, 4:28 PM

      ^ as stated if a box is member of AD, it should point to your AD dns.. Your AD dns then can lookup other things you want to lookup via either forwarder or root directly.

      And if your running AD, its best to run your dhcp on your AD as well, if need be you can setup a dhcp relay on your pfsense to forward to your AD dhcp.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by Jul 31, 2013, 5:28 PM

        I have DHCP from pfSense, but it gives out the AD DNS. That works fine - so you can have DHCP on pfSense and the DNS on the Windows AD Server.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by Jul 31, 2013, 5:41 PM

          @phil.davis:

          I have DHCP from pfSense, but it gives out the AD DNS. That works fine - so you can have DHCP on pfSense and the DNS on the Windows AD Server.

          Cannot really see how you get secure DDNS updates working with similar configuration on pfsense….

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Jul 31, 2013, 5:48 PM

            You can hand out the AD dns from your dhcp server on pfsense sure – but what is the point??  You clearly have a box that can run dhcp.. And even has to be authed in AD to do so, etc..  What are the advantages of running dhcp on pfsense other than in your AD setup??

            I just don't see a reason to do it.  Can you give advantages you see or reasons you run dhcp on pfsense vs your AD infrastructure that your running anyway.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by Jul 31, 2013, 5:53 PM

              @johnpoz:

              You can hand out the AD dns from your dhcp server on pfsense sure – but what is the point?? 
              I just don't see a reason to do it.

              Pretty much… I've done bind with AD DHCP. It was a geniune PITA. I've done ISC DHCPd with AD DNS. It was tripple PITA to get working with secure DNS updates. (The latter is IMHO impossible with pfSense out of the box since there's no kerberos shipped at all.)

              1 Reply Last reply Reply Quote 0
              • G
                gspadari
                last edited by Aug 1, 2013, 5:57 PM

                :o Wow!!!… I really appreciate all the help you gave me.

                I was misunderstanding the Forwarders option. I thought the Forwarder was responsible for informing the Name-IP to the real DNS, and not the client itself.

                I like to have pfSense as DHCP because of the CARP ability.

                Finally: I'll let DNS on AD, and every client box will point to AD DNS. Then, those DNS will use as forwarders the pfSense who will talk to the root hints.

                Thank you everybody.

                1 Reply Last reply Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator
                  last edited by Aug 1, 2013, 6:12 PM Aug 1, 2013, 6:09 PM

                  "I like to have pfSense as DHCP because of the CARP ability."

                  And what does that solve if your DC that does dns is down?  Before you could do dhcp in a cluster to provide HA, or you could setup a split scope..  But the 2012 server provides real dhcp failover..

                  Any of the above options allow for HA in dhcp in microsoft..  So no need for carp for dhcp ha.

                  btw: the forwarder service in pfsense does not talk to root hints, it talks to whatever dns you have setup.. which might talk to root hints, or might also forward to something else..  Are you running unbound or tinydns on your pfsense box?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • G
                    gspadari
                    last edited by Aug 2, 2013, 2:37 AM

                    Well… I've 2 AD-DNS. If one goes down, I trust that the other will serve as well.
                    I'm trying to reduce the number of Win srvrs, so I'm not seeing the 2012 as an option.
                    Thanks about the root hints. I thought it was different.
                    I'm using the default that come with pfSense... it is "dnsmasq", right?

                    Thanks again.

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by Aug 3, 2013, 11:15 AM

                      "I'm trying to reduce the number of Win srvrs, so I'm not seeing the 2012 as an option."

                      What??? That makes no sense at all – what does wins have to do with moving to 2012 which supports failover dhcp, or for that matter using dhcp in a cluster of your current version or just using split dhcp..  If what your worried about is HA for your dhcp..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • G
                        gspadari
                        last edited by Aug 3, 2013, 2:49 PM Aug 3, 2013, 2:46 PM

                        Did you interpret "WINS Server"? I mean, "Windows Servers" or "Windows Services", not "WINS Server".  :P

                        1 Reply Last reply Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator
                          last edited by Aug 6, 2013, 12:15 PM

                          "I've 2 AD-DNS"

                          I assume those are Windows – upgrade those to 2012, there you go failover dhcp without increase in your number of windows servers.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          13 out of 13
                          • First post
                            13/13
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received