Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
DHCP and DNS
»
DNS Forwarder: Port Shut?
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: DNS Forwarder: Port Shut? (Read 896 times)
0 Members and 1 Guest are viewing this topic.
tlum
Jr. Member
Offline
Posts: 44
DNS Forwarder: Port Shut?
«
on:
June 21, 2012, 07:42:27 pm »
I'm trying to start using the DNS Forwarder in pfSense. My internal DNS servers - which also answer recursive external queries - are on one internal subnet. Its kind of annoying to have to go in and set up rules on all the other subnets to pass traffic to the DNS servers. I was hoping to let pfSense magically proxy that traffic. However, all the DNS queries return ICMP - udp port 53 unreachable which usually means the port is shut.
So jumping to conclusions I would guess the forwarder is behind the firewall filters and each subnet is going to need filter rules to allow DNS traffic to pfSense so the DNS Forwarder will work?
Is there any documentation on the setup of DNS Forwarder? From what I've seen it makes it sound like you just enable the check box and it just magically works but I'm finding that not to be the case.
So DNS Forwarder is not going to help me because I have to set up rules on every subnet anyway so I might as well not use it?
Logged
cmb
Administrator
Hero Member
Offline
Posts: 6032
Re: DNS Forwarder: Port Shut?
«
Reply #1 on:
June 21, 2012, 09:19:26 pm »
With any service, you have to permit traffic to reach it via the firewall for it to work. There are ways to ease that process, with interface groups, or floating rules.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
tlum
Jr. Member
Offline
Posts: 44
Re: DNS Forwarder: Port Shut?
«
Reply #2 on:
June 21, 2012, 09:49:28 pm »
Well, sounds like it won't reduce the number of rules to manually maintain so its best not to use it in this case because its an increase in complexity with no benefit [for me]. Thanks
Logged
cmb
Administrator
Hero Member
Offline
Posts: 6032
Re: DNS Forwarder: Port Shut?
«
Reply #3 on:
June 22, 2012, 01:14:27 pm »
As I said, use interface groups or floating rules. You can do that with 1 rule.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
tlum
Jr. Member
Offline
Posts: 44
Re: DNS Forwarder: Port Shut?
«
Reply #4 on:
June 22, 2012, 06:27:28 pm »
That being the case I can "allow" to the local DNS servers with one rule too. I think the main argument for DNS Forwarder is split horizon where you have to proxy DNS requests to different servers. Since all of my DNS queries are answered by one set of servers regardless of whether its an internal or external domain, DNS Forwarder offers no real benefit [that I can see] and would contribute to the complexity of the setup... the rules are really a wash.
Logged
cmb
Administrator
Hero Member
Offline
Posts: 6032
Re: DNS Forwarder: Port Shut?
«
Reply #5 on:
June 23, 2012, 09:54:50 am »
Where you already have internal DNS servers, the only benefit of the DNS forwarder is it may improve lookup performance since it'll query all its configured servers simultaneously and take the fastest response. Aside from that, it's mostly beneficial for networks that don't have any local DNS servers.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...