I use pfsense router and OpenVPN to connect my network from outside. Everything is workig fine via IP, but If i want to connect something useig the device DNS names resolving doesn’t work. I know this is DNS problem, but i don’t nkow how can i configure correctly.
Once connected, can you get a DNS response for a local address? You can test by using dig @192.168.111.1 SomeComputerOnYourNetwork and see what the response is. https://youtu.be/hYZY75xMjlY
Someone has the same issue before: „I was having an issue using this tutorial with DNS. I had only configured my DNS server and it would not resolve my internal names when using the VPN. The trick is to use ACLs in Unbound (DNS resolver) to allow the VPN virtual network to connect.”
But I don’t know what he did whit the ACLs. I don’t want to make a mistake and create a security hole on my network.
Adam,
Both the Dig and NSLookup didn’t give you a valid “answer” or record. Dig should give you something like this:
;; ANSWER SECTION:
COMPUTERNAME 3600 IN A 192.168.11X.X
I notice on the nslookup the name server fully resolved itself from you using the IP 192.168.111.1 it responded back with a named response of PAPPLAN-R1.PAPP.LAN
I am not expert at this, but whenever my DNS server wasn’t communicating properly I never got to it spit back name, just the IP
Are you sure an A record exists on the server to answer you back for papplan-nas 192.168.111.1
I don’t know how much this will prove…Im just running through troubleshooting steps in my head.
If you do: dig @PAPPLAN-R1.PAPP.LAN google.com
And that works with an answer section…then I would say DNS resolution is working, you just have no record.
See to me you just don’t have any A record present for local devices. They don’t get there by magic, you have to create the record (or have something setup/enabled to allow clients to register their hostname and IP).
Lets say the client you want paplan-nas 192.168.111.51
Would need: local-data: "papplan-ns.papp.lan A 192.168.111.51"
Please note: I don’t have, nor do I use PFSense, so please follow the docs guide or wait for Tom or others. I have only done DNS with BIND on Linux or Windows Server.
I checked the DNS records on my DNS server as you Shane and tbigs2011 suggested. My DNS server is my PFsense. So checked the DNS resolver settings and my test subject to the host overrides.