Thanks. Here are the full Services → Unbound DNS → General settings (advanced mode on):
Enable Unbound: enabled
Listen Port: 53
Network Interfaces: All (recommended)
Enable DNSSEC Support: off
Enable DNS64 Support: off
Enable AAAA-only mode: off
Register ISC DHCP4 Leases: off
DHCP Domain Override: empty
Register DHCP Static Mappings: on
Do not register IPv6 Link-Local addresses: off
Do not register system A/AAAA records: off
TXT Comment Support: off
Flush DNS Cache during reload: on
Force SafeSearch: off
Local Zone Type: transparent
Recursion mode (no query forwarding). Access Lists allow 192.168.20.0/24 (STAFF). Listening socket confirmed on *:53 (udp4/tcp4). The firewall's own DNS Lookup tool resolves fine, and MGMT VLAN clients resolve through this same Unbound with no problem — only STAFF (VLAN 20) fails, and its queries never appear in the Unbound query log at all.
Enable Unbound: enabled
Listen Port: 53
Network Interfaces: All (recommended)
Enable DNSSEC Support: off
Enable DNS64 Support: off
Enable AAAA-only mode: off
Register ISC DHCP4 Leases: off
DHCP Domain Override: empty
Register DHCP Static Mappings: on
Do not register IPv6 Link-Local addresses: off
Do not register system A/AAAA records: off
TXT Comment Support: off
Flush DNS Cache during reload: on
Force SafeSearch: off
Local Zone Type: transparent
Recursion mode (no query forwarding). Access Lists allow 192.168.20.0/24 (STAFF). Listening socket confirmed on *:53 (udp4/tcp4). The firewall's own DNS Lookup tool resolves fine, and MGMT VLAN clients resolve through this same Unbound with no problem — only STAFF (VLAN 20) fails, and its queries never appear in the Unbound query log at all.
"