HOWTO - DNS Security / Unbound DNS with DNSCrypt, DoH Plugin for IPv4 + IPv6

Started by p1n0ck10, December 13, 2018, 10:14:12 PM

Previous topic - Next topic
As a pointer for what you might need to tweak in your configuration of OPN: 0.0.0.0:5353 means listen on that port on all interfaces, and that will include 127.0.0.1 aka "loopback".

Hi,

the Unbound Docu say on top also set listening and unbound interfaces to "All" but what are the implications when the "WAN Interface" is listening on Port 5353 for example? Just want to be sure, that my Opnsense cannot be used from others then, to be a Public DNS Server?

Warning
Below table contains the options to manually set listening and outbound interfaces, the recommended setting for both is "All" for good reasons. Unless you absolutely know what you are doing, best keep these settings default as misuse often causes startup issues.


Trying now to create a local loopack interface

Interfaces -> Other Type -> Loopback -> + > Name LO1
Interfaces -> Assigment Name "LO1",
Interfaces -> LO1 - Enable Interface
IPv4 Configuration Type: Static IPv4
IPv4 address: 127.0.0.1/8

When i try to save i get the error: The following input errors were detected:
   •   This IPv4 address is being used by another interface or VIP.


Has someone correctly accomplished this?