

This is a community subreddit so lets try and keep the discourse polite. This subreddit is primarily for the community to help each other out, if you have something you want the maintainers of the project to see we recommend posting in the appropriate category on our Netgate forum. You can leave the DNS Resolver of PFSense and set an upstream DNS for NxFilter Just give a rule on PFSense to allow connections on port 53 for the new VM. If you are looking to sell or buy used hardware, please try /r/hardwareswap. A Armando Alvel Aug 22, 2018, 1:29 AM I have set NxFilter on other VM inside the LAN created by PfSense. If you are looking for help with basic networking concepts, please try /r/homelab or for more advanced, /r/networking.ĭo not post items for sale in this subreddit. Use a search engine like Google to search across the domain:

We have a great community that helps support each other, but we also provide 24x7 commercial support.īefore asking for help please do the following: You can install the software yourself on your own hardware. You can buy official pfSense appliances directly from Netgate or a Netgate Partner. Then you can filter the whitelist with nxFilter.The pfSense project is a free, open source tailored version of FreeBSD for use as a firewall and router with an easy-to-use web interface. Then I made the primary DNS Server on pfSense to be 10.127.1.240(which is my nxFilter) and the secondary DNS Server 1.1.1.1 and on NxFilter I have made my upstream DNS Server 10.127.1.254 which points back to pfSense. IPv4 TCP/UDP * * * 53 (DNS) * Block All other DNS Servers (if you use the above) Then you can filter the whitelist with nxFilter. IPv4 TCP/UDP * * 127.0.0.1 53 (DNS) * NAT Redirect DNS Then I made the primary DNS Server on pfSense to be 10.127.1.240(which is my nxFilter) and the secondary DNS Server 1.1.1.1 and on NxFilter I have made my upstream DNS Server 10.127.1.254 which points back to pfSense. Protocol Source Port Destination Port Gateway Description If i change the DNS address on device level to the IP of any other DNS Server it auto-bypass the NxFilter which I understand it will do, thus have I implemented firewall rules to block access to any other dns server, firewall rules as follow. So I run pfSense (10.127.1.254) as the main firewall/router and on a separate device I have NxFilter (10.127.1.240) to filter the DNS content which works great. I want to filter web content at the DNS level.
