I want to know if I can use HA proxy for this purpose.
I don't use unbound for homeassistant but for other haproxy services that depend also on LE and I don't have problems. Inside and vpn are redirected to the local address (the new virt-ip of the haproxy-frontend) but LE is working and looking for the official dns-servers.Edit: the condition and rule is simple:cond: host starts (match or end will most likely be also possible) with: fqdn / or something like itrule: it cond -> execute function use backend ...rule selected/applied on the frontend then.Best regards,Bernd
Why don’t you just use split-dns for this? OPNsense is handling letsencrypt on public ip. Then you define an override in unbound for the same hostname as you used for the letsencrypt cert with the internal IP of the OPNsense.