OPNsense Forum

English Forums => General Discussion => Topic started by: August8828 on October 10, 2024, 09:38:09 AM

Title: How to use DNS-Forge with DOT on unbound?
Post by: August8828 on October 10, 2024, 09:38:09 AM
This is confusing to me. How do I set up DOT with DNSFORGE on the unbound interface of my Opnsense?

Those are the unencrypted settings I've found:

Here are the unencrypted settings:

https://ibb.co/jkdDY3t

here are the encrypted settings:

https://ibb.co/kB69yYG

Here are the unbound settings:

https://ibb.co/KmJnjJY

I just screenshotted the last image because I do not have access to my Opnsense now. That's the reason why 1.1.1.1 is in there.

Do I just have to enter the IPV4 of the unenencrypted settings and add port 853 to it? Or do I use the hostname?

Title: Re: How to use DNS-Forge with DOT on unbound?
Post by: viragomann on October 10, 2024, 11:03:01 PM
For each DoT server, you want to forward DNS queries to, you need its IP and its respective common name (CN) of the SSL cert. The CN is usually corresponding to the host name.

From your screenshots I cannot tell you, which CN correlate with which, however IP. But I think, DNSForge might have this publicized anywhere.