I'm unable to query DNS for certain sites when connected to open sense. I run unbound and I use a block list but I have tested this with the block list disabled and I have also tested trying to go around open sense and directly to cloudflare.
Oddly, when I force dig to query 1.1.1.1 directly, I get failures for the same domain names just like when I query unbound.
I did my best with this editor but it still would not display the at symbol correctly, but I was running dig at 1.1.1.1
$ dig .1.1.1 youtube.com ;; communications error to 1.1.1.1#53: timed out ;; communications error to 1.1.1.1#53: timed out ;; communications error to 1.1.1.1#53: timed out ; <<>> DiG 9.20.26 <<>> .1.1.1 youtube.com ; (1 server found) ;; global options: +cmd ;; no servers could be reached Sep06 17:40:30 hippie@sterling:~ $ dig +short google.com 142.251.210.238 Sep06 17:40:37 hippie@sterling:~ $ dig +short reddit.com ;; communications error to 172.16.0.1#53: timed out ;; communications error to 172.16.0.1#53: timed out ^CSep06 17:41:02 hippie@sterling:~ $ dig .1.1.1 +short reddit.com ;; communications error to 1.1.1.1#53: timed out ^CSep06 17:41:20 hippie@sterling:~ $ dig u/1.1.1.1 +short cnn.com 151.101.131.5 151.101.3.5 151.101.67.5 151.101.195.5
If I connect to a vpn, I can resolve everything just fine. Also, if I plug my laptop directly into my ISP modem, I can resolve everything.
If I ssh to the open sense box, I am able to resolve those domains without issue and can even curl YouTube's landing page, it's just not allowing guests on the LAN to do so.
A little history, when this started the only recent Network changes made were me unplugging my ISP modem and plugging it back in. On or about that time my queries started failing for certain urls, but I ignored it thinking it was an Android issue like usual. I did dig into my ISP modem settings and found that a firewall had been enabled with very restrictive settings including a list of blocked domains that mentioned gmail. I went ahead and turned all this off so there's no blocking whatsoever being done and I rebooted the modem to make sure. After doing this, I was able to start resolving YouTube and reddit domain names directly from the opnsense firewall whereas before removing those ISP firewall settings I could not. Everything seems to work fine from the opnsense command line now, just not from the LAN unless I bypass open since physically or with a VPN.
I have dug into my firewall settings and there are no rules that would cause this behavior. The default filter shows all the rules but I went ahead and checked the separate rules for lan, and floating, and there's nothing affecting Port 53. That wouldn't make much sense anyway since most domains resolve either directly from unbound or from going around it to cloudflare but just those specific ones don't.
I updated opnsense today to the latest and greatest, OPNsense 26.7.3_11-amd64 FreeBSD 15.1-RELEASE-p3 OpenSSL 3.5.8, but the problem was occurring with 26.1 as well. I had to do a major version upgrade and then a second upgrade to get up to current.
I've spent a few hours with a couple ai chatbots and neither have been able to solve it so far, but have sent me on a lot of tcdumping goose chases.
Does anyone have any insight or is in a similar situation?
Thanks!
Source: r/opnsense · by /u/h1pp13p373