<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DNS forwarder question]]></title><description><![CDATA[<p dir="auto">I have questions related to https://doc.pfsense.org/index.php/DNS_Forwarder</p>
<p dir="auto">I am using default settings except that I checked the box next to "Register DHCP static mappings in the DNS Resolver".</p>
<p dir="auto">In the docs, I found this note:</p>
<blockquote>
<p dir="auto">Important Note: This service should not be exposed publicly. Ensure inbound rules on WANs do not allow connections from the Internet to reach the DNS Forwarder service on the firewall.</p>
</blockquote>
<p dir="auto">Does this mean I need to add a rule to my firewall to protect against this service being exposed?  I am using the default firewall rules that come with a default pfSense installation.</p>
]]></description><link>https://forum.netgate.com/topic/81238/dns-forwarder-question</link><generator>RSS for Node</generator><lastBuildDate>Fri, 14 Aug 2026 18:50:52 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/81238.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 16 Mar 2015 01:30:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DNS forwarder question on Mon, 16 Mar 2015 01:34:26 GMT]]></title><description><![CDATA[<p dir="auto">No - All it means is that you should not add an allow rule on your WAN, thereby exposing port 53 to external traffic.</p>
<p dir="auto">If you want to check your service ports to see if port 53 is open or closed you can use:</p>
<p dir="auto">https://www.grc.com/x/ne.dll?bh0bkyd2</p>
]]></description><link>https://forum.netgate.com/post/527829</link><guid isPermaLink="true">https://forum.netgate.com/post/527829</guid><dc:creator><![CDATA[kejianshi]]></dc:creator><pubDate>Mon, 16 Mar 2015 01:34:26 GMT</pubDate></item></channel></rss>