Skip to content

Obviate.io

To anticipate and prevent

  • Home
  • About Us
  • History
  • Privacy Policy
  • Toggle search form

Unblocking Private IPs from Public DNS under PFSense

Posted on 2015-09-03 By Jon No Comments on Unblocking Private IPs from Public DNS under PFSense

2015-08-31 12_58_10-pfSense - Status_ Dashboard
2015-08-31 12_58_10-pfSense – Status_ Dashboard

My home network has a domain name, so I don’t have to remember all the IP addresses of my various servers. However, I publish all the DNS information using AWS Route 53 since $0.50/month is much more palatable to me than running BIND. This works flawlessly until you get a firewall like PFsense that blocks all DNS responses for private IP address blocks (e.g. 192.168.x, 10.x, 172.16.x). Fortunately, it’s very easy to fix this under PFsense.

  • Login to PFSense
  • System
  • Advanced
  • Check “Disable DNS Rebinding Checks”

2015-08-31 12_59_21-pfSense - System_ Advanced_ Admin Access
2015-08-31 12_59_21-pfSense – System_ Advanced_ Admin Access

Keep in mind that this is a security function you are disabling. This feature helps mitigate DNS Rebinding Attacks, so you should read more to understand the implications of such. You can also allow private IP resolution on a domain-by-domain basis per the PFSense docs. Personally, I prefer to use OpenDNS resolvers as they have better protection over DNS Rebinding and just about every other type of attack out there.

Tech Tags:attack, dns rebinding, dns resolver, opendns, pfsense, private IP, private networks

Post navigation

Previous Post: Tutorial: Using VMWare ESXi and PFsense as a network firewall/router
Next Post: Outbound Email Security – Part 1 – SPF

More Related Articles

Project “Falcon” – The DIY Router (server?) Experiment Hardware
IPv6: Backwater hick to bleeding edge – in a weekend?! IPv6
Tutorial: Using VMWare ESXi and PFsense as a network firewall/router Hardware

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

September 2015
S M T W T F S
 12345
6789101112
13141516171819
20212223242526
27282930  
« Aug   Oct »

Copyright © 2022 Obviate.io

Powered by PressBook Premium theme