Bumping this - same issue here.
Also, suricata still throws alerts for ET_info although I removed (disabled) that ruleset ..
Also, suricata still throws alerts for ET_info although I removed (disabled) that ruleset ..
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuMS Name/IP address Stratum Poll Reach LastRx Last sample
===============================================================================
^* time.cloudflare.com 3 6 37 11 -36us[ +469us] +/- 17ms
^? sth1.nts.netnod.se 0 8 0 - +0ns[ +0ns] +/- 0ns
^? sth2.nts.netnod.se 0 8 0 - +0ns[ +0ns] +/- 0ns
^? ptbtime1.ptb.de 0 8 0 - +0ns[ +0ns] +/- 0ns
^? ptbtime2.ptb.de 0 8 0 - +0ns[ +0ns] +/- 0ns
^? ptbtime3.ptb.de 0 8 0 - +0ns[ +0ns] +/- 0ns
^- nts1.time.nl 2 6 37 10 -2907us[-2907us] +/- 39ms
^? nts.ntp.se 0 8 0 - +0ns[ +0ns] +/- 0ns
^? ntp2.glypnod.com 0 8 0 - +0ns[ +0ns] +/- 0ns
^? ntpmon.dcs1.biz 0 8 0 - +0ns[ +0ns] +/- 0ns
^? netmon2.dcs1.biz 0 8 0 - +0ns[ +0ns] +/- 0ns
^? sth-ts.nts.netnod.se 0 8 0 - +0ns[ +0ns] +/- 0ns
2021-12-02T14:15:43 chronyd[5971] Selected source 162.159.200.123 (time.cloudflare.com)
2021-12-02T14:15:41 chronyd[5971] Selected source 94.198.159.11 (nts1.time.nl)
2021-12-02T14:15:36 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:35 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:35 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:35 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:35 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:35 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:34 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:34 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:34 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:34 chronyd[5971] Could not set credentials : Error while reading file.
2021-12-02T14:15:34 chronyd[5971] Source 194.58.202.203 changed to 194.58.202.202 (nts.netnod.se)
2021-12-02T14:15:20 configctl[3020] event @ 1638450920.24 exec: system event config_changed
[ Chrony restart ]
Quote from: mimugmail on November 01, 2021, 04:58:17 PMI have not found a way to set this up from GUI unfortunately. Otherwise, would be the "cleanest" IMHO.
I would use Unbound listen to localhost only and System : Settings : General DNS Server empty so it uses unbound. AdGuardHome only listen to LAN address. Should work best
Quote from: franco on November 01, 2021, 03:35:23 PMFor the time being I have a port forward but the other way round: DNS queries to port 53 _from_ the local firewall get forwarded to Unbound at 127.0.0.1:5553; anything else goes to adguard at 53 first (and Adguard then queries 127.0.0.1:5553).
In particular, it would still be better to have an internal resolver like Dnsmasq or Unbound that is properly wired to provide the system with a way to resolve DNS during boot up and then rather use port forwards to capture DNS traffic from attached networks to funnel through AdGuard which uses the local service as a forward.
root@OPNsense:~ # nslookup photon
Server: 10.10.100.1
Address: 10.10.100.1#53
** server can't find photon: NXDOMAIN
WAN Oct 19 18:08:48 10.10.100.1:5353 224.0.0.251:5353 udp Block private networks from WAN
__timestamp__ Oct 19 18:08:48
action [block]
anchorname
datalen 69
dir [in]
dst 224.0.0.251
dstport 5353
ecn
id 46266
interface igb0
interface_name WAN
ipflags none
ipversion 4
label Block private networks from WAN
length 89
offset 0
protoname udp
protonum 17
reason match
rid 1eb94a38e58994641aff378c21d5984f
rulenr 69
src 10.10.100.1
srcport 5353
subrulenr
tos 0x0
ttl 1