OPNsense Forum

English Forums => 25.7, 25.10 Series => Topic started by: dunxd on December 17, 2025, 09:04:42 AM

Title: DNS lookups by opnsense server
Post by: dunxd on December 17, 2025, 09:04:42 AM
I use pihole as the DNS server on my network, with all clients told to use it via DHCP from DNSmasq running on my OPNsense box.

Daily I get warnings about rate limiting being applied to my OPNsense router's IP address, and OPNsense is making over 50% of DNS requests.

I have configured OPNsense to use only upstream DNS servers on the Settings > General page, and again for Zenarmor's DNS enrichment setting - so I would not expect the OPNsense server to be doing any DNS lookups via pihole at all.

Is there somewhere else that OPNsense might be configured to do DNS lookups?
Title: Re: DNS lookups by opnsense server
Post by: meyergru on December 17, 2025, 09:42:29 AM
You can check the outbound DNS requests by using a tcpdump on the WAN interface for UDP port 53 and see who and what it being asked to get an idea of what it can be.