1
24.1 Legacy Series / Re: Use specified DNS servers instead of ISP DNS from DHCP
« on: June 06, 2024, 05:26:51 pm »This what I set
System , Settings, General - DNS servers blank
Disable - Allow DNS server list to be overridden by DHCP/PPP on WAN
Disable - Do not use the local DNS service as a nameserver for this system
Unbound on LAN INT listening port 53
LAN firewall rules , source internal vlans to destination (this firewall) port 53
Unbound access lists allowing internal vlans
Unbound - DNS over TLS
8.8.8.8
853
dns.google.com
1.1.1.1
853
cloudflare-dns.com
Clients DNS set to opnsense DNS. Or if internal DNS servers like domain controllers, client's DNS set to DC. DC forwards set to opnsense 53. Internal DNS unencrypted 53. External queries over TLS 853 to ones you specify.
Thank you! That seems to have fixed the issue and now I got a bit of a security upgrade with DNS over TLS