Community discussions

MikroTik App
 
Belikearu
just joined
Topic Author
Posts: 4
Joined: Mon Dec 30, 2019 5:53 am
Location: General Santos City, Philippines

Forward dns related traffic to pfsense

Sat Dec 17, 2022 2:34 am

Hello, Good Day.

I have pfsense and mikrotik combo in my setup. pfsense serves as our internet firewall which handles all the processing (filter etc.) for internet related traffic and it is where our 2 ISP are plugged in, also it serves as our internal dns server. Mikrotik on the other hand handles internal routing (inter-vlan) and also a firewall to filter unnecessary traffic between our vlans.

Here's the diagram with config I'm having a problem with.
topology.PNG
The rules in between are all related to inter-vlan filtering and that works perfectly fine. My only problem is simply forwarding dns related traffic to pfsense as it is our dns server
for the clients to access internet.

If anyone could enlighten me on this, would be appreciated. thnx

Note***
This setup with mikrotik filter rules disabled works perfectly fine. With filter rules implemented, it also works fine except allowing dns traffic to be forwarded to pfsense.
You do not have the required permissions to view the files attached to this post.
 
Sob
Forum Guru
Forum Guru
Posts: 9119
Joined: Mon Apr 20, 2009 9:11 pm

Re: Forward dns related traffic to pfsense

Sun Dec 18, 2022 3:28 am

It should work, any connection to 192.168.4.254:53 should be allowed. If you have rules at the beginning as shown, there's nothing to stop this traffic.
 
Belikearu
just joined
Topic Author
Posts: 4
Joined: Mon Dec 30, 2019 5:53 am
Location: General Santos City, Philippines

Re: Forward dns related traffic to pfsense

Sun Dec 18, 2022 8:15 am

It should work, any connection to 192.168.4.254:53 should be allowed. If you have rules at the beginning as shown, there's nothing to stop this traffic.
I know right, that's exactly why I'm scratching my head with this co'z I know this pretty dang simple rule but it's not working somehow. ugh
 
Sob
Forum Guru
Forum Guru
Posts: 9119
Joined: Mon Apr 20, 2009 9:11 pm

Re: Forward dns related traffic to pfsense

Sun Dec 18, 2022 3:24 pm

You need to look closely at what happens. Tools->Netwatch, logging rules in right places, ... find out where exactly it goes wrong. Step by step, see incoming packets in prerouting, verify in postrouting that nothing blocked them, watch for responses, etc..
 
Belikearu
just joined
Topic Author
Posts: 4
Joined: Mon Dec 30, 2019 5:53 am
Location: General Santos City, Philippines

Re: Forward dns related traffic to pfsense

Fri Dec 23, 2022 10:32 am

I would like to follow up on this and if anyone is kind enough to recreate the setup to see how it goes on your end.
My last test was from a freshly config mikrotik with only rule set of the ff

- accept established/related (forward)
- accept protocol udp 53 (forward)
- accept protocol tcp 53 (forward)
- drop everything else (forward)

Still not working :(

Who is online

Users browsing this forum: Amazon [Bot] and 34 guests