OPNsense Forum

Archive => 20.7 Legacy Series => Topic started by: logan23 on May 05, 2020, 07:02:27 am

Title: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: logan23 on May 05, 2020, 07:02:27 am
It would ALSO be very convenient to load a list of domains or hosts to override directly from a text file...
Aliases are very convenient to quickly enable/disable a group of domains to override included in one alias.
Thanks for your good work.
Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: ruggerio on May 05, 2020, 07:12:46 am
it's already there: go to services->unbound->bridgeing (Überbrückung), the 2nd point in unbound-menu.
Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: logan23 on May 05, 2020, 07:41:29 am
I'm afraid you're wrong: I'm talking about Domain Overrides, not Host Overrides.

Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: mimugmail on May 05, 2020, 07:52:11 am
What about a wildcards host override?
Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: logan23 on May 05, 2020, 08:03:57 am
Good try.

The problem is it crashes unbound if you activate os-unbound-plus 1.1_1 DNSBL plugin.

In Host Overrides, add these domains to block:
host=*   domain=windowsupdate.com    ip=0.0.0.0
host=*   domain=microsoft.com    ip=0.0.0.0

Now install this unbound additional plugin (see above) and select these 3 BL :
WindowsSpyBlocker (spy)
WindowsSpyBlocker (update)
WindowsSpyBlocker (extra)

...now enable the blacklist plugin

2020-05-04T08:26:46    unbound: [92889:0] fatal error: Could not set up local zones
2020-05-04T08:26:46    unbound: [92889:0] error: local-data in redirect zone must reside at top of zone, not at 00015e-1.l.windowsupdate.com A 0.0.0.0
2020-05-04T08:26:46    unbound: [92889:0] debug: duplicate acl address ignored.
2020-05-04T08:26:46    unbound: [92889:0] debug: duplicate acl address ignored.
2020-05-04T08:26:46    unbound: [92889:0] debug: drop user privileges, run as unbound
2020-05-04T08:26:46    unbound: [92889:0] debug: chroot to /var/unbound
2020-05-04T08:26:46    unbound: [92889:0] debug: chdir to /var/unbound
2020-05-04T08:26:45    unbound: [69721:0] debug: switching log to stderr
2020-05-04T08:26:45    unbound: [69721:0] info: 0.262144 0.524288 12

I've talked to Michael Muenz, but he didn't find any workaround:
> No idea, sorry. Maybe you can ask in the forums

Moreover, if you have a long list of domains to override, it is very tiresome to add them one by one.
Instead, loading a text file would be cool... and deleting all the domains under one alias.
Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: mimugmail on May 05, 2020, 09:13:25 am
Yes thats me. I still dont get why you need this (Domain Override) If you already use the Tracking list? It's just a limitation of Unbound and design that you cant mix it
Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: logan23 on May 05, 2020, 10:52:42 am
Anyways, IMHO, unbound shouldn't crash whatever the settings are between OPNsense standard override settings and the plugin.

There should be a solution to fix this, such as Host Overrides settings that would prevail over the plugin blacklists for instance, it's just a quick idea.

You still don't get it? Seriously? The tracking lists are far from being perfect and everyone should be able to create their own list without risking unbound to crash.

For example, I hate Facebook, I consider it is nothing else than a US government agency asking people over the world to fill their own information/intelligence sheet/card for the benefit of NSA databases (you know? the motherf*ckers on the planet - https://prism-break.org/en/ (https://prism-break.org/en/))

See the attachment:



Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: mimugmail on May 06, 2020, 08:03:52 am

You still don't get it? Seriously? The tracking lists are far from being perfect and everyone should be able to create their own list without risking unbound to crash.



Just  use an internal webserver, or github account, create your own list as a text file and load it via the manual blacklist link. Easy.

The error of Unbound is a limitation of Unbound itself and should reported over there as we have no chance to influence.
Title: Re: Unbound OVERRIDE DOMAIN : ALIASES please! (new feature request)
Post by: logan23 on May 06, 2020, 09:54:05 am
Just  use an internal webserver, or github account, create your own list as a text file and load it via the manual blacklist link. Easy.

thanks mate!
However it's not convenient at all if you want to temporarily disable/enable a group of domains under one alias...