you don't say where is OPN in the chain. Please add that and confirm what is the Draytek Vigor doing, if anything other than dialing the PPoE creds.On a "normal" setup where OPN is the firewall and router between your WAN and LANs, the firewall live view you screenshoted is the one where you trace the incoming call to that DNS server. In short, it will give you the ip of the client initiating the connection: into the LAN is attached to, gets processed by rules i.e. allowed or denied, then out of WAN. Then response back is processed in reverse.
How is DNS configured on your system? Under General? Unbound? How should your modem request DNS from your OPNsense? What are these porkbun domains resolved? Anybody from your LAN? Any client with strange DNS settings? Which rules on LAN?So many questions..
Like said. The connection to this porkbun stuff is initiated over the PPPoE interface(WAN), nowhere else.
First off, the Draytek cannot do any DNS lookups unless you have configured it to do so. It is configured as a bridge, probably you did not even assign a virtual IP on your WAN port in order to be abled to access its web interface and even if you did, you most probably did not allow traffic from its IP to the internet.Porkbun is a hoster who also sells domains, so that the DNS requests you see are most probably recursive queries for domains hosted there directed at their nameservers. I would argue that some program on your PC or IoT device tries to phone home to somewhere and in the process, it resolves domains.This could be malware activity, but is does not have to be. I would look at the content of the queries and go from there.
Nope. See my last post.
All I am saying is that it is viertually impossible that this traffic comes from the Draytek.You say that you intercept the SSL traffic. Isn't that what I wrote? If you use a transparent proxy, the DNS queries for the domains originate at your OpnSense, so you will not see them on other interfaces.Why don't you inspect the DNS queries directed at the porkbun NS servers? Only this can shed light on what is being asked for and give a hint as to what is causing this.