Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Does a DNS firewall redir rule take precedence over DNS query forward?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Does a DNS firewall redir rule take precedence over DNS query forward? (Read 945 times)
tdalej
Newbie
Posts: 46
Karma: 0
Does a DNS firewall redir rule take precedence over DNS query forward?
«
on:
January 19, 2024, 09:21:29 pm »
If a query forward for a specific domain exists in unbound AND a redirect for all DNS queries are redirected to 127.0.0.1, which takes precedent?
Logged
cookiemonster
Hero Member
Posts: 1823
Karma: 95
Re: Does a DNS firewall redir rule take precedence over DNS query forward?
«
Reply #1 on:
January 19, 2024, 10:51:13 pm »
https://docs.opnsense.org/manual/firewall.html
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Does a DNS firewall redir rule take precedence over DNS query forward?
«
Reply #2 on:
January 19, 2024, 11:00:54 pm »
You are confusing layers. The firewall rule directs the queries at the service listening on 127.0.0.1, nothing more, nothing less.
Whatever service that is will handle the request. If that is Unbound it will apply the forward for a particular domain. If it is a different one it will do whatever it is configured to do.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cookiemonster
Hero Member
Posts: 1823
Karma: 95
Re: Does a DNS firewall redir rule take precedence over DNS query forward?
«
Reply #3 on:
January 19, 2024, 11:04:49 pm »
I misread the question, apologies.
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Does a DNS firewall redir rule take precedence over DNS query forward?
«
Reply #4 on:
January 19, 2024, 11:14:09 pm »
My answer was directed at the OP.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
tdalej
Newbie
Posts: 46
Karma: 0
Re: Does a DNS firewall redir rule take precedence over DNS query forward?
«
Reply #5 on:
January 19, 2024, 11:43:21 pm »
Thank you both!
I thought it would work this way:
Any network covered by the rule would intercept DNS requests and send the to loopback (local DNS)
Unbound, being the local DNS would then (based on a redirect) send a query to the specified DNS server on a domain match.
If that's a correct statement, something on OPNSense is still blocking traffic between networks behind the firewall.
I'll try RTFM'ing the doc that cookiemonster pointed to.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Does a DNS firewall redir rule take precedence over DNS query forward?