OPNsense Forum

English Forums => General Discussion => Topic started by: lmnsour on March 04, 2023, 07:45:13 pm

Title: Microsoft Broken
Post by: lmnsour on March 04, 2023, 07:45:13 pm
For some reason I can't connect with Microsoft sites any updates.  Answers.microsoft.com doesn't work and can't connect to Microsoft update servers. 

How do I troubleshoot this?

I disabled Suricata, ZenArmor, and Unbound DNS. 

Currently I have Unbound DNS connected to Cloudflare DNS over TLS.

I have a firewall rule to rout all DNS queries through OPNSENSE.  Until about a week ago, I didn't have any issues so maybe this is from a recent update?
Title: Re: Microsoft Broken
Post by: bartjsmit on March 05, 2023, 12:55:03 pm
How do I troubleshoot this?
maybe this is from a recent update?
Microsoft community works for me with the latest OPNsense.

Simplify your setup by setting your client to external DNS directly (1.1.1.1 if you want to stick to Cloudflare) to confirm your issue is with DNS

Bart...
Title: Re: Microsoft Broken
Post by: lmnsour on March 05, 2023, 08:24:54 pm
I disabled Unbound DNS and reconfigured OPNSENSE settings for the DNS server and nothing worked.  Had to re-enable Unbound DNS to get connection back.
Title: Re: Microsoft Broken
Post by: lmnsour on March 06, 2023, 08:29:43 am
I disabled Unbound DNS and reconfigured OPNSENSE settings for the DNS server and nothing worked.  Had to re-enable Unbound DNS to get connection back.

So if I disable unboundDNS and disable the DNS over TLS, then manually put the DNS servers into System -> Settings -> General, I get not connection at all.

Did something get corrupted?
Title: Re: Microsoft Broken
Post by: Patrick M. Hausen on March 06, 2023, 08:47:18 am
You will need to refresh the client's DHCP lease, so it picks up the new DNS settings. Also check your DHCP configuration for explicitly specified DNS servers. If you disable Unbound, it cannot serve clients.
Title: Re: Microsoft Broken
Post by: lmnsour on March 06, 2023, 06:04:39 pm
You will need to refresh the client's DHCP lease, so it picks up the new DNS settings. Also check your DHCP configuration for explicitly specified DNS servers. If you disable Unbound, it cannot serve clients.
Ahh, yeah I figured.

I'm just using the cloudflare DNS servers over TLS but I have a firewall rule to route all DNS queries to the firewall.  I think this is what broke MS downloads / MS sites.

How do I go about fixing these.  I saw a thread about adding MS certs to the Authorities but it wasn't clear and I don't want to bugger anything up without first getting more info.
Title: Re: Microsoft Broken
Post by: aleks222 on March 08, 2023, 01:11:04 pm
Mine also crashed recently. To be honest, there have been some problems lately
Title: Re: Microsoft Broken
Post by: Patrick M. Hausen on March 08, 2023, 01:22:36 pm
How do I go about fixing these.
Sorry, no idea. I do not mess with Microsoft products talking to Microsoft, Apple products talking to Apple, etc. If I was concerned I would not be running Windows, plain and simple.

Keeping systems maintained and up to date is far more important from a security standpoint.

Kind regards
Patrick
Title: Re: Microsoft Broken
Post by: lmnsour on March 16, 2023, 09:28:43 pm
How do I go about fixing these.
Sorry, no idea. I do not mess with Microsoft products talking to Microsoft, Apple products talking to Apple, etc. If I was concerned I would not be running Windows, plain and simple.

Keeping systems maintained and up to date is far more important from a security standpoint.

Kind regards
Patrick

This issue for me is with the Firewall rule that re-directs all DNS queries to Opnsense. Microsoft doesn't like this for some reason. Again, I think it can be fixed / configured under System-> Trust -> Authorities / Certificates but I'm still reading up on how to set this up for Microsoft.

In the meantime, I manually set my DNS on my computer and disabled the Firewall rule.
Title: Re: Microsoft Broken
Post by: Patrick M. Hausen on March 16, 2023, 10:03:25 pm
Are you using some overly zealous DNS blocklists, possibly?
Title: Re: Microsoft Broken
Post by: noviceiii on March 19, 2023, 08:06:43 pm
I have the same issue here: a few Microsoft services to not work, if the opensense Unbound DNS server is used.

For now, I've added public DNS servers to the be distributed by DHCP (Services -> DCPv4 -> LAN -> DNS Servers) to the local clients which can therefore lookup directly.

I haven't investigated any further but I guess, it is an issue that Microsoft wants to connect through DNS 853 (SSL/TLS).
Title: Re: Microsoft Broken
Post by: noviceiii on March 19, 2023, 09:21:19 pm
ok.. I DID investigate. It was the blocklist.
Title: Re: Microsoft Broken
Post by: siatraneagic1978 on May 18, 2023, 06:06:55 pm
It's possible that the recent changes you made to your network configuration could be causing the issue. To troubleshoot, check your firewall rules and DNS settings to ensure they're properly configured for Microsoft services. If you're still facing difficulties, contacting Microsoft support or consulting with network professionals could be helpful. By the way, if you're looking to enhance your Microsoft knowledge, consider exploring Trainocate's microsoft training (https://trainocate.com.my/product-category/microsoft/) courses. They offer a range of courses that can help you navigate and troubleshoot such technical challenges effectively.
Title: Re: Microsoft Broken
Post by: noviceiii on May 24, 2023, 12:22:59 am
Thank you for the suggestion. But, although I make damage in various ways, it wasn't because of that. This time :-)

It was blocked by one of the unboundDNS DNSBL blocklists. 

As I figured, I guess, it was mainly my understanding of the use of wildcards for the whitelist that was not in line of how opnsense understands it. And, there where 2 or 3 list items, I've added directly manualy from the block log (m.hotmail, outlook.office365 and officeclient.microsoft if I remember right).

n3