F5F Stay Refreshed Power Users Networks Are you experiencing confusion from pfSense? DNS issues are common.

Are you experiencing confusion from pfSense? DNS issues are common.

Are you experiencing confusion from pfSense? DNS issues are common.

L
ladymorepork
Posting Freak
791
05-20-2016, 07:47 PM
#1
I've set up a standard WAN connection on pfSense with several VPN gateways. I've enabled DNS resolver, turned off DNS DHCP override, and set Google DNS as the default resolver. The issue lies in DNS queries—my home devices still rely on my ISP DNS, but some machines show different results during leak tests. One device resolves to my ISP while another goes to my VPN DNS. No configuration changes seem to be causing this inconsistency.
L
ladymorepork
05-20-2016, 07:47 PM #1

I've set up a standard WAN connection on pfSense with several VPN gateways. I've enabled DNS resolver, turned off DNS DHCP override, and set Google DNS as the default resolver. The issue lies in DNS queries—my home devices still rely on my ISP DNS, but some machines show different results during leak tests. One device resolves to my ISP while another goes to my VPN DNS. No configuration changes seem to be causing this inconsistency.

L
Liam_M_5000
Member
72
05-21-2016, 03:55 AM
#2
When using VPN tunnels, DNS settings on the tunnel side are typically set to forward all traffic through the tunnel rather than handling DNS at the exit. This prevents DNS lookups from occurring. In pfSense's configuration, DNS values inside the tunnel don't affect the setup if you're routing every traffic—including UDP 53—through the VPN. You can usually define the DNS servers for the tunnel itself.
L
Liam_M_5000
05-21-2016, 03:55 AM #2

When using VPN tunnels, DNS settings on the tunnel side are typically set to forward all traffic through the tunnel rather than handling DNS at the exit. This prevents DNS lookups from occurring. In pfSense's configuration, DNS values inside the tunnel don't affect the setup if you're routing every traffic—including UDP 53—through the VPN. You can usually define the DNS servers for the tunnel itself.