OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • HOWTO - Redirect all DNS Requests to Opnsense
« previous next »
  • Print
Pages: 1 2 3 [4]

Author Topic: HOWTO - Redirect all DNS Requests to Opnsense  (Read 75649 times)

Mks

  • Sr. Member
  • ****
  • Posts: 259
  • Karma: 19
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #45 on: March 19, 2022, 04:31:10 pm »
Quote from: skyfighter on March 19, 2022, 11:04:52 am
Hi, many thanks for this HowTo, works flawlessly for me.
Would it be possible to add a similar Redirect rule for NTP service port 123 so that Opnsense NTP server will only be used?

Yes, its basically the same.

br
Logged

ChrisChros

  • Full Member
  • ***
  • Posts: 124
  • Karma: 5
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #46 on: March 19, 2022, 10:38:32 pm »
I use a Port Forward rule to forward all NTP traffic, which is not coming from the firewall, to my OPNsense.
The interface local_Networks is an alias for all my lan and vlan, so I need only one rule.
« Last Edit: March 19, 2022, 10:40:20 pm by ChrisChros »
Logged
XSK NUC Intel Celeron J3160 aka Protectli FW4B, 8GB RAM
OPNsense 22.1

hushcoden

  • Sr. Member
  • ****
  • Posts: 383
  • Karma: 17
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #47 on: March 21, 2022, 07:00:24 pm »
I found this article https://www.derekseaman.com/2021/04/how-to-redirect-hardcoded-dns-to-opnsense.html and it's slightly different as it also considers the source address, why is that and which solution is better?

Tia.
Logged

hushcoden

  • Sr. Member
  • ****
  • Posts: 383
  • Karma: 17
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #48 on: March 30, 2022, 10:30:43 am »
I'd really like to understand what the difference in using as source address 'any' vs !firewall_ip_address ?!?

Tia.
Logged

tiermutter

  • Sr. Member
  • ****
  • Posts: 483
  • Karma: 25
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #49 on: March 30, 2022, 02:01:34 pm »
"!firewall_ip" as source takes care (or should to) that the firewall itself can use any DNS servers without being redirected to itself. I think this is superfluous as the rule is placed on LAN interface and the firewall itself will never hit the rule for outgoing DNS requests. However, without specifying the source everything works fine and the firewall itself is able to make necessary requests to DNS servers in WAN.
Logged
i am not an expert... just trying to help...

hushcoden

  • Sr. Member
  • ****
  • Posts: 383
  • Karma: 17
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #50 on: April 21, 2022, 06:23:58 pm »
One more question: is it possible for just a device on the LAN being able to use custom DNS servers ?

Tia.
Logged

RamSense

  • Sr. Member
  • ****
  • Posts: 421
  • Karma: 9
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #51 on: April 21, 2022, 06:53:32 pm »
When configure that device with static ip and then add the dns you like in the " DNS servers" field. Have not tried that myself while I use adguard home for all devices / dns.
Logged

tiermutter

  • Sr. Member
  • ****
  • Posts: 483
  • Karma: 25
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #52 on: June 15, 2022, 09:45:30 am »
A few months later.... :)

In the past I excluded my wifes smartphone (IP by alias) from being redirected because she didnt want to use (ad-)filtered DNS servers. Just edit the forward rule and add the IP/alias negated ( ! ) to the source.
Logged
i am not an expert... just trying to help...

hushcoden

  • Sr. Member
  • ****
  • Posts: 383
  • Karma: 17
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #53 on: June 15, 2022, 02:59:36 pm »
Quote from: tiermutter on June 15, 2022, 09:45:30 am
In the past I excluded my wifes smartphone (IP by alias) from being redirected because she didnt want to use (ad-)filtered DNS servers. Just edit the forward rule and add the IP/alias negated ( ! ) to the source.
Can you please check the two attachments (NAT before, NAT2 after)? After that change, the port forward will work for all the IPs but 192.168.0.13 ?

Tia.
Logged

tiermutter

  • Sr. Member
  • ****
  • Posts: 483
  • Karma: 25
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #54 on: June 15, 2022, 03:30:21 pm »
Yes, this should work and this IP can use those DNS specified in the clients setting or whatever any app wants to. Remember IPv6... If there is a redirect rule for v6, the client must be excluded here too. In this case it might be better to use MAC address instead of IPs.
Logged
i am not an expert... just trying to help...

xkpx

  • Newbie
  • *
  • Posts: 8
  • Karma: 0
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #55 on: July 02, 2022, 12:20:33 pm »
Simple and clean tutorial Thanks!
« Last Edit: July 02, 2022, 12:26:26 pm by xkpx »
Logged

cgi2099

  • Newbie
  • *
  • Posts: 12
  • Karma: 0
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #56 on: September 01, 2022, 01:30:37 pm »
Thank you so much OP of this tutorial everything seems to be working :)

Quote from: RamSense on April 21, 2022, 06:53:32 pm
When configure that device with static ip and then add the dns you like in the " DNS servers" field. Have not tried that myself while I use adguard home for all devices / dns.

I also use Adguard Home but want to exclude a VLAN from this to be redirected to the DNS I have setup in the DHCP for the VLAN interface, is this possible? I haven't been able to figure out a way to exclude my VLAN for Adguard.

Josh
Logged

cgi2099

  • Newbie
  • *
  • Posts: 12
  • Karma: 0
    • View Profile
Re: HOWTO - Redirect all DNS Requests to Opnsense
« Reply #57 on: September 02, 2022, 12:41:47 am »
After hours of testing this, I can get my Chromecast to have the correct DNS and all of that, I can fool the Chromecast with the direction above or at least I think I am. But certain apps like Disney, HBO Max and Hulu just won't work on the Chromecast. On my phone and computer it is no problem.
I believe there is something going on with the apps themselves or I am not doing something right. I even went as far as changing my DNS in AdGuard home to my VPNs and it does work but all these apps are still detecting a VPN.

Hopefully I am doing something wrong here?
Logged

  • Print
Pages: 1 2 3 [4]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • HOWTO - Redirect all DNS Requests to Opnsense
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2