Bug #13454
closedEnabling DoT (DNS over TLS) breaks IPSec VPN DNS
0%
Description
Using pfsense plus 22.05 (current newest). Among other services, we run DNS and 'road warrior' IPSec VPN. Setup has worked well for years.
Recently, we turned on DoT for local clients. i.e. enabled the "Respond to incoming SSL/TLS queries from local clients" checkbox. Inside the LAN, it works great! TCP port 853 is opened, and DoT works according to tests with `kdig`. Plain old DNS still works too.
Alas, for those connected from home by IPSec VPN, plain old DNS is totally broken, UDP port 53 appears closed according to both an `nmap` scan and tests with `kdig`.
If we disable the DoT checkbox, DNS works again. We redo the port scan and UDP port 53 is back open.
There are two related (and unanswered) forum posts:
https://forum.netgate.com/topic/174247/enabling-dot-dns-over-tls-breaks-ipsec-vpn-dns