pfSense English Support > Installation and Upgrades

Upgrade 2.4.0: firewall rule with alias and FQDN not working anymore

(1/8) > >>

ggzengel:
After upgrade the ports are closed.

Diagnostic->Ping is working.
I saved the alias again to force dns lookup.
still unchecked (never enabled before): Do not use the DNS Forwarder/DNS Resolver as a DNS server for the firewall
I use DNS Forwarder.
After changing the alias to IP it's working but not preferred.


--- Code: --- <alias>
<name>smtp_server</name>
<type>host</type>
<address>smtp.domain.local</address>
<descr><![CDATA[SMTP Server]]></descr>
<detail><![CDATA[Entry added Fri, 14 Sep 2012 13:58:06 +0000]]></detail>
</alias>
--- End code ---


--- Code: --- <rule>
<id></id>
<type>pass</type>
<interface>opt2</interface>
<tag></tag>
<tagged></tagged>
<max></max>
<max-src-nodes></max-src-nodes>
<max-src-conn></max-src-conn>
<max-src-states></max-src-states>
<statetimeout></statetimeout>
<statetype><![CDATA[keep state]]></statetype>
<os></os>
<protocol>tcp</protocol>
<source>
<any></any>
</source>
<destination>
<address>smtp_server</address>
<port>25</port>
</destination>
<descr><![CDATA[SMTP Server]]></descr>
<tracker>1460899172</tracker>
</rule>
--- End code ---

pauby:
I have EXACTLY the same issue although I'm using DNS Resolver and not DNS Forwarder. As many many of my rules rely on aliases (and names) it's broken the best part of my network.

ggzengel:
I opened a bug for this: https://redmine.pfsense.org/issues/7958

johnpoz:
You opened a bug report with ZERO info to suggest it is..

So you have an alias for smtp.domain.local as a fqdn in it..

Does this resolve?  Simple query to pfsense for that fqdn should show you if pfsense can resolve it.  Or simple dns lookup under diag.

What does the table for your alias show also under diag..  As the comment in the bug you created states.. They can not duplicate your problem, nor can I..

Where should smtp.domain.local resolve?  Is this a host override on pfsense?  reservation in dhcp that you have register in forwarder/resolver?  Is it some downstream dns that should resolve that?  If so do you have a domain override in place so pfsense knows where to go ask for smtp.domain.local?

ggzengel:
Can you read?

> Diagnostic->Ping is working.

And it worked before update!

Navigation

[0] Message Index

[#] Next page

Go to full version