DNS failures after upgrade to 25.7 series - NOT solved as I thought

Started by pseudonym3k, August 02, 2025, 10:18:47 PM

Previous topic - Next topic
I was getting a lot of "server not found" browser messages after the upgrade to 25.7. All would seem OK for a while, then there'd be a period of failures. (Multiple devices, wired and wireless, and multiple browsers on those devices). Also, most devices were laggy at intervals, without any error messages. It would just take a long time before any result would appear (in the case of browsing).

I previously had Unbound enabled (it came that way by default). I did nothing further with it. In System->Settings->General, I had specified three DNS server IPs. Nothing more for DNS. It's been this way for a couple of years, and no trouble here that I'm aware of.

After upgrade to 25.7, the problems came.

In searching the 'net for help, I stumbled on a setup post for Unbound that had me mark Enable DNSSEC Support, Register ISC DHCP4 Leases, and optionally Flush DNS Cache during reload, which I also marked. After applying the changes I rebooted.

It has now been several hours and I have not seen any DNS failures or experienced any lags. Performance is quite snappy again.

I assume what I had was a poorly configured DNS situation that was better tolerated before 25.7.

Most people here are far beyond me in config and expertise, I'm just posting in case it helps someone.

(Cable modem -> Protectli Vault with OPNsense -> Cisco switch -> wired clients and one wireless AP for the rest. Basic install setup plus some reserