1
24.7 Production Series / Unbound DNS slow website loading and finally stucking
« on: October 27, 2024, 09:53:46 pm »
I have noticed a website loading performance problem when I use Unbound DNS. I only noticed this problem in the last few days, websites sporadically load very slowly and finally stuck. I blamed it on my playing computer running Ubuntu.
Today, however, I also noticed the performance problem on my main computer runnming macOS and I think I have been able to locate the source of the error in my OPNsense firewall after gradually decommissioning all devices one after another.
I can't say whether this was caused by an OPNsense update or has been the case for some time.
Unfortunately, I don't have the technical Linux/BSD background to be able to provide detailed diagnostics or logs.
I think I have localised the problem with OPNsense, because when I switch to Dnsmasq DNS instead of Unbound DNS I no longer have any website performance problems.
My system
OPNsense 24.7.7-amd64
FreeBSD 14.1-RELEASE-p5
OpenSSL 3.0.15
Under System > Settings > General the option "Allow DHCP/PPP to overwrite DNS server list on WAN" is disabled as long as I am using Unbound DNS. If I understand this correctly, the upstream/root DNS servers are then queried for Unbound DNS. I had to reactivate this option when using Dnsmasq DNS, as otherwise there was no DNS resolving in the WAN.
Is this a known problem?
Today, however, I also noticed the performance problem on my main computer runnming macOS and I think I have been able to locate the source of the error in my OPNsense firewall after gradually decommissioning all devices one after another.
I can't say whether this was caused by an OPNsense update or has been the case for some time.
Unfortunately, I don't have the technical Linux/BSD background to be able to provide detailed diagnostics or logs.
I think I have localised the problem with OPNsense, because when I switch to Dnsmasq DNS instead of Unbound DNS I no longer have any website performance problems.
My system
OPNsense 24.7.7-amd64
FreeBSD 14.1-RELEASE-p5
OpenSSL 3.0.15
Under System > Settings > General the option "Allow DHCP/PPP to overwrite DNS server list on WAN" is disabled as long as I am using Unbound DNS. If I understand this correctly, the upstream/root DNS servers are then queried for Unbound DNS. I had to reactivate this option when using Dnsmasq DNS, as otherwise there was no DNS resolving in the WAN.
Is this a known problem?




) bringt es die WiFi Karte nur auf max. 54MBit/s. Eingestellt habe ich 802.11 na, Kanal, Sendeleistung, Sende- und Empfangsantenne, Geschwindigkeit/Duplex alles auf Automatik. Ich habe die Kanäle mal manuell durchprobiert ohne sichtbaren Erfolg, mich wundert es allerdings, dass ich bei "Geschwindigkeit und Duplex" (wo ich Standard, üblicherweise automatische Auswahl natürlich so eingestellt lasse) nur maximal 54MBit/s in der Liste finde und auswählen könnte.