I do not know what the "bootstrap" is for from the top of my head but I also do not set this. If AGH forwards to a full capable local resolver, e.g. Unbound or BIND, only the "upstream" setting is necessary.
Yes.
If the forward DNS server is identical with the one keeping your local forward and reverse zones, than you do not need the "private reverse" setting. This is for the occasions when the two are different.
it states that ALL is recommended :-), but you can change it see also the opnsense manual: https://docs.opnsense.org/manual/settingsmenu.html
Do you have the same 192.168.1.1:53530 as the regular upstream DNS?
bind_host: 192.168.1.1bind_port: 3000beta_bind_port: 0...dns: bind_hosts: - 0.0.0.0 port: 53
Upstream DNS servers: 192.168.1.1:53530
Listen Port: 53530Interfaces: AllDNSSEC = onDHCP leases = onStatic mappings = onIpv6 link-local = onLocal Zone Type = transparent