Skip to content
DnsLister Forum

Where domain hunters compare notes

Firewalla redirecting DNS

Hi,

I'm running Pi-hole on one box and unbound separately on another as Pi-hole's upstream. I know Firewalla can run unbound itself, but I want it kept separate from Pi-hole/Firewalla so I have full control over the config.

My problem is Firewalla appears to be redirecting all outbound port 53 traffic to Pi-hole, and that's catching unbound's own recursive queries to root/TLD servers too, not just LAN client traffic. So when unbound asks a real root server something, Firewalla quietly answers as Pi-hole's dnsmasq instead. Unbound notices the response doesn't make sense, retries a bunch of times, then gives up with SERVFAIL.

I confirmed it with dig @<root-server-ip> version.bind CH TXT +time=3 which should say "ATLAS" from a real root server, but I get "dnsmasq-UNKNOWN" instead.

I've removed all of the redirect / DNS prevention I can find, but I'm still getting the dnsmasq answer. Does anyone know the actual setting to fully exempt one device's outbound DNS from Firewalla's redirect?

(This does work, or appears to, but with cloudflared's proxy-DNS being deprecated, I'm looking to migrate)

Source: r/firewalla · by /u/Life-Cow-7945

Leave a Reply

Your email address will not be published. Required fields are marked *