OPNsense Forum

English Forums => General Discussion => Topic started by: Nekromantik on March 21, 2021, 11:29:38 PM

Title: Unbound for DoT Upstream or DNS-Crypt Proxy?
Post by: Nekromantik on March 21, 2021, 11:29:38 PM
hi all
I been using Unbound as my network DNS server and upstream to DNS Crypt Proxy.
However I constantly get DNS not resolving on browsers. This does not happen if I use Unbound to upstream to Quad9 instead.

So do most of you guys just use Unbound to upstream to DoT servers with DNSSEC or use DNSCrypt?
Title: Re: Unbound for DoT Upstream or DNS-Crypt Proxy?
Post by: hushcoden on March 22, 2021, 08:40:14 AM
Quote from: Nekromantik on March 21, 2021, 11:29:38 PM
So do most of you guys just use Unbound to upstream to DoT servers with DNSSEC or use DNSCrypt?
The former and never had problems so far... but I started to study if/how DNSCrypt can be used to add an additional layer of security: do you know any online documentation for beginners on this?
Title: Re: Unbound for DoT Upstream or DNS-Crypt Proxy?
Post by: Nekromantik on March 22, 2021, 06:03:31 PM
Quote from: hushcoden on March 22, 2021, 08:40:14 AM
Quote from: Nekromantik on March 21, 2021, 11:29:38 PM
So do most of you guys just use Unbound to upstream to DoT servers with DNSSEC or use DNSCrypt?
The former and never had problems so far... but I started to study if/how DNSCrypt can be used to add an additional layer of security: do you know any online documentation for beginners on this?

dont think you can do anything else with it
it just does DNSSEC, Ad Blocking and DoH.