Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Tutorials and FAQs
»
HOWTO - Redirect all DNS Requests to Opnsense
« previous
next »
Print
Pages:
1
2
[
3
]
4
5
...
8
Author
Topic: HOWTO - Redirect all DNS Requests to Opnsense (Read 143965 times)
yeraycito
Sr. Member
Posts: 288
Karma: 17
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #30 on:
January 29, 2022, 04:48:31 pm »
Other configuration:
https://www.sunnyvalley.io/docs/network-security-tutorials/how-to-configure-opnsense-firewall-rules#1-allowing-only-specific-dns-servers
Logged
RamSense
Hero Member
Posts: 594
Karma: 10
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #31 on:
January 29, 2022, 05:08:39 pm »
i have those redirect and block rules operating.
I thing that zenarmor/semsei is operating before those firewall rules(?)
Logged
ChrisChros
Full Member
Posts: 134
Karma: 5
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #32 on:
February 03, 2022, 10:50:51 am »
Is someone else facing problems with DNS redirection an Google Nest mini?
My Google Home mini is working as expected with the redirecting rules but the Nest mini not. The Nest is not able to establish an internet connection and stops working.
I tried with port forward rule only as well a combination of outbound and port forward, no luck with the Nest mini.
Any suggestions to fix this problem?
UPDATE:
So I think I have it now.
I checked all my port forward rules and realized that NAT reflection was set to "Use system default", this has to be set to "Disabled".
«
Last Edit: February 03, 2022, 05:40:23 pm by ChrisChros
»
Logged
XSK NUC Intel Celeron J3160 aka Protectli FW4B, 8GB RAM
OPNsense 22.1
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #33 on:
February 24, 2022, 11:26:14 pm »
I'm also trying to understand how this works and I have created the NAT-> port forward rule (attached) and the rule 1 has automatically been created.
The issue I have with my Google Chromecast is that it only works if I have rules 2 and 3, but my understanding was that I didn't need any addional rule, can someoen shed some light?
Tia.
Logged
tiermutter
Hero Member
Posts: 1094
Karma: 61
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #34 on:
February 25, 2022, 08:51:25 am »
Destination has to be negated ( ! ) as you want to redirect traffic whichs destination is NOT lanNet/ThisFirewall.
LAN TCP/UDP * * ! This Firewall 53 (DNS) 10.13.12.2 53 (DNS) Redirect DNS to this Firewall
LAN TCP/UDP * * ! This Firewall 53 (DNS) fd00:10:13:12::2 53 (DNS) Redirect v6 DNS to this Firewall
Logged
i am not an expert... just trying to help...
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #35 on:
February 25, 2022, 10:02:25 am »
@tiermutter
I guess you're referring to the port forward rule, right? In that case, it's been negated (see screenshot) -
! LAN address
- or you mean something elese?
Logged
tiermutter
Hero Member
Posts: 1094
Karma: 61
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #36 on:
February 25, 2022, 10:28:47 am »
huh?! Sorry... watched the secreenshots on the smartphone, looks like I mixed up something.
I remember I had problems using loopback IP for redirect to, thats why I use the LAN interface IP instead.
Logged
i am not an expert... just trying to help...
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #37 on:
February 25, 2022, 10:44:03 am »
Ah no worries, I will change the loopback address with the address of my firewall and will see if any better, will keep you posted.
Thanks.
Logged
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #38 on:
February 25, 2022, 08:50:22 pm »
Yes, after changing the loopback address also my Goolge chromcast is working
Logged
ChrisChros
Full Member
Posts: 134
Karma: 5
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #39 on:
February 25, 2022, 10:44:40 pm »
@hushcoden
Can you please share a picture of your now working rules.
Logged
XSK NUC Intel Celeron J3160 aka Protectli FW4B, 8GB RAM
OPNsense 22.1
hushcoden
Hero Member
Posts: 544
Karma: 23
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #40 on:
February 25, 2022, 10:50:19 pm »
Two attachments, one for the port forward and one for the LAN rule, which is automatically created.
Logged
tiermutter
Hero Member
Posts: 1094
Karma: 61
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #41 on:
February 25, 2022, 11:01:36 pm »
Don't forget the rules for IPv6, if it's not disabled...
Logged
i am not an expert... just trying to help...
ChrisChros
Full Member
Posts: 134
Karma: 5
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #42 on:
February 26, 2022, 09:13:26 am »
comprehension questions, what is the difference between "127.0.0.1" and "This Firewall"?
Logged
XSK NUC Intel Celeron J3160 aka Protectli FW4B, 8GB RAM
OPNsense 22.1
tiermutter
Hero Member
Posts: 1094
Karma: 61
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #43 on:
February 26, 2022, 10:54:01 am »
Im not really sure, but I think "this firewall" contains all interface IPs of the firewall. All client traffic passing the firewall will be destinated to this firewall / an interface IP or to another network, but can never be destinated to a loopback address.
Logged
i am not an expert... just trying to help...
skyfighter
Newbie
Posts: 5
Karma: 1
Re: HOWTO - Redirect all DNS Requests to Opnsense
«
Reply #44 on:
March 19, 2022, 11:04:52 am »
Hi, many thanks for this HowTo, works flawlessly for me.
Would it be possible to add a similar Redirect rule for NTP service port 123 so that Opnsense NTP server will only be used?
Logged
Print
Pages:
1
2
[
3
]
4
5
...
8
« previous
next »
OPNsense Forum
»
English Forums
»
Tutorials and FAQs
»
HOWTO - Redirect all DNS Requests to Opnsense