Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver Network Interfaces

    Scheduled Pinned Locked Moved DHCP and DNS
    5 Posts 5 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      Wheeler
      last edited by

      I am puzzled by one point in the setup configuration while installing pfSense for the first time. Specifically, in the section pertaining to "Services:DNS Resolver" for Network Interfaces, we are allowed to decide on "Interface IPs used by the DNS Resolver for responding to queries from clients." The options include these: All, WAN, LAN or Localhost. My question is why, under what circumstances, would I want to allow pfSense to respond to queries from the WAN? I mean, if I am not mistaken, would not all the clients be querying from the LAN, or possibly from Localhost depending on the setup. How or why would it be from the WAN?

      Could it be the case that I would allow a remote client to query the DNS server in pfSense if it were configured with a public facing WAN IP? Thanks.

      keyserK 1 Reply Last reply Reply Quote 0
      • N
        n3by
        last edited by

        If you don't open port 53 on WAN interface firewall then you don't have to worry.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Not what he was asking at all…  Yes Wheeler all setups are different, while I agree generally you wouldn't allow dns queries to your wan.  But maybe someone is using pfsense inside their network and not even natting and just using it as a downstream router/firewall..  And in that case maybe they want queries to the wan, etc..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • i64ruI
            i64ru
            last edited by

            Please tell me how to make the names of local computers have the original look and not p44-harc2-renfrew4.tch.dtn.ntl.com , ****.static.virginm.net
            Thanks!

            1 Reply Last reply Reply Quote 0
            • keyserK
              keyser Rebel Alliance @Wheeler
              last edited by

              @wheeler While I cannot recommend it😂, I have at times considered opening for DNS quieries on my Public IP/WAN interface. That way I could hardcode all my mobile clients to use my public IP as DNS, and “always” have the benefit of pfBlockerNG filtering. The browsable internet is borderline unusable under normal circumstances, once you have gotten use to such an effective add blocker :-)

              But don’t - use VPN instead.

              Love the no fuss of using the official appliances :-)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.