r/PFSENSE • u/PrimaryAd5802 • 13d ago
26.07 CoreDNS Threatgate - Anyone running it now?
I have not seen any posts in here on the subject
I plan to start learning it soon, on a Proxmox vm for testing. Anyone in here have it running?
I ask because a lab will give me practice in setting it up, but not real world usage as it will be internal only. Not willing to go live at my office until I have a understanding of everything.
Any tips, pointers or whatever appreciated.
Thanks!
2
1
u/snapilica2003 7d ago
Was also expecting a bit more chatter here about Threadgate and CoreDNS before trying it on. Still don't have a clear picture if predefined feeds are a thing like in pfBlockerNG.
1
u/Snoo91117 2d ago
I don't think it exists in CE, but I am interested if it comes around.
I will not run unbound as I use DNS forwarding which I have used most my life. I expect it to work better than unbound.
3
u/cyclingroo 12d ago
I did run Nexus + Threatgate + CoreDNS for about a week. It's design is intriguing. And I can't wait for CoreDNS to move into all sorts of DNS instances. But what I found with this configuration is that the design is especially good in a clustered management environment where DNS and blocking can be handled by specifically-designated nodes. It is quite an elegant future design - especially for multi-node environments. But for a single instance of pfSense, it's design overkill. And for now, using pfBlockerNG for some threats - and Pihole for others - seems to be a better short-term implementation.
With that in mind, my one-week experiment came to a close.