Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Block an interface from resolving IPs of public internet addresses

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 6 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      paulanand
      last edited by

      In my setup I have 2 VLANs, Workstations and Servers. All the hosts are statically mapped with hostname.

      What I would like to do?

      • All local machines to be able to resolve the other local machines

      • Only workstations to be able to resolve public addresses (basically have internet access)

      • Servers not to be able to resolve public addresses (basically not have internet access)

      What have I done?

      • Checked Register DHCP static mappings in the DNS Resolver

      • Setup firewall rule on WORKSTATION interface to allow traffic from WORKSTATION net to This Firewall on port 53

      • Setup firewall rule on SERVER interface to allow traffic from SERVER net to This Firewall on port 53

      • Setup firewall rule on SERVER interface to block traffic from SERVER net to WAN net

      What I observed?

      • Hosts on the WORKSTATION net was able to resolve local hostnames and public addresses

      • Hosts on the SERVER net was able to resolve local hostnames and public addresses

      • Hosts on the SERVER net was not able connect to the internet but on the host it says it has Internet access

      1 Reply Last reply Reply Quote 0
      • 2 Offline
        2chemlud Banned
        last edited by

        Hmmm, what exactly is your question now?

        1 Reply Last reply Reply Quote 0
        • P Offline
          paulanand
          last edited by

          I have allowed host1 to connect to pfsense dns. When I do this, host1 can resolve the ip address of public network (for example google.com) and my private network (mydomain.com). But host1 can't access the internet

          What should I do such that host1 can only resolve ip address of my private network? The reason that I want to do this is because on my host1 it shows that it has internet access.

          1 Reply Last reply Reply Quote 0
          • 2 Offline
            2chemlud Banned
            last edited by

            do not allow host1 for port 53. resolving the local net you can't disable anyway.

            ("The reason that I want to do this is because on my host1 it shows that it has internet access." Windows? Symbol for network in the lower right corner? Don't care about that… But no updates then, huh?)

            1 Reply Last reply Reply Quote 0
            • P Offline
              paulanand
              last edited by

              If I block host1 from accessing the This firewall on port 53 (DNS), I cant resolve local net hostnames.

              But if you say it is okay that windows shows internet access, then I guess there is no problem.

              Nevertheless, thank you for the information.

              1 Reply Last reply Reply Quote 0
              • 2 Offline
                2chemlud Banned
                last edited by

                … I reach my local resources via IP. As long as Windows can resolve names via DNS it will show "online" status, my guess. But you won't get any updates without internet access. Is it http or https that's needed to retrieve Windows updates? Dunno...

                1 Reply Last reply Reply Quote 0
                • D Offline
                  doktornotor Banned
                  last edited by

                  There's bind with views feature and this blackhole thing.

                  1 Reply Last reply Reply Quote 0
                  • 2 Offline
                    2chemlud Banned
                    last edited by

                    2nd link non-functional

                    TL;DR

                    what's the message? :-)

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      doktornotor Banned
                      last edited by

                      @2chemlud:

                      2nd link non-functional

                      Fixed.

                      @2chemlud:

                      TL;DR

                      what's the message? :-)

                      Huh? No, I'm not gonna rewrite the bind documentation here just because you cannot be bothered to read it.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        "Servers not to be able to resolve public addresses (basically not have internet access)"

                        So which is it do you want them not to resolve public or not have internet?  Who gives a shit if they resolve www.cnn.com from pfsense if they don't actually have internet access.  Simple firewall rule to not allow your server vlan internet access..  Just because you set up so they can not resolve www.cnn.com does not mean they cant just go http:\ipaddressofcnn for example.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 26.03 | Lab VMs 2.8.1, 26.03

                        1 Reply Last reply Reply Quote 0
                        • DerelictD Offline
                          Derelict LAYER 8 Netgate
                          last edited by

                          Or, worse, irc://84.85.86.87/ botnet command and control.

                          If you want to block access to the internet, block it.  Don't just block DNS and consider the job done.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            paulanand
                            last edited by

                            @Derelict:

                            Or, worse, irc://84.85.86.87/ botnet command and control.

                            If you want to block access to the internet, block it.  Don't just block DNS and consider the job done.

                            I have blocked internet access using firewall but allowed access to pfSense DNS.

                            Its just that on my Windows Servers, the icon says it has Internet access. Stupid question but, is this okay?

                            1 Reply Last reply Reply Quote 0
                            • H Offline
                              Harvy66
                              last edited by

                              Blocking DNS does not block access. There is this thing call IP, also known as Internet Protocol. Block this and the internet will stop working.

                              1 Reply Last reply Reply Quote 0
                              • 2 Offline
                                2chemlud Banned
                                last edited by

                                Is this the dyslexia thread? He ALLOWS DNS, but blocks internet access. headsheaking

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.