firewall allowing WAN to connect to Google DNS servers

Started by Inxsible, March 03, 2021, 07:18:05 AM

Previous topic - Next topic
QuoteI am only allowing the DNS to the opnsense server.
no.
you allow all traffic by "allow iot to any rule". you can try to enable logging on this rule and check logs
QuoteWhich brings me back to the question, why can't I disable/delete the auto-generated rules?
why do you want to block the request when it is already trying to exit the WAN? block on ingress interface: just block dns-traffic from iot-network to any except "this firewall"

Quote from: Fright on March 05, 2021, 07:03:42 AM
block on ingress interface: just block dns-traffic from iot-network to any except "this firewall"
I think the TS don“t want to just block DNS requests to WAN. He wants all DNS requests to be resolved by unbound, even if the devices have hardcoded DNS Servers.
i am not an expert... just trying to help...

I found Google APIs Client Library for PHP as part of the package php82-google-api-php-client.
Could this also be the cause?

the "cause" of this was a misconfugration on the firewall rules.