1
Tutorials and FAQs / Re: FRESH NEW AND IMPROVED GETDNS STUBBY AND UNBOUND AKA DNS PRIVACY
« on: May 20, 2020, 09:47:05 pm »
Thank you for this big update on how to install unbound + stubby on opnsense.
I am a satisfied user of these 2 softwares for about a year now.
I have got a few questions for you. I hope you will have the time to answer a few of them.
1) I have seen that you have enable the DNSSEC extension in Stubby.
We can see it in the stubby.yml files:
If you have already activated the DNSSEC validation in unbound, don't you think that it is useless to activate it in stubby?
I have enabled DNSSEC only in unbound and everything is fine.
Unbound is making all the stuff about the dns queries. I am using stubby only to send the dns queries from unbound with DoT or DoH to several servers.
2) I will try your new settings with the main LAN Address instead of the localhost address. What is exactly the pro of this new settings ?
3)With the new plugin unbound-plus we will soon not have access anymore to the "custom options" in unbound GUI.
Where can we then specify the following to transfer the dns queries from unbound to stubby?
Thanks again for all the help provided on the install of stubby on opnsense.
I am a satisfied user of these 2 softwares for about a year now.
I have got a few questions for you. I hope you will have the time to answer a few of them.
1) I have seen that you have enable the DNSSEC extension in Stubby.
We can see it in the stubby.yml files:
Quote
dnssec_return_status: GETDNS_EXTENSION_TRUE
If you have already activated the DNSSEC validation in unbound, don't you think that it is useless to activate it in stubby?
I have enabled DNSSEC only in unbound and everything is fine.
Unbound is making all the stuff about the dns queries. I am using stubby only to send the dns queries from unbound with DoT or DoH to several servers.
2) I will try your new settings with the main LAN Address instead of the localhost address. What is exactly the pro of this new settings ?
3)With the new plugin unbound-plus we will soon not have access anymore to the "custom options" in unbound GUI.
Where can we then specify the following to transfer the dns queries from unbound to stubby?
Quote
server:
forward-zone:
name: "." # Allow all DNS queries
forward-addr: 192.168.7.11@8053 ## ( Your One Main LAN Address )
## END OF ENTRY
Thanks again for all the help provided on the install of stubby on opnsense.