Now that the "custom options" are gone for Unbound DNS since OPNsense 21.7, how do I configure Unbound DNS with DNSCRYPT-PROXY ?
Quote from: JohnnyBeee on August 14, 2021, 10:05:17 amNow that the "custom options" are gone for Unbound DNS since OPNsense 21.7, how do I configure Unbound DNS with DNSCRYPT-PROXY ?It appears that the only straight way is Enable Forwarding Mode with DNSCrypt-Proxy being listed in system DNS. Ugly and will also create madness with multiple WANs.
Quote from: ingvarr on August 14, 2021, 03:12:03 pmQuote from: JohnnyBeee on August 14, 2021, 10:05:17 amNow that the "custom options" are gone for Unbound DNS since OPNsense 21.7, how do I configure Unbound DNS with DNSCRYPT-PROXY ?It appears that the only straight way is Enable Forwarding Mode with DNSCrypt-Proxy being listed in system DNS. Ugly and will also create madness with multiple WANs.The only problem with that is the port. You cannot specify a port in the system settings and you cannot have 2 services listening on the same port (53).So am I right to assume that the custom options have only disappeared from the configuration GUI but are still taken into account when entered in unbound.conf?
Advanced Configurations in https://docs.opnsense.org/manual/unbound.html#advanced-configurationsis describing new way to add custom option into unbound.So I did create file/usr/local/etc/unbound.opnsense.d/dns-crypt-forward.confwith this contentserver:do-not-query-localhost: noforward-zone: name: "." forward-addr: 127.0.0.1@5353 forward-addr: ::1@5353command configctl unbound check is OK with that now, question is how to check if unbound is forwarding queries to dns-cryopt?so trying these webs:- http://verteiltesysteme.net/ saying OK- https://dnsleaktest.com/ running extetended test and result is list of different DNS resolvers from different countries- https://cmdns.dev.dns-oarc.net/ looks OK