OPNsense Forum

English Forums => 25.7, 25.10 Series => Topic started by: wallnas on December 11, 2025, 05:45:13 PM

Title: Unbound DNS, DoT - Priority Dns on TLS
Post by: wallnas on December 11, 2025, 05:45:13 PM
good evening,
I entered 2 DNS addresses in "Unbound DNS: DNS over TLS" and I need them to be processed with priority, so elect the primary and secondary.
If the first doesn't respond because it doesn't work, pass the execution to the second: can it be done?
Title: Re: Unbound DNS, DoT - Priority Dns on TLS
Post by: Kets_One on December 11, 2025, 08:47:13 PM
When the first DoT server does not respond, Unbound treats it as unresponsive and applies a probing scheme with exponential backoff. Initially, failed queries receive a SERVFAIL response. Unbound then blocks the non-responsive server for a default period (typically 15 minutes, controlled by infra-ttl) and periodically sends a single probe query to test its availability.

During this time, Unbound automatically forwards new queries to the next available server in the configuration. Once the blocked server responds to a probe, it is reinstated into the pool for normal use
Title: Re: Unbound DNS, DoT - Priority Dns on TLS
Post by: wallnas on December 12, 2025, 04:11:03 PM
Hi Kets_One
I configured in "DNS overs TLS" 2 server IP, I need to check 185.236.104.254 as primary and 8.8.8.8 as secondary.
I can't find inside how to set the priority

It is important that the DNS to be used is always 185.236.104.254. If it does not work 8.8.8.8 must be activated.