root@uribou:~ # cat /usr/local/etc/unbound.opnsense.d/dot.confserver: do-not-query-localhost: no# Forward zonesforward-zone: name: "." forward-addr: 127.0.0.1@5353root@uribou:~ # dig opnsense.org @127.0.0.1 -p 53; <<>> DiG 9.18.16 <<>> opnsense.org @127.0.0.1 -p 53;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 4928;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;opnsense.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 16:25:22 JST 2023;; MSG SIZE rcvd: 41root@uribou:~ # dig opnsense.org @127.0.0.1 -p 5353; <<>> DiG 9.18.16 <<>> opnsense.org @127.0.0.1 -p 5353;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46478;; flags: qr rd ra ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;opnsense.org. IN A;; ANSWER SECTION:opnsense.org. 899 IN A 178.162.131.118;; Query time: 38 msec;; SERVER: 127.0.0.1#5353(127.0.0.1) (UDP);; WHEN: Thu Jul 20 16:25:31 JST 2023;; MSG SIZE rcvd: 57
error: SERVFAIL <opnsense.org. A IN>: all the configured stub or forward servers failed, at zone . no server to query nameserver addresses not usable have no nameserver names
unbound unbound 40899 3 stream /tmp/php-fastcgi.socket-1unbound unbound 40899 6 udp4 10.11.0.1:53 *:*unbound unbound 40899 7 tcp4 10.11.0.1:53 *:*unbound unbound 40899 8 udp4 127.0.0.1:53 *:*unbound unbound 40899 9 tcp4 127.0.0.1:53 *:*unbound unbound 40899 10 udp4 10.11.0.1:53 *:*unbound unbound 40899 11 tcp4 10.11.0.1:53 *:*unbound unbound 40899 12 udp4 127.0.0.1:53 *:*unbound unbound 40899 13 tcp4 127.0.0.1:53 *:*unbound unbound 40899 14 udp4 10.11.0.1:53 *:*unbound unbound 40899 15 tcp4 10.11.0.1:53 *:*unbound unbound 40899 16 udp4 127.0.0.1:53 *:*unbound unbound 40899 17 tcp4 127.0.0.1:53 *:*unbound unbound 40899 18 udp4 10.11.0.1:53 *:*unbound unbound 40899 19 tcp4 10.11.0.1:53 *:*unbound unbound 40899 20 udp4 127.0.0.1:53 *:*unbound unbound 40899 21 tcp4 127.0.0.1:53 *:*unbound unbound 40899 22 tcp4 127.0.0.1:953 *:*unbound unbound 40899 23 dgram -> /var/run/logprivunbound unbound 40899 24 stream -> ??unbound unbound 40899 25 stream -> ??unbound unbound 40899 26 stream -> ??unbound unbound 40899 27 stream -> ??unbound unbound 40899 28 stream -> ??unbound unbound 40899 29 stream -> ??unbound unbound 40899 30 stream -> ??unbound unbound 40899 31 stream -> ??root dnscrypt-p 26384 7 udp46 *:5353 *:*root dnscrypt-p 26384 8 tcp46 *:5353 *:*
root@uribou:~ # dig opnsense.org @127.0.0.1 -p 53; <<>> DiG 9.18.16 <<>> opnsense.org @127.0.0.1 -p 53;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 20714;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;opnsense.org. IN A;; ANSWER SECTION:opnsense.org. 571 IN A 178.162.131.118;; Query time: 400 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 20:02:07 JST 2023;; MSG SIZE rcvd: 57
root@uribou:~ # dig opnsense.org @127.0.0.1 -p 53; <<>> DiG 9.18.16 <<>> opnsense.org @127.0.0.1 -p 53;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 33337;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;opnsense.org. IN A;; Query time: 13 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 20:05:13 JST 2023;; MSG SIZE rcvd: 41
root@uribou:~ # sockstatUSER COMMAND PID FD PROTO LOCAL ADDRESS FOREIGN ADDRESS root python3.9 33321 5 dgram -> /var/run/logprivroot daemon 33124 5 dgram -> /var/run/logprivunbound unbound 31977 5 udp4 10.11.0.1:53 *:*unbound unbound 31977 6 tcp4 10.11.0.1:53 *:*unbound unbound 31977 7 udp4 127.0.0.1:53 *:*unbound unbound 31977 8 tcp4 127.0.0.1:53 *:*unbound unbound 31977 9 udp4 10.11.0.1:53 *:*unbound unbound 31977 10 tcp4 10.11.0.1:53 *:*unbound unbound 31977 11 udp4 127.0.0.1:53 *:*unbound unbound 31977 12 tcp4 127.0.0.1:53 *:*unbound unbound 31977 13 udp4 10.11.0.1:53 *:*unbound unbound 31977 14 tcp4 10.11.0.1:53 *:*unbound unbound 31977 15 udp4 127.0.0.1:53 *:*unbound unbound 31977 16 tcp4 127.0.0.1:53 *:*unbound unbound 31977 17 udp4 10.11.0.1:53 *:*unbound unbound 31977 18 tcp4 10.11.0.1:53 *:*unbound unbound 31977 19 udp4 127.0.0.1:53 *:*unbound unbound 31977 20 tcp4 127.0.0.1:53 *:*unbound unbound 31977 21 tcp4 127.0.0.1:953 *:*unbound unbound 31977 22 dgram -> /var/run/logprivunbound unbound 31977 23 stream -> ??unbound unbound 31977 24 stream -> ??unbound unbound 31977 25 stream -> ??unbound unbound 31977 26 stream -> ??unbound unbound 31977 27 stream -> ??unbound unbound 31977 28 stream -> ??unbound unbound 31977 29 stream -> ??unbound unbound 31977 30 stream -> ??
