2021-11-27T19:21:06 unbound[47763] [47763:2] debug: process_response: new external response event 2021-11-27T19:21:06 unbound[47763] [47763:6] debug: cache memory msg=269840 rrset=289047 infra=15986 val=267448 2021-11-27T19:21:06 unbound[47763] [47763:3] debug: tcp error for address ip4 1.0.0.1 port 853 (len 16) 2021-11-27T19:21:06 unbound[47763] [47763:6] debug: cache memory msg=269840 rrset=289047 infra=15986 val=267448 2021-11-27T19:21:06 unbound[47763] [47763:5] info: 8RDd mod1 rep AMS-efz.ms-acdc.office.com. A IN
2021-11-27T19:21:06 unbound[47763] [47763:3] debug: tcp error for address ip4 1.0.0.1 port 853 (len 16)
Hi,DoT with unbound on OPNsense 21.7.6 works for meTM Code: [Select]2021-11-27T19:21:06 unbound[47763] [47763:3] debug: tcp error for address ip4 1.0.0.1 port 853 (len 16)Seems like your unbound is not able to reach the server 1.0.0.1 on port 853.Can you ping 1.0.0.1?Do you get errors with openssl s_client -connect 1.0.0.1:853 on the OPNsense?KH
> those are request on your WAN side, does your clients really encrypt the DNS?Clients don't magically encrypt traffic when you set DoT upstream servers in Unbound GUI.Maybe you can start by how you enabled the DoT server on OPNsense if you want LAN traffic to be encrypted. Your setup is entirely unclear.Cheers,Franco
Thank you for your answer.those are request on your WAN side, does your clients really encrypt the DNS?
i was happy having Dot working for couple of weeks, after i updated today, i noticed it stops working.after some reboot it seems the dns is working but its exttremly slow....Code: [Select]2021-11-27T19:21:06 unbound[47763] [47763:2] debug: process_response: new external response event 2021-11-27T19:21:06 unbound[47763] [47763:6] debug: cache memory msg=269840 rrset=289047 infra=15986 val=267448 2021-11-27T19:21:06 unbound[47763] [47763:3] debug: tcp error for address ip4 1.0.0.1 port 853 (len 16) 2021-11-27T19:21:06 unbound[47763] [47763:6] debug: cache memory msg=269840 rrset=289047 infra=15986 val=267448 2021-11-27T19:21:06 unbound[47763] [47763:5] info: 8RDd mod1 rep AMS-efz.ms-acdc.office.com. A IN