tcpdump -v -i igb0 dst port 53 # LAN showing SERVFAILS, when DNS stopped workingtcpdump -v -i igb1 dst port 853 # WAN when DoT enabled
After this (I was pretty sure a fresh install would help, because migration could have screwed things up maybe), I decided to disable DNSSEC and DoT, but leave Unbound DNS as default DNS.This setup is now stable for at least 24 hours!
Hi, valid point and thanks for the advice, I can give it a try and based on the setup guide on quad9 its anyway not mentioned https://www.quad9.net/support/set-up-guides/setup-opnsense-and-dns-over-tls.