OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Constant DNS queries for opnsense.emergingthreats.net
« previous next »
  • Print
Pages: [1]

Author Topic: Constant DNS queries for opnsense.emergingthreats.net  (Read 1442 times)

nikon112

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Constant DNS queries for opnsense.emergingthreats.net
« on: January 30, 2023, 08:38:49 pm »
After enabling Unbound DNS reporting I am seeing over 40,000 DNS queries for opnsense.emergingthreats.net over the course of six hours.

I am using Unbound (no blocklist) on opnsense with DoT to nextdns.
The queries all Pass and come back NOERROR with the vast majority being answered from Cache.
Since the queries are mostly being answered from cache they don't show up on nextdns, which is why I had not noticed before.
To be clear the queries are also not being blocked by nextdns.

Is anyone else seeing this issue, or know how to fix it?

Thanks.
Logged

Fright

  • Hero Member
  • *****
  • Posts: 1777
  • Karma: 164
    • View Profile
Re: Constant DNS queries for opnsense.emergingthreats.net
« Reply #1 on: January 31, 2023, 01:04:58 pm »
using os-etpro-telemetry ids rules plugin?
"When you allow your OPNsense system to share anonymized information about detected threats - the alerts -
you are able to use the ETPro ruleset free of charge."
Logged

nanoguy

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: Constant DNS queries for opnsense.emergingthreats.net
« Reply #2 on: November 11, 2024, 11:21:18 pm »
Getting the same, only the number of queries is much larger for me. Anyone got any idea how to mitigate against this?
Logged

OpalALeslie

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: Constant DNS queries for opnsense.emergingthreats.net
« Reply #3 on: November 13, 2024, 06:00:39 am »
Quote from: nikon112 on January 30, 2023, 08:38:49 pm
After enabling Unbound DNS reporting I am seeing over 40,000 DNS queries for opnsense.emergingthreats.net over the course of six hours.


I am using Unbound (no blocklist) on opnsense with DoT to nextdns.
The queries all Pass and come back NOERROR with the vast majority being answered from Cache.
Since the queries are mostly being answered from cache they don't show up on nextdns, which is why I had not noticed before.
To be clear the queries are also not being blocked by nextdns.

Is anyone else seeing this issue, or know how to fix it?

Thanks.
Excessive DNS query issue for opnsense.emergingthreats.net within six hours when using Unbound DNS on OPNsense, while users search for solutions to minimize the continuously generated traffic.

poppy playtime chapter 3
« Last Edit: November 13, 2024, 09:46:34 am by OpalALeslie »
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6923
  • Karma: 583
    • View Profile
Re: Constant DNS queries for opnsense.emergingthreats.net
« Reply #4 on: November 13, 2024, 09:11:35 am »
Don't use Suricata?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

someone

  • Full Member
  • ***
  • Posts: 115
  • Karma: 2
    • View Profile
Re: Constant DNS queries for opnsense.emergingthreats.net
« Reply #5 on: November 21, 2024, 12:17:29 am »
Original question sounds like DNS or a misbehaving schedule possibly
Is your DNS sticking to its set IP
DNS settings in unbound
set your servers in system general
have the correct settings in unbound
« Last Edit: November 21, 2024, 01:13:10 am by someone »
Logged

someone

  • Full Member
  • ***
  • Posts: 115
  • Karma: 2
    • View Profile
Re: Constant DNS queries for opnsense.emergingthreats.net
« Reply #6 on: November 21, 2024, 12:56:46 am »
Are you behind a IPS router
Did you reset it before you went online
When you load opnsense, download your rules and apply them, and make your changes
I would create a snapshot and click it to be active, so thats what will be booted on the next powerup
After changes I would make another snapshot
Are you capturing packets or looking at them or the traffic
Once you set your DNS servers and reboot, look for your DNS server IP
Does your IPS let you select your own DNS or have to use theirs
Make sure let ISP over ride your settings is unchecked
Are you using firefox
In the settings under privacy and security
At the bottom check use your own DNS servers
Do you have a ET schedule activated
I am not getting that traffic
But I was getting DNS bombs, not any more
« Last Edit: November 21, 2024, 01:17:16 am by someone »
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Constant DNS queries for opnsense.emergingthreats.net
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2