Discussion:
Outbound port forward
Arquivos
2011-09-06 19:08:50 UTC
Permalink
Hi all.

I have a pfSense 2.0 box with 1 LAN and two WAN´s; Actually i´m facing a
problem:
i need to forward all the requests going out by the port 53 (DNS) to a
single external DNS server, in dispite off the DNS configured in the
clients. Can someone help me in that?

Danilo



---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org
For additional commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org
David Burgess
2011-09-06 19:12:38 UTC
Permalink
Post by Arquivos
i need to forward all the requests going out by the port 53 (DNS) to a
single external DNS server, in dispite off the DNS configured in the
clients. Can someone help me in that?
What you want is a NAT Port Forward entry on your LAN interface to
destination port 53 and a redirect target IP of the server you want to
force. I haven't tried this but I believe it will do what you are
asking.

db

---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org
For additional commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org
Seth Mos
2011-09-06 20:32:38 UTC
Permalink
Post by David Burgess
Post by Arquivos
i need to forward all the requests going out by the port 53 (DNS) to a
single external DNS server, in dispite off the DNS configured in the
clients. Can someone help me in that?
What you want is a NAT Port Forward entry on your LAN interface to
destination port 53 and a redirect target IP of the server you want to
force. I haven't tried this but I believe it will do what you are
asking.
This should work, i've been doing this a while back where I had a combination of a port forward on the LAN and a outbound NAT rule on the LAN interface to mangle traffic.

That was 1.2.3 or a early 2.0 beta.

Regards,

Seth
---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org
For additional commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org
Arquivos
2011-09-06 19:34:11 UTC
Permalink
Post by David Burgess
What you want is a NAT Port Forward entry on your LAN interface to
destination port 53 and a redirect target IP of the server you want to
force. I haven't tried this but I believe it will do what you are
asking.
I´ve tried this config and it didn´t work :(
In NAT por forward only internal IP´s can be specified and i need an
external DNS server, so i´m still in the dark.
Tks..

Danilo



---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org
For additional commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org
Ryan Rodrigue
2011-09-06 20:54:59 UTC
Permalink
What if you enabled DNS Forwarder and forwarded All DNS Request to PFsense.

Ryan Rodrigue
P.O. Box 4336
Chief Technical Manager
Houma, LA 70361
A A R Electronics, Inc
Phone (985) 876-4096
510 West Tunnel Blvd
Phone (800) 649-7346
Houma, LA 70360
Fax (985) 853-0134
Radiotech1-VLNP13999mZWk0Htik3J/***@public.gmane.org
www.aarelectronics.com


-----Original Message-----
From: Arquivos [mailto:arquivos-XbLTj5g7dhlfyO9Q7EP/***@public.gmane.org]
Sent: Tuesday, September 06, 2011 2:34 PM
To: support-***@public.gmane.org
Subject: Re: [pfSense Support] Outbound port forward
Post by David Burgess
What you want is a NAT Port Forward entry on your LAN interface to
destination port 53 and a redirect target IP of the server you want to
force. I haven't tried this but I believe it will do what you are
asking.
I´ve tried this config and it didn´t work :( In NAT por forward only
internal IP´s can be specified and i need an external DNS server, so i´m
still in the dark.
Tks..

Danilo



---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org For additional
commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org



__________ Information from ESET NOD32 Antivirus, version of virus signature
database 6441 (20110906) __________

The message was checked by ESET NOD32 Antivirus.

http://www.eset.com




---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org
For additional commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org
Adam Piasecki
2011-09-07 13:19:10 UTC
Permalink
This works, and works great. Combined with open dns, it's a great way of
filtering domains.

Adam
Post by Ryan Rodrigue
What if you enabled DNS Forwarder and forwarded All DNS Request to PFsense.
Ryan Rodrigue
P.O. Box 4336
Chief Technical Manager
Houma, LA 70361
A A R Electronics, Inc
Phone (985) 876-4096
510 West Tunnel Blvd
Phone (800) 649-7346
Houma, LA 70360
Fax (985) 853-0134
www.aarelectronics.com
-----Original Message-----
Sent: Tuesday, September 06, 2011 2:34 PM
Subject: Re: [pfSense Support] Outbound port forward
Post by David Burgess
What you want is a NAT Port Forward entry on your LAN interface to
destination port 53 and a redirect target IP of the server you want to
force. I haven't tried this but I believe it will do what you are
asking.
I´ve tried this config and it didn´t work :( In NAT por forward only
internal IP´s can be specified and i need an external DNS server, so i´m
still in the dark.
Tks..
Danilo
---------------------------------------------------------------------
Commercial support available - https://portal.pfsense.org
__________ Information from ESET NOD32 Antivirus, version of virus signature
database 6441 (20110906) __________
The message was checked by ESET NOD32 Antivirus.
http://www.eset.com
---------------------------------------------------------------------
Commercial support available - https://portal.pfsense.org
---------------------------------------------------------------------
To unsubscribe, e-mail: support-unsubscribe-***@public.gmane.org
For additional commands, e-mail: support-help-***@public.gmane.org

Commercial support available - https://portal.pfsense.org

Continue reading on narkive:
Loading...