Skip to content

Obviate.io

To anticipate and prevent

  • Home
  • About Us
  • History
  • Privacy Policy
  • Toggle search form

Unblocking Private IPs from Public DNS under PFSense

Posted on 2015-09-03 By Jon No Comments on Unblocking Private IPs from Public DNS under PFSense

2015-08-31 12_58_10-pfSense - Status_ Dashboard
2015-08-31 12_58_10-pfSense – Status_ Dashboard

My home network has a domain name, so I don’t have to remember all the IP addresses of my various servers. However, I publish all the DNS information using AWS Route 53 since $0.50/month is much more palatable to me than running BIND. This works flawlessly until you get a firewall like PFsense that blocks all DNS responses for private IP address blocks (e.g. 192.168.x, 10.x, 172.16.x). Fortunately, it’s very easy to fix this under PFsense.

  • Login to PFSense
  • System
  • Advanced
  • Check “Disable DNS Rebinding Checks”

2015-08-31 12_59_21-pfSense - System_ Advanced_ Admin Access
2015-08-31 12_59_21-pfSense – System_ Advanced_ Admin Access

Keep in mind that this is a security function you are disabling. This feature helps mitigate DNS Rebinding Attacks, so you should read more to understand the implications of such. You can also allow private IP resolution on a domain-by-domain basis per the PFSense docs. Personally, I prefer to use OpenDNS resolvers as they have better protection over DNS Rebinding and just about every other type of attack out there.

Tech Tags:attack, dns rebinding, dns resolver, opendns, pfsense, private IP, private networks

Post navigation

Previous Post: Tutorial: Using VMWare ESXi and PFsense as a network firewall/router
Next Post: Outbound Email Security – Part 1 – SPF

More Related Articles

All Quiet on the Blog Front (again) Personal
Tutorial: Using VMWare ESXi and PFsense as a network firewall/router Hardware
IPv6: Backwater hick to bleeding edge – in a weekend?! IPv6

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

September 2015
S M T W T F S
 12345
6789101112
13141516171819
20212223242526
27282930  
« Aug   Oct »

amazon Android anime apache apple arduino asus averatec AWS Bad Company 2 cloud DIY eee fanime fanimecon github google iPad iphone IPv6 javascript kindle linkedin linux macbook air mass effect nodejs openvpn osx php review San Francisco security tutorial Ubuntu urban garden usb video wifi windows 7 winter urban garden wordpress xbox xbox 360 XboxLIVE

Copyright © 2022 Obviate.io

Powered by PressBook Premium theme