OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • [SOLVED] get rid of host forgery detected
« previous next »
  • Print
Pages: 1 [2]

Author Topic: [SOLVED] get rid of host forgery detected  (Read 15960 times)

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: [SOLVED] get rid of host forgery detected
« Reply #15 on: May 07, 2019, 06:56:31 pm »
Quote from: mimugmail on May 02, 2019, 11:19:54 am
Do you use IPv6 (or are you aware of it)? I had a similar problem where clients and proxy use the same v4 DNS, but the client did the DNS via v6 and then there were again forgery attacks :)
Right. I use ipv6. How did you resolve this issue? The clients are dual stack, as firewall itself. Firewall acts as ipv6 dns server (unbound). Firewall itself just has ipv4 addresses configured for dns servers. Should I add the ipv6 ips of dns servers, too?
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: [SOLVED] get rid of host forgery detected
« Reply #16 on: May 07, 2019, 08:23:49 pm »
Port forward for v6 Port 53 to localhost :)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: [SOLVED] get rid of host forgery detected
« Reply #17 on: May 07, 2019, 08:50:01 pm »
Quote from: mimugmail on May 07, 2019, 08:23:49 pm
Port forward for v6 Port 53 to localhost :)
How dies this work? This would violate ipv6 scope.
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=193568
For this reason, I use the interface ipv6 address for redirect in transparent proxy.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: [SOLVED] get rid of host forgery detected
« Reply #18 on: May 07, 2019, 08:54:21 pm »
Hm, I'm quite sure it works, will test it tomorrow
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • [SOLVED] get rid of host forgery detected
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2