1
General Discussion / Unbound binds to all addresses?
« on: September 22, 2024, 08:30:31 pm »
I am trying to set up a separate VLAN for a kids’ network on my home setup. Latest stable opnsense running on a stand-alone box. The main goal is to firewall as well as DNS limit kids from accessing stuff on the web they don’t nee via my NextDNS subscription. However I am running into a limitation where I can’t run two separate DNS services on port 53 even though I specify which address/interface I want used. My main DNS server is Unbound and it is set up to run on the LAN interface, port 53. Trying to spin up Bind, or dnsmasq, or ideally dnscrypt-proxy on the address associated with my KIDS0 interface and port 53 says “Unbound is already using port 53 on this address”. This seems like a bug in Unbound unless I am missing something.
The eventual goal is to have Unbound continue serving LAN and forwarding its queries to the main/adult NextDNS profile, and another forwarded just on the KIDS0 interface that forwards queries to a kids NextDNS profile. I do have options such as using a separate piece of hardware to run a separate DNS server for the kids VLAN or setting up each of the kids’ devices with a DNS config for DNS-over-HTTPS directly to NextDNS but I was hoping there would be an oprion that involved me only configuring things in my opnsene box.
Thanks in advance.
The eventual goal is to have Unbound continue serving LAN and forwarding its queries to the main/adult NextDNS profile, and another forwarded just on the KIDS0 interface that forwards queries to a kids NextDNS profile. I do have options such as using a separate piece of hardware to run a separate DNS server for the kids VLAN or setting up each of the kids’ devices with a DNS config for DNS-over-HTTPS directly to NextDNS but I was hoping there would be an oprion that involved me only configuring things in my opnsene box.
Thanks in advance.