1
24.1 Production Series / Re: SNMP interface indexing bug(?)
« on: May 15, 2024, 10:00:38 pm »
I am monitoring with librenms, but it does not detect it correctly, it puts it as a freebsd pc
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
same here!
I´m trying to costumize the ruleset with policies. But no matter what settings I use in the policy, it just have no effect on the alerts its generates.
I would be very happy about a solution
So i stumbled upon a rather correct and detailed guide on LabZilla (https://labzilla.io/blog/force-dns-pihole)
i tried out those rules and everything worked. I'm able to resolve domain names on both PiHole and the clients, and DNS is being redirected to my DNS server.
I was getting close with last post. Traffic wasn't going to where it was supposed to be. I had the first ruleCode: [Select]NAT Rule 1: Redirect DNS queries to PiHole
Interface: VLANTEST
Protcol: TCP/UDP
Source: VLANTEST net
Source Port range: From: Any - To: Any
Destination / Invert: Ticked
Destination: 192.168.99.11
Destination Port Range: From: DNS - To: DNS
Redirect Target IP: 192.168.99.11
Redirect Target Port: DNS
But what i mostly tried was to add a firewall rule to allow traffic from my DNS server. Instead, i needed to create another NAT rule, but without the port forwarding.Code: [Select]NAT Rule 2: Exempt PiHole from DNS query redirects (Above Rule 1)
.
No RDR (NOT): Ticked
Interface: VLANTEST
Protcol: TCP/UDP
Source: VLANTEST net
Destination: Any
Destination Port Range: From: DNS - To: DNS
I also added the 3rd rule the author described, to Firewall > NAT > Outbound. I'm not sure if i will come across it but i added it just to be sure.Code: [Select]NAT Rule 3: Prevent clients from giving unexpected source errors
Interface: VLANTEST
TCP/IP Version: IPv4
Protcol: Any
Source: VLANTEST net
Source Port range: Any
Destination: 192.168.99.11
Destination Port: DNS
Translation / Target: Interface address
Translation / Port: EMPTY
All in all, over a week of blood, sweat and tears, i finally got what i wanted.
I wrote to you privately
My license key was less than an hour and we are in the USA so there are some conversions that needed to be done.
Got an email that an order was placed, a few minutes later got an email that the order was accepted, and then some time later the key was emailed but the whole process was under an hour during their after work hours so the system must be working.