Skip to main content
All CollectionsDNS GuardDevice setup & enrollment
pfSense configuration guide (external IP linking)
pfSense configuration guide (external IP linking)

Learn how to configure DNS guard on your pfSense firewall.

Updated over 9 months ago

In this article, we will configure DNS Guard on your pfSense firewall using external IP linking. You can learn more about external IP linking in our knowledgebase. Please read that article first and link your external IP.

This article is written based on pfSense 2.6.0-RELEASE.

Configure DNS Guard as upstream

  1. Go to your pfSense firewall and log in as administrator. You can find the login page often via your web browser by going to https://ip-of-your-gateway/.

  2. Click System >> General Setup

  3. Enter the two DNS server IP addresses as listed on your DNS Guard server page where you linked your external IP and click Save.

Kapture+2023-03-06+at+22.20.47

Configure firewall rules

We must create firewall rules to block DNS queries to other DNS servers.

Ensure you block traffic to port 53 (DNS) and 853 (DNS over TLS) except for connections to your firewall or domain controller.

  1. Allow any source to destination gateway_ip on port 53 UDP

  2. Allow gateway_ip source to destination DNS Guard servers on port 53 UDP

  3. Deny any source to any destination on port 53 UDP

Did this answer your question?