truenas_admin@truenas[~]$ ip -brief a
lo UNKNOWN 127.0.0.1/8 ::1/128
enp6s0 UP
enp3s0 UP
bond1 UP fe80::<redacted>:4109/64
vlan20@bond1 UP fe80::<redacted>:4109/64
vlan30@bond1 UP fe80::<redacted>:4109/64
vlan60@bond1 UP fe80::<redacted>:4109/64
br1 UP 192.168.1.118/24 fe80::<redacted>:850b/64
br20 UP fe80::<redacted>:9746/64
br30 UP 172.21.30.118/24 fe80::<redacted>:435e/64
br60 UP fe80::<redacted>:952c/64
$ iperf3 -c truenas.clear.h1.internal
Connecting to host truenas.clear.h1.internal, port 5201
[ 5] local 172.21.30.100 port 46912 connected to 172.21.30.118 port 5201
[ ID] Interval Transfer Bitrate Retr Cwnd
[ 5] 0.00-1.00 sec 283 MBytes 2.37 Gbits/sec 0 311 KBytes
[ 5] 1.00-2.00 sec 281 MBytes 2.36 Gbits/sec 0 291 KBytes
[ 5] 2.00-3.00 sec 281 MBytes 2.36 Gbits/sec 0 297 KBytes
[ 5] 3.00-4.00 sec 280 MBytes 2.35 Gbits/sec 0 303 KBytes
[ 5] 4.00-5.00 sec 280 MBytes 2.35 Gbits/sec 0 294 KBytes
[ 5] 5.00-6.00 sec 281 MBytes 2.36 Gbits/sec 0 300 KBytes
[ 5] 6.00-7.00 sec 280 MBytes 2.35 Gbits/sec 0 291 KBytes
[ 5] 7.00-8.00 sec 280 MBytes 2.35 Gbits/sec 0 291 KBytes
[ 5] 8.00-9.00 sec 281 MBytes 2.36 Gbits/sec 0 294 KBytes
[ 5] 9.00-10.00 sec 281 MBytes 2.35 Gbits/sec 0 291 KBytes
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-10.00 sec 2.74 GBytes 2.36 Gbits/sec 0 sender
[ 5] 0.00-10.00 sec 2.74 GBytes 2.35 Gbits/sec receiver
Quote from: ceeeeej on March 08, 2025, 12:56:41 AMI have OPNSense setup with Adguard Home and Unbound with DNS over TLS.
I was having some trouble getting the Caddy access lists working to restrict some services to my LAN IPs only. To get this all working I had to setup overrides in Unbound that point these URLs back to my Caddy when on my LAN. i.e. I setup example.website.com in Caddy and then in Unbound I had to setup an override to point this URL back to 192.168.1.1 (where Caddy is running on my opnsense router).
My assumption was that because they were encrypted with DNS over TLS that the Caddy reverse proxy can't intercept them?
Just posting in case anyone has feedback or other ideas here. I was hoping to not require setting these up but it works now.