DoH when in bridge mode behind a pfsense firewall
I have my firewalla in bridge mode between a unifi dream machine and a netgate 4200 pfsense firewall. There are no special rules on the firewall for dns (other than pass UDP/53). Each subnet passes the gateway address as the dns and at this point the DNS Resolver in pfsense handles the requests. When I turn on DoH in firewalla it does not seem to have any affect at all. DNS does not go where it should (it goes to CloudFlare even though DoH is set up to go to NextDNS). I would suspect the firewall is the problem but the DNS resolves (and I can see activity on the DNS rule) it just doesn't seem to use firewalla at all.
When considering this in pfsense, I am assuming the DoH packets will be from Firewalla, not rewritten to look as if they came from the source client?
Another question. If I enable DoH and Unbound, does that mean that DoH uses Unbound, or vice versa? Meaning that dns requests will be converted to DoH and Unbound will act as a local cache?
Please sign in to leave a comment.
Comments
5 comments