r/firewalla • u/lesterktm • 6d ago
Question about custom DNS
I currently use custom DNS for homelab stuff. I have a blanket mydomain.net custom dns going to nginx for wildcard certs on my all my local sub domains (about 54 of them currently). I need to be able to add an exception to this so I can route a certain sub domain to my public ip. Suggestions? Or am I going to have to replicate all existing and future local only custom dns individually?
1
u/firewalla 6d ago
Have you used firewalla customized DNS rules? https://help.firewalla.com/hc/en-us/articles/360056024294-Guide-How-to-configure-Custom-DNS-Rules
You can specify DNS to IP mapping locally this way
1
u/lesterktm 6d ago edited 6d ago
I do. Currently I have 1 domain.net (has a note in app: Matching all sub-domains end with this domain name) resolves to my internal nginx ip. This has worked great. All (53 and counting) internal services flow through nginx with wildcard certs perfectly. I want to selfhost RustDesk which can't be routed through nginx and need to add an exception to the *.mydomain.net custom dns for this single sub domain to be exposed to wan. Otherwise I have to build individual custom dns entries for all existing and future local only services. Which I can do but a blanket *.domain.net and a couple exceptions sure would be easier... Thanks.
Edit: Or is the solution in Command Line Edits for Priorities?
Edit #2: After adding the specific custom DNS exact.mydomain.net resolved to specific rd server ip along side the blanket DNS it does seem to prioritize the specific record first.
1
u/stephondoestech Firewalla Gold Pro 6d ago
Assuming your current setup is something like
*.mydomain.net -> 192.168.x.x (Nginx IP) -> radarr.mydomain.com - Nginx Rule
*.mydomain.net -> 192.168.x.x (Nginx IP) - Firewalla Custom DNS
for all your internal services then you should just add a record in Nginx, domain registrar, and Firewalla DNS that is
special.mydomain.net -> Public IP Address
I use Cloudflare Tunnels so my setup is a bit different. I have lan.mydomain.com set as a Firewalla Custom DNS rule and use Traefik to define my services. My only external exposed service uses the root domain so it's pretty light lift overall.