OPNsense Forum

Archive => 24.1, 24.4 Legacy Series => Topic started by: Mayo132 on May 30, 2024, 04:10:32 PM

Title: How to handle DNS Queries / Or switch Topology
Post by: Mayo132 on May 30, 2024, 04:10:32 PM
Hey everyone,

at the moment iam dealing with some sporadic DNS problems (timeouts, or answering at the second request).


So it seems to me that there could be a limitation in DNS Queries.

The network was first designed for about 20 people, and now from time to time more people using this network.

Attached to this post, i've added the topology of my network.

At the moment there are about 80 people using the internet.

The ISP only offers 2 connections with each 100/40Mbit, but there is a plan to switch to a fiber internet (but this is not available at the moment)

At the Baseground (V1) is located:


At the OpnSense firewall iam using a traffic shaper to prioritize the "important" traffic, like Video Calls or Phone Calls.

But now, there are some timeouts in the DNS queries.
First i tried to switch all DNS Queries to the seperate DNS Server (Adgaurd) > The timeouts increases
Then i switched to "Primary AdGuard" and "Secondary Opnsense" > This is now working

Is there any recommendation (Best Practise) how, to deploy DNS Servers ?
> There is no local Active Directory Server - All Users are managed by Azure Active Directory.

Thanks a lot.

Mario
Title: Re: How to handle DNS Queries / Or switch Topology
Post by: va176thunderbolt on May 30, 2024, 09:42:04 PM
I'd start with grabbing some packet captures of the DNS traffic at the firewall and see if the issue is internal or external.