Query DNS servers sequentially

  • The 'Query DNS servers sequentially' confuses me; it doesn't behave how I'd expect.

    I have this feature enabled.

    Under System > General Setup > DNS Servers, I have:

    DNS requests to the DNS Forwarder seems to be getting responses from (or possibly even though and can handle the request.

    The DNS Forwarder supplies the correct responses when Domain Overrides are provided and point to the DNS server.

    Given the above settings, I'd expect the DNS Forwarder to get responses from regardless of the Domain Overrides, but that doesn't seem to be the case.

    pfSense version is 2.1.3-RELEASE (amd64)

    What am I misunderstanding?

  • Anyone? I'll take shot in the dark guesses.

  • The checkbox to use sequentially enables dnsmasq's –strict-order. Their man page describes that as:

    By default, dnsmasq will send queries to any of the upstream servers it knows about and tries to favour servers that are known to be up. Setting this flag forces dnsmasq to try each query with each server strictly in the order they appear in /etc/resolv.conf


    The order in resolv.conf should match what you have configured under System>General Setup, at least assuming you also have no dynamic WANs or have disabled DNS server updates from DHCP/PPP.

    If resolv.conf has the order as desired, then I suspect either your internal DNS servers aren't responding for some things, or maybe dnsmasq's –strict-order doesn't do what you're expecting and stopping at the first server that replies (I would think it does, but not entirely sure off the top of my head).

    Getting a packet capture of all UDP 53 traffic on LAN and seeing what that looks like might be telling. Maybe your internal servers are failing to respond at times.

Log in to reply