Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sarel@atlasict.co.za

#1
Quote from: Patrick M. Hausen on January 08, 2024, 02:27:35 PM
Clients ask some name server, OPNsense redirects the packet to your designated resolver. If that system is also connected to LAN, it will answer the client directly.

The client will ignore the answer because it's from a server it did not ask in the first place.

So you must NAT your client addresses somehow, so the replies go back to OPNsense which will then answer the client with a correct source address.

I have added an outbound NAT rule to get this to work

Interface:  LAN
Destination Port: 53
NAT Address: Interface Address