Hi,
just to make sure before I suggest building just another dedicated DNS server: OPNsense can only do forwarding and cannot run as slave DNS server having the zone actually loaded? At a site I need a DNS server that can still resolve the internal names when the connection to the DNS servers holding the actual zone is not available.
Greetings, Marc Haber
You could use the os-bind plugin fir Zone updates of a secondary zone.
What @monviech said - BTDT, works great.
Thank you. Will look for available plugins in the future.
You might want to still run Unbound as the primary recursive resolver for local synchronisation of DHCP & DNS. You can run BIND on e.g. port 53530 and set a forwarding entry for the zone in question in Unbound.