Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Packages» Just cannot get tinydns to work...
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: Just cannot get tinydns to work...  (Read 2027 times)
0 Members and 1 Guest are viewing this topic.
p0ddie
Jr. Member
**
Offline Offline

Posts: 47


View Profile
« on: February 18, 2011, 10:06:23 am »

Hi,

I can't get tinyDNS to work as my internal dns server, no matter how hard I try. I deleted and readded the package, tried with different domains.. no luck.

2.0BETA5, build 16th of February.

Here's what I set up:

- installed tinyDNS package
- deactivated DNS forwarder
- under general prefs, set the dns IP to the IP of pfsense (192.168.1.1), gave my appliance the hostname it will user later: pfsense.domain.internal

- Used the tinyDNS wizard to set up the domain domain.internal
- the wizard added domain.internal as SOA, I added pfsense.domain.internal as A record with IP 192.168.1.1 and as NS record
- put the listening ip of tinydns to 127.0.0.1, listen to LAN and loopback (tried WAN, too)
- put in a firewall rule to allow all LAN traffic on UDP 53 (DNS)
- started the service, restarted the appliance

Interestingly, in the tinyDNS log i saw stuff it tried to resolve like "www.google.com.domain.internal".

I am not that experienced with tinyDNS or pfsense, but I am quite sure I set up everything correctly...

What can I do?
Logged
firewold
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #1 on: February 20, 2011, 11:31:04 am »

Should be listening on LAN and no port 53 open needed.  Be sure to untick allow DNS server to be overridden in General settings
« Last Edit: February 20, 2011, 11:34:54 am by firewold » Logged
Gloom
Full Member
***
Offline Offline

Posts: 196


View Profile
« Reply #2 on: February 21, 2011, 11:11:15 am »

You do need to setup a port forward for port 53 from the LAN IP address (Assuming internal DNS) through to the loopback address you bound TinyDNS to.
You might also need a firewall rule to permit UDP traffic through to loopback on port 53

For testing try running the following on any Unix/Linux box on your network

dig @192.168.1.1 "Whatever your Domain" any

That should return all the stuff you have setup.
Logged

Never underestimate the power of human stupidity
firewold
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #3 on: February 21, 2011, 01:43:42 pm »

There must be something wrong with my settings.  Port 53 is explicitly blocked in my system and TynyDNS is still working.
Logged
Gloom
Full Member
***
Offline Offline

Posts: 196


View Profile
« Reply #4 on: February 22, 2011, 03:13:34 am »

Odd as the default LAN rule only allows traffic on ports 80 and 22. Can your LAN computers make DNS requests outside of the network eg OpenDNS 208.67.222.222.
If so your rules are wrong or in the wrong order.
Logged

Never underestimate the power of human stupidity
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.031 seconds with 19 queries.