root@uribou:~ # dig opnsense.org ; <<>> DiG 9.18.16 <<>> opnsense.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 47216;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;opnsense.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 20:29:40 JST 2023;; MSG SIZE rcvd: 41
2023-07-20T20:33:15 Debug unbound [31977:2] debug: cache memory msg=135044 rrset=132120 infra=10617 val=0 2023-07-20T20:33:15 Error unbound [31977:2] error: SERVFAIL <opnsense.org. A IN>: all the configured stub or forward servers failed, at zone . no server to query nameserver addresses not usable have no nameserver names 2023-07-20T20:33:15 Debug unbound [31977:2] debug: return error response SERVFAIL 2023-07-20T20:33:15 Debug unbound [31977:2] debug: configured stub or forward servers failed -- returning SERVFAIL 2023-07-20T20:33:15 Informational unbound [31977:2] info: processQueryTargets: opnsense.org. A IN 2023-07-20T20:33:15 Informational unbound [31977:2] info: resolving opnsense.org. A IN 2023-07-20T20:33:15 Debug unbound [31977:2] debug: iterator[module 1] operate: extstate:module_state_initial event:module_event_pass
root@uribou:~ # dig freebsd.org && dig openssl.org && dig icann.org && dig aarnet.edu.au && dig home.cern; <<>> DiG 9.18.16 <<>> freebsd.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 62566;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;freebsd.org. IN A;; ANSWER SECTION:freebsd.org. 1300 IN A 96.47.72.84;; Query time: 16 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:41:33 JST 2023;; MSG SIZE rcvd: 56; <<>> DiG 9.18.16 <<>> openssl.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 61269;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;openssl.org. IN A;; ANSWER SECTION:openssl.org. 3600 IN A 194.97.150.230;; Query time: 272 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:41:33 JST 2023;; MSG SIZE rcvd: 56; <<>> DiG 9.18.16 <<>> icann.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 55531;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;icann.org. IN A;; ANSWER SECTION:icann.org. 600 IN A 192.0.43.7;; Query time: 199 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:41:33 JST 2023;; MSG SIZE rcvd: 54; <<>> DiG 9.18.16 <<>> aarnet.edu.au;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19319;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;aarnet.edu.au. IN A;; ANSWER SECTION:aarnet.edu.au. 300 IN A 202.158.207.3;; Query time: 974 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:41:34 JST 2023;; MSG SIZE rcvd: 58; <<>> DiG 9.18.16 <<>> home.cern;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 55844;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;home.cern. IN A;; ANSWER SECTION:home.cern. 300 IN A 188.184.37.219;; Query time: 1016 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:41:35 JST 2023;; MSG SIZE rcvd: 54
root@uribou:~ # dig freebsd.org && dig openssl.org && dig icann.org && dig aarnet.edu.au && dig home.cern; <<>> DiG 9.18.16 <<>> freebsd.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 53366;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;freebsd.org. IN A;; Query time: 2 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:44:59 JST 2023;; MSG SIZE rcvd: 40; <<>> DiG 9.18.16 <<>> openssl.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 7142;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;openssl.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:44:59 JST 2023;; MSG SIZE rcvd: 40; <<>> DiG 9.18.16 <<>> icann.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 47173;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;icann.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:44:59 JST 2023;; MSG SIZE rcvd: 38; <<>> DiG 9.18.16 <<>> aarnet.edu.au;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 29921;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;aarnet.edu.au. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:44:59 JST 2023;; MSG SIZE rcvd: 42; <<>> DiG 9.18.16 <<>> home.cern;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 30371;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;home.cern. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:44:59 JST 2023;; MSG SIZE rcvd: 38
root@uribou:~ # dig freebsd.org && dig openssl.org && dig icann.org && dig aarnet.edu.au && dig home.cern; <<>> DiG 9.18.16 <<>> freebsd.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 22237;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;freebsd.org. IN A;; Query time: 10 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:46:48 JST 2023;; MSG SIZE rcvd: 40; <<>> DiG 9.18.16 <<>> openssl.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 11238;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;openssl.org. IN A;; Query time: 3 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:46:48 JST 2023;; MSG SIZE rcvd: 40; <<>> DiG 9.18.16 <<>> icann.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 54659;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;icann.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:46:48 JST 2023;; MSG SIZE rcvd: 38; <<>> DiG 9.18.16 <<>> aarnet.edu.au;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 41278;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;aarnet.edu.au. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:46:48 JST 2023;; MSG SIZE rcvd: 42; <<>> DiG 9.18.16 <<>> home.cern;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 57233;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;home.cern. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:46:48 JST 2023;; MSG SIZE rcvd: 38
root@uribou:~ # dig freebsd.org && dig openssl.org && dig icann.org && dig aarnet.edu.au && dig home.cern; <<>> DiG 9.18.16 <<>> freebsd.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 59008;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;freebsd.org. IN A;; Query time: 1 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:48:04 JST 2023;; MSG SIZE rcvd: 40; <<>> DiG 9.18.16 <<>> openssl.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 23335;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;openssl.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:48:04 JST 2023;; MSG SIZE rcvd: 40; <<>> DiG 9.18.16 <<>> icann.org;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 41790;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;icann.org. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:48:04 JST 2023;; MSG SIZE rcvd: 38; <<>> DiG 9.18.16 <<>> aarnet.edu.au;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 16850;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;aarnet.edu.au. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:48:04 JST 2023;; MSG SIZE rcvd: 42; <<>> DiG 9.18.16 <<>> home.cern;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 48176;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1232;; QUESTION SECTION:;home.cern. IN A;; Query time: 0 msec;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP);; WHEN: Thu Jul 20 21:48:04 JST 2023;; MSG SIZE rcvd: 38