OPNsense Forum

Archive => 24.1, 24.4 Legacy Series => Topic started by: Alec246 on April 24, 2024, 12:57:10 AM

Title: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 24, 2024, 12:57:10 AM
So, I am getting these log errors whenever I try to access SPotify on my Cellphone via my WiFi AP connected to Opnsense.

"dhcpd leases: NODE_WIFI_ec:a9:40:29:be:f5 not a valid hostname, ignoring"

This is generated by my Deco TP-Link XE75 Node Wifi, where my Phone is connected to.

I read underline might be the problem, but there is nothing I can do to change the Deco device. So how can I tell Unbound to accept this kind of hostname?

Thank you!
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: netnut on April 24, 2024, 02:44:01 AM
Quote from: Alec246 on April 24, 2024, 12:57:10 AM
So how can I tell Unbound to accept this kind of hostname?

Provide a valid hostname. Underscores don't belong in hostnames  on "The Internet" and so DNS (only with some obscure Operating Systems)

https://www.rfc-editor.org/rfc/rfc952 and it's update https://www.rfc-editor.org/rfc/rfc1123


And in case you wonder: What about a DNS service record with underscores ? That's not a hostname..

Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 24, 2024, 01:42:20 PM
Hi! Thank you for your reply.

It doesnt seem to be a way to me to control how the TP-Link Deco unit creates its hostnames. Unless I could modify it somehow later down the path?

I find very weird that nobody had this issue so far? The TP-Link Deco is one of the biggest selling Mesh Units available, and to find out it doesn't work properly with OPNSense and there isnt anything that could be done is shocking.

The previous Routers never complained, which is even more strange. I had the ISP one, and an Asus RT-AX86U, both Stock and Merlin Firmware. All worked fine?

I really hope this doesnt leave me with just the option of needing to change my OPNSense to another solution, because i really wanted to make it work in our home, but I cant have all my Wifi devices full of issues.
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Patrick M. Hausen on April 24, 2024, 02:59:22 PM
So the "NODE_WIFI_ec:a9:40:29:be:f5" hostname is your TP-Link device or your Spotify client/server/whatever?
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 24, 2024, 07:46:21 PM
Quote from: Patrick M. Hausen on April 24, 2024, 02:59:22 PM
So the "NODE_WIFI_ec:a9:40:29:be:f5" hostname is your TP-Link device or your Spotify client/server/whatever?

This is what is shown to me in the OPNSense ARP Table

192.168.50.111   ec:a9:40:29:be:f5   ARRIS Group, Inc.   igc1   lan   NODE_WIFI_ec:a9:40:29:be:f5

What is weird is that that Arris made my TV Box? THe ISP is Fiber going from the OTN to the ISP Router, then a Lan going from the ISP Router to the TV Box. And the ISP Router is Bridge mode going to OPNSense
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Patrick M. Hausen on April 24, 2024, 07:56:33 PM
My question was aming at ... how is using spotify depending on registering that hostname? Is that hostname "the spotify box"? I have no idea how spotify works, just know a bit about DNS or two ...

Why must that hostname be registered in Unbound?
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 24, 2024, 08:23:06 PM
What I noticed since we switched to OPNSense, is that Twitter App stopped loading the images, and the videos, when both my wife and my Phones are connected to the Wifi. Spotify just doesnt work at all, loads as Offline Mode.

And whenever I try playing a music at Spotify Android App, a new Log shows on like that entry on my Unbound DNS log.

I confirmed the Mac Address is from my TV Box, which is actually IPTV.

I wonder how that could be getting in the way of my Cellphones Wifi?
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Patrick M. Hausen on April 24, 2024, 08:33:06 PM
Yes, but these two things are probably entirely unrelated.

Internal lookup is not a prerequisite for twitter or spotify to work. And the log message is really just a notification, nothing serious.

Could you explain your setup in a bit more detail? Are you using any DNS blocklists, IDS/IPS, or stuff like that? Or are you running with the default "permit everything out from LAN" rule?

Also is that WiFi connected to LAN and is the access point configured in bridge mode or is there anything special?

Kind regards,
Patrick
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 25, 2024, 12:34:47 AM
Thank you for the help Patrick,

My network is my ISP Router as Bridge. That goes into my OPNSense Machine. Then goes to a MikroTik Switch, from that a cable to my TPLink Deco AP, which is set as Access Point, DHCP turned off. The TV Box is not connected to the Switch, it is still connected to the ISP Modem.

Nothing fancy enabled, I just followed the basic tutorial, enabled DHCP only on OPNSense, no Firewall, All allowed. Tried both ISP DNS, and Custom DNS, no difference.

I read that my IPTV TV Box might be flooding my network due to me not doing VLANs, or other Multicast stuff I really dont know how to do. But I am not sure if this would be the reason of my Wifi devices misbehaving.
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 25, 2024, 10:00:15 PM
After spending hours on this, I am thinking there may be a Firewall Rule blocking out these Music Streaming Apps?

Spotify doesnt work, Prime Music doesnt work. Should I enable specially rules for specific Apps I Want in OPNSense?
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Patrick M. Hausen on April 25, 2024, 10:58:33 PM
The default installation of OPNsense permits everything originating from your LAN.
Title: Re: Unable to use Certain Apps via WiFi due to Unbound DNS
Post by: Alec246 on April 26, 2024, 12:11:35 AM
Found the issue Patrick,

It was IPv6, which made my cellphones have issues with these apps. I saw this post and decided to try, IPv4 only and its back on!

https://forum.opnsense.org/index.php?topic=32674.0

Now i have to investigate why that is happening here!