OPNsense 23.1.1_2-amd64FreeBSD 13.1-RELEASE-p6OpenSSL 1.1.1t 7 Feb 2023
Adguard Home v0.107.25 - installed from mimugmail's repo "os-adguardhome-maxit" v1.8Unbound v1.17.1_2
***GOT REQUEST TO CHECK FOR UPDATES***Currently running OPNsense 23.1.1_2 at Thu Feb 23 23:22:38 GMT 2023Fetching changelog information, please wait... fetch: transfer timed outUpdating OPNsense repository catalogue...pkg: https://pkg.opnsense.org/FreeBSD:13:amd64/23.1/latest/meta.txz: No address recordrepository OPNsense has no meta file, using default settingspkg: https://pkg.opnsense.org/FreeBSD:13:amd64/23.1/latest/packagesite.pkg: No address recordpkg: https://pkg.opnsense.org/FreeBSD:13:amd64/23.1/latest/packagesite.txz: No address recordUnable to update repository OPNsenseUpdating mimugmail repository catalogue...pkg: https://opn-repo.routerperformance.net/repo/FreeBSD:13:amd64/meta.txz: No address recordrepository mimugmail has no meta file, using default settingspkg: https://opn-repo.routerperformance.net/repo/FreeBSD:13:amd64/packagesite.pkg: No address recordpkg: https://opn-repo.routerperformance.net/repo/FreeBSD:13:amd64/packagesite.txz: No address recordUnable to update repository mimugmailError updating repositories!pkg: Repository OPNsense cannot be opened. 'pkg update' requiredChecking integrity... done (0 conflicting)Your packages are up to date.***DONE***
Hostname:pkg.opnsense.orgServer:Result -Query failureError: error sending query: Could not send or receive, because of network error
Hostname:pkg.opnsense.orgServer:10.0.0.1Result -Type:AAnswer:pkg.opnsense.org. 30 IN A 89.149.211.205Server:10.0.0.1Query time: 0 msecType:AAAAAnswer:pkg.opnsense.org. 340 IN AAAA 2001:1af8:4f00:a005:5::Server:10.0.0.1Query time: 22 msec
Prefer IPv4 over IPv6:✘DNS Servers:noneAllow DNS server list to be overridden by DHCP/PPP on WAN:✘Do not use the local DNS service as a nameserver for this system:✘
Enable Unbound:✓Listen Port:5553Network Interfaces:LAN,WANEnable DNSSEC Support:✓Outgoing Network Interfaces:All
Server:9.9.9.9Port:853Verify CN:dns.quad9.netServer:149.112.112.112Port:853Verify CN:dns.quad9.netServer:1.1.1.1Port:853Verify CN:cloudflare-dns.comServer:1.0.0.1Port:853Verify CN:cloudflare-dns.com
Upstream DNS Servers:127.0.0.1:5553Bootstrap DNS Servers:127.0.0.1:5553Private reverse DNS Servers:127.0.0.1:5553Use private reverse DNS resolvers:✓Enable reverse resolving of clients' IP addresses:✓Enable DNSSEC:✓
root@OPNsense:~ # cat /etc/resolv.confdomain home.arpanameserver 127.0.0.1search home.arpa
Looks normal.Possibly ACL problem like Unbound/Adguard not accepting query from loopbackCan you try "drill google.com @127.0.0.1 -p 5553"If it works then you should check Adguard's ACL to allow query from 127.0.0.1 or loopback adapter
root@OPNsense:~ # drill google.com @127.0.0.1 -p 5553Error: error sending query: Could not send or receive, because of network error
What is your OPN LAN ip address?
root@OPNsense:~ # ping google.co.ukping: Unknown hostroot@OPNsense:~ # drill google.co.ukError: error sending query: Could not send or receive, because of network error
sockstat -l | grep 'unbound\|AdGuard'
pfctl -ddrill @localhost -p5553 google.compfctl -e
Try this and see if unbound is listening on the loopback:Code: [Select]sockstat -l | grep 'unbound\|AdGuard'If it does, then try this:Code: [Select]pfctl -ddrill @localhost -p5553 google.compfctl -eto make sure it is not a firewall issue.
root@OPNsense:~ # sockstat -l | grep 'unbound\|AdGuard'unbound unbound 57271 5 stream /tmp/php-fastcgi.socket-1unbound unbound 57271 8 udp4 10.0.0.1:5553 *:*unbound unbound 57271 9 tcp4 10.0.0.1:5553 *:*unbound unbound 57271 10 udp4 95.151.***.***:5553 *:*unbound unbound 57271 11 tcp4 95.151.***.***:5553 *:*unbound unbound 57271 12 udp4 127.0.0.1:5553 *:*unbound unbound 57271 13 tcp4 127.0.0.1:5553 *:*unbound unbound 57271 14 udp4 10.0.0.1:5553 *:*unbound unbound 57271 15 tcp4 10.0.0.1:5553 *:*unbound unbound 57271 16 udp4 95.151.***.***:5553 *:*unbound unbound 57271 17 tcp4 95.151.***.***:5553 *:*unbound unbound 57271 18 udp4 127.0.0.1:5553 *:*unbound unbound 57271 19 tcp4 127.0.0.1:5553 *:*unbound unbound 57271 20 udp4 10.0.0.1:5553 *:*unbound unbound 57271 21 tcp4 10.0.0.1:5553 *:*unbound unbound 57271 22 udp4 95.151.***.***:5553 *:*unbound unbound 57271 23 tcp4 95.151.***.***:5553 *:*unbound unbound 57271 24 udp4 127.0.0.1:5553 *:*unbound unbound 57271 25 tcp4 127.0.0.1:5553 *:*unbound unbound 57271 26 udp4 10.0.0.1:5553 *:*unbound unbound 57271 27 tcp4 10.0.0.1:5553 *:*unbound unbound 57271 28 udp4 95.151.***.***:5553 *:*unbound unbound 57271 29 tcp4 95.151.***.***:5553 *:*unbound unbound 57271 30 udp4 127.0.0.1:5553 *:*unbound unbound 57271 31 tcp4 127.0.0.1:5553 *:*unbound unbound 57271 32 tcp4 127.0.0.1:953 *:*root AdGuardHom 61200 13 udp4 10.0.0.1:53 *:*root AdGuardHom 61200 14 tcp4 10.0.0.1:53 *:*root AdGuardHom 61200 21 tcp4 10.0.0.1:8080 *:*root syslog-ng 19509 22 dgram /var/unbound/var/run/log
root@OPNsense:~ # pfctl -dlocalhost -p5553 google.compfctl -epf disabledroot@OPNsense:~ # drill @localhost -p5553 google.comError: error sending query: Could not send or receive, because of network errorroot@OPNsense:~ # pfctl -epf enabled
Yes good point about no upstreams if you clear out the DoT providers - I forgot my DoT upstreams go out in a different way. Put a non-DoT one for now, say 8.8.8.8 for now and test again please.
Do not use the local DNS service as a nameserver for this system:✘This setting controls as per help that by default localhost (127.0.0.1) will be used as the first nameserver when e.g. Dnsmasq or Unbound is enabled, so system can use the local DNS service to perform lookups. Checking this box omits localhost from the list of DNS servers. Therefore if you have it disabled, the system is not using the loopback and the system has no alternative to use.You could enable it and see it populate /etc/resolv.conf and I'm pretty sure the problem goes away.If however you want it disabled, you'll need to give the system an alternative ie. forward to AdGuard.
root@OPNsense:~ # cat /etc/resolv.confdomain home.arpasearch home.arpa