OPNsense Forum

Archive => 18.7 Legacy Series => Topic started by: cclloyd on September 20, 2018, 06:25:53 am

Title: Unbound DNS not resolving for external connections
Post by: cclloyd on September 20, 2018, 06:25:53 am
I'm using unbound DNS as my DNS for my OPNSense installation.  The interface for it is set to all, but for some reason it won't resolve for external connections. 

Like I have an override:

Name: bt
Domain: example.com
Host: 10.0.1.11
Type: A

And when I try to access the host on my network it works just fine.  But when I try it from anything outside my network, it fails to connect.
Title: Re: Unbound DNS not resolving for external connections
Post by: marjohn56 on September 20, 2018, 10:37:49 am
What are you trying to do exactly?


Are you trying to connect to a device on your LAN from the WAN?
Title: Re: Unbound DNS not resolving for external connections
Post by: cclloyd on September 20, 2018, 12:24:33 pm
Yes. 
Title: Re: Unbound DNS not resolving for external connections
Post by: marjohn56 on September 20, 2018, 12:36:38 pm
You cannot do it that way...


When your device (mobile phone etc ) is connected to the WAN i.e. via mobile or external wifi, coffee shop etc it uses their DNS servers. You have to set up a DNS entry at your domain host. If you have a static WAN IP address you should be able to set up an entry pointing at your WAN IP, if you have a dynamic WAN IP address you will need to use a dynamic DNS service such as DynDNS.


You will also then need to port forward whatever ports you need through the firewall. If you are trying to use OpenVPN to connect to your LAN, then you just enter your WAN IP or FQDN in the client.
Title: Re: Unbound DNS not resolving for external connections
Post by: cclloyd on September 21, 2018, 12:23:12 am
I do have a static IP.  My domain is through google domains.
Title: Re: Unbound DNS not resolving for external connections
Post by: ab5g on September 21, 2018, 03:29:29 am
Ok - are you trying to connect to your DNS server (which is running on Opnsense) over the WAN and use it to resolve the IP's ?
If yes then do you plan to

1. Access the DNS server over a VPN (perhaps SSL)
2. Access the DNS server over internet - (Isn't the recommended approach)

In both cases you need to complete the 2 steps
1.  Tell the  DNS server to listen for requests on different interfaces - Services: Unbound DNS: General:Network Interfaces.
2. Allow DNS to respond to Services: Unbound DNS: Access Lists