root@<OPNSENSE>:~ # nslookup www.cnn.com;; Got SERVFAIL reply from 127.0.0.1Server: 127.0.0.1Address: 127.0.0.1#53** server can't find www.cnn.com: SERVFAIL
root@<OPNSENSE>:/var/log/resolver # tail -n 20 -f ./resolver_20241013.log<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66103"] [86469:2] debug: iterator[module 1] operate: extstate:module_wait_reply event:module_event_noreply<30>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66104"] [86469:2] info: iterator operate: query api.crowdsec.net.<DOMA.IN>. A IN<30>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66105"] [86469:2] info: processQueryTargets: api.crowdsec.net.<DOMA.IN>. A IN<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66106"] [86469:2] debug: configured stub or forward servers failed -- returning SERVFAIL<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66107"] [86469:2] debug: return error response SERVFAIL<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66108"] [86469:2] debug: cache memory msg=133580 rrset=132184 infra=11490 val=0<30>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66109"] [86469:2] info: 192.168.18.60 debug.opendns.com. TXT IN<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66110"] [86469:2] debug: worker request: max UDP reply size modified (1280 to max-udp-size)<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66111"] [86469:2] debug: iterator[module 1] operate: extstate:module_state_initial event:module_event_pass<30>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66112"] [86469:2] info: resolving debug.opendns.com. TXT IN<30>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66113"] [86469:2] info: processQueryTargets: debug.opendns.com. TXT IN<30>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66114"] [86469:2] info: sending query: debug.opendns.com. TXT IN<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66115"] [86469:2] debug: sending to target: <.> 149.112.112.112#853<31>1 2024-10-13T16:00:43+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66116"] [86469:2] debug: cache memory msg=133580 rrset=132184 infra=11490 val=0<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66117"] [86469:2] info: 127.0.0.1 www.cnn.com. A IN<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66118"] [86469:2] debug: iterator[module 1] operate: extstate:module_state_initial event:module_event_pass<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66119"] [86469:2] info: resolving www.cnn.com. A IN<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66120"] [86469:2] info: processQueryTargets: www.cnn.com. A IN<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66121"] [86469:2] debug: configured stub or forward servers failed -- returning SERVFAIL<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66122"] [86469:2] debug: return error response SERVFAIL<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66123"] [86469:2] info: dnsbl_module: attempting to open pipe<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66124"] [86469:2] info: dnsbl_module: successfully opened pipe<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66125"] [86469:2] info: 127.0.0.1 www.cnn.com. A IN SERVFAIL 0.000000 0 29<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66126"] [86469:2] debug: cache memory msg=133769 rrset=132184 infra=11490 val=0<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66127"] [86469:2] info: 127.0.0.1 1.opnsense.pool.ntp.org.<DOMA.IN>. A IN<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66128"] [86469:2] debug: iterator[module 1] operate: extstate:module_state_initial event:module_event_pass<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66129"] [86469:2] info: resolving 1.opnsense.pool.ntp.org.<DOMA.IN>. A IN<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66130"] [86469:2] info: processQueryTargets: 1.opnsense.pool.ntp.org.<DOMA.IN>. A IN<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66131"] [86469:2] debug: configured stub or forward servers failed -- returning SERVFAIL<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66132"] [86469:2] debug: return error response SERVFAIL<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66133"] [86469:2] info: 127.0.0.1 1.opnsense.pool.ntp.org.<DOMA.IN>. A IN SERVFAIL 0.000000 0 51<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66134"] [86469:2] debug: cache memory msg=133980 rrset=132184 infra=11490 val=0<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66135"] [86469:3] info: 127.0.0.1 1.opnsense.pool.ntp.org.<DOMA.IN>. A IN<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66136"] [86469:3] info: 127.0.0.1 1.opnsense.pool.ntp.org.<DOMA.IN>. A IN SERVFAIL 0.000000 1 51<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66137"] [86469:2] info: 127.0.0.1 1.opnsense.pool.ntp.org.<DOMA.IN>. AAAA IN<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66138"] [86469:2] debug: iterator[module 1] operate: extstate:module_state_initial event:module_event_pass<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66139"] [86469:2] info: resolving 1.opnsense.pool.ntp.org.<DOMA.IN>. AAAA IN<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66140"] [86469:2] info: processQueryTargets: 1.opnsense.pool.ntp.org.<DOMA.IN>. AAAA IN<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66141"] [86469:2] debug: configured stub or forward servers failed -- returning SERVFAIL<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66142"] [86469:2] debug: return error response SERVFAIL<30>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66143"] [86469:2] info: 127.0.0.1 1.opnsense.pool.ntp.org.<DOMA.IN>. AAAA IN SERVFAIL 0.000000 0 51<31>1 2024-10-13T16:00:46+02:00 <OPNSENSE>.<DOMA.IN> unbound 86469 - [meta sequenceId="66144"] [86469:2] debug: cache memory msg=134191 rrset=132184 infra=11490 val=0^Croot@<OPNSENSE>:/var/log/resolver #
please try restore unbound config only in firmware backup.
So, i copy all the blocklist and firewall rules into my notepad then create all the rules one by one. It takes few hours for me to migrate all the pfsense setting to opnsense unbound. Now, my firewall table entries and unbound blocklist are 4618097 and 2876467 respectively are running blazingly fast with n305 cpu and 32GB DDR5.
Go back to you question, before you do any changes of setting, please go to system=>configurations=>backups. you can backup the null or default setting into your hard driver before you start to change anything in the opnsense.
2024-10-26T17:39:57 Error unbound [74508:3] error: SSL_handshake syscall: Operation timed out 2024-10-26T17:39:56 Error unbound [74508:1] error: SSL_handshake syscall: Operation timed out
If you want my unbound blocklist, i can share to you. I just install a ultimate blocklist as core blocklist to remove 99% ads for daily web surfing. For the Bad IP filtering, i have added tenth badIP blocklists in firewall aliases which contribute firewall tables entries about 420000. Those entries block more than 90% scanner, hacker....daily.
My suggestion for OPN: don't use them and Unbound will be 100% solid. Instead use them in AdGuardHome on OPNSense. Straight forward installation. Add a repo, get an update of packages with the new repo, install and configure with a couple of clicks. Then add the lists on AdGH. And you get additional functionality too.
Can be but I am not suggesting that setup.AdGH does only ad blocking with lists. Other lists can also be added.Then it uses Unbound as upstream resolver.client -> AdGH -> Unbound -> Root servers (or others if you prefer)