Hi Mario,I don't do DNS on OPNsense since I was always told explicitly in firewall training that you need to minimise the attack surface of your security devices. Traffic should only go through a firewall and it should not be a source or a destination of traffic itself, (outside its management network).My internal DNS ultimately resolves to a Pi-Hole. Horses for courses.Bart...
Hi, thanks a lot for these hint. Maybe you can tell me the Size of your Network and what machine (Hardware) you are using for the Pihole service ? => Do you use Unbound at you Pihole installation? Or are you using external DNS Server? Iam so sorry, to ask but i would like to see how "other people" build ther Networks. I think building networks is a neverending process - there is always the possibilty to improve the security or something else. Thanks
Hi Bart,you made a very good point and I was planning to use my raspberry pi for this puprose by deploying pi-hole + unbound, but then I'm not sure which way to connect the raspberry pi to the network, i.e. to a port of the OPNsense box or? Could you shed some light?Tia.
So thanks for the replies. If i get it right so everyone recommend not using the internal DNS Server of the firewalls. So it should be better to create a new DNS Server within the network - like pi-hole -. So you configre the firewall like following: Firewall: DNS (under Gateways): 1.1.1.1 / 9.9.9.9 (to get the firewall connected to the Internet) DHCP : You deploy - the first DNS Resolver is your PIhile -> the second one ? a public Server? Or do you point the DNS Server of the Firewall also so to your Pihole ?
IMHO the easiest way of doing DNS with OPNsense is to configure Unbound as a recursive DNS server + blocklist (avoid DOT to preserve your privacy, no need to let Quad9 or Cloudflare know which websites you're visiting).[...]Besides I'm going to install on a VM Technitium and play with it as it seems to be a pi-hole + a recursive DNS server all-in-one - info hereMerry Christmas!
But please let me ask a question of DOT - you said, that i just avoid these to prevent my privacy. But i always thougt, that these methots DOH/ DOT save my privacy, cause the traffic is encrypted. Maybe you can explain it ? Or give me a hint, where i can start to "google" for ? Thanks !