OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 22.7 Legacy Series »
  • GUI generates a flawed UNBOUND configuration
« previous next »
  • Print
Pages: [1]

Author Topic: GUI generates a flawed UNBOUND configuration  (Read 1055 times)

redstonemason

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
GUI generates a flawed UNBOUND configuration
« on: January 05, 2023, 09:32:00 pm »
I decided to move to OPNsense from pfSense in my LAB in order to easily get IPv6 working on my new ISP (Rogers Canada).

I performed:

1) Installed from the latest image "OPNsense-22.7-OpenSSL-vga-amd64.img".

2) Ran "System/Status/Check For Updates" and installed"22.7.10_2 (amd64/OpenSSL)".

3) Set "DNS Servers" to 1.1.1.1 and 9.9.9.9 in "System/General/Settings".

4) Disabled "System Nameservers" by unckecking "Use System NameServers" in "Services: Unbound DNS: DNS over TLS".

5) Setup "Custom Forwarding" in "Services: Unbound DNS: DNS over TLS" with "1.1.1.1 853" and "9.9.9.9 853".

6) Ran

    # configctl unbound check

   Got
   [1672949530] unbound-checkconf[37450:0] error: duplicate forward zone . ignored.
   no errors in /var/unbound/unbound.conf

This is the contents of my "/var/unbound/etc/dot.conf":
Code: [Select]

# Forward zones
forward-zone:
  name: "."
  forward-addr: 1.1.1.1@853
  forward-addr: 9.9.9.9@853

# Forward zones over TLS
server:
  tls-cert-bundle: /etc/ssl/cert.pem

forward-zone:
  name: "."
  forward-tls-upstream: yes
  forward-addr: 1.1.1.1@853
  forward-addr: 9.9.9.9@853


So the GUI definitely generates a duplicate "." zone.

BTW, I do score 100% on https://internet.nl/connection


« Last Edit: January 05, 2023, 10:19:47 pm by redstonemason »
Logged
Long time pfSense User
Permanently Converting to OPNsense.

OPNsense 22.7.10_2-amd64
FreeBSD 13.1-RELEASE-p5
OpenSSL 1.1.1s 1 Nov 2022

Fright

  • Hero Member
  • *****
  • Posts: 1777
  • Karma: 164
    • View Profile
Re: GUI generates a flawed UNBOUND configuration
« Reply #1 on: January 06, 2023, 09:42:44 am »
first one
Code: [Select]
# Forward zones
forward-zone:
  name: "."
  forward-addr: 1.1.1.1@853
  forward-addr: 9.9.9.9@853
is from Services: Unbound DNS: Query Forwarding
Logged

redstonemason

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: GUI generates a flawed UNBOUND configuration
« Reply #2 on: January 06, 2023, 04:42:53 pm »
I don't recall adding those entries into that tab. Were they auto-applied? Are they necessary?
Logged
Long time pfSense User
Permanently Converting to OPNsense.

OPNsense 22.7.10_2-amd64
FreeBSD 13.1-RELEASE-p5
OpenSSL 1.1.1s 1 Nov 2022

Fright

  • Hero Member
  • *****
  • Posts: 1777
  • Karma: 164
    • View Profile
Re: GUI generates a flawed UNBOUND configuration
« Reply #3 on: January 06, 2023, 07:09:06 pm »
Quote
Were they auto-applied? Are they necessary?
no and no  :)
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 22.7 Legacy Series »
  • GUI generates a flawed UNBOUND configuration
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2