LAN w/ Static V4 IP-------------------10.0.100.200/24 |10.0.100.208/24 |10.0.100.207/24 | Static LAN10.0.100.230/24 |---- LAN ---- 10.0.100.1 OPNsense w/ Unbound ----- WAN DHCP V4 and V610.0.100.240/24 | DHCP V6 and V410.0.100.220/24 |10.0.100.210/24 |
$ more unbound.conf########################### Unbound Configuration############################# Server configuration##server:chroot: /var/unboundusername: unbounddirectory: /var/unboundpidfile: /var/run/unbound.pidroot-hints: /root.hintsuse-syslog: yesport: 53verbosity: 1hide-identity: yeshide-version: noharden-referral-path: nodo-ip4: yesdo-ip6: yesdo-udp: yesdo-tcp: yesdo-daemonize: yesmodule-config: "validator iterator"cache-max-ttl: 86400cache-min-ttl: 0harden-dnssec-stripped: yesserve-expired: nooutgoing-num-tcp: 10incoming-num-tcp: 10num-queries-per-thread: 4096outgoing-range: 8192infra-host-ttl: 900infra-cache-numhosts: 10000unwanted-reply-threshold: 0jostle-timeout: 200msg-cache-size: 4mrrset-cache-size: 8mnum-threads: 1msg-cache-slabs: 2rrset-cache-slabs: 2infra-cache-slabs: 2key-cache-slabs: 2auto-trust-anchor-file: /var/unbound/root.keyprefetch: noprefetch-key: no# Interface IP(s) to bind tointerface: 0.0.0.0interface: ::0interface-automatic: yes# Outgoing interfaces to be usedoutgoing-interface: 192.168.1.92outgoing-interface: 2605:6000:151b:22a4:a00:27ff:fe90:261# DNS Rebinding# For DNS Rebinding prevention## All these addresses are either private or should not be routable in the global IPv4 or IPv6 internet.## IPv4 Addresses#private-address: 0.0.0.0/8 # Broadcast addressprivate-address: 10.0.0.0/8private-address: 100.64.0.0/10private-address: 127.0.0.0/8 # Loopback Localhostprivate-address: 169.254.0.0/16private-address: 172.16.0.0/12private-address: 192.0.0.0/24 # IANA IPv4 special purpose netprivate-address: 192.0.2.0/24 # Documentation network TEST-NETprivate-address: 192.168.0.0/16private-address: 198.18.0.0/15 # Used for testing inter-network communicationsprivate-address: 198.51.100.0/24 # Documentation network TEST-NET-2private-address: 203.0.113.0/24 # Documentation network TEST-NET-3private-address: 233.252.0.0/24 # Documentation network MCAST-TEST-NET## IPv6 Addresses#private-address: ::1/128 # Loopback Localhostprivate-address: 2001:db8::/32 # Documentation network IPv6private-address: fc00::/8 # Unique local address (ULA) part of "fc00::/7", not defined yetprivate-address: fd00::/8 # Unique local address (ULA) part of "fc00::/7", "/48" prefix groupprivate-address: fe80::/10 # Link-local address (LLA)# Set private domains in case authoritative name server returns a Private IP addressprivate-domain: "lan"domain-insecure: "lan"# Access listsinclude: /var/unbound/access_lists.conf# Static host entriesinclude: /var/unbound/host_entries.conf# DHCP leases (if configured)include: /var/unbound/dhcpleases.conf# Domain overridesinclude: /var/unbound/domainoverrides.conf# Unbound custom optionsnameserver 8.8.8.8# Forwardingforward-zone: name: "." forward-addr: 192.168.1.1remote-control: control-enable: yes control-interface: 127.0.0.1 control-port: 953 server-key-file: /var/unbound/unbound_server.key server-cert-file: /var/unbound/unbound_server.pem control-key-file: /var/unbound/unbound_control.key control-cert-file: /var/unbound/unbound_control.pem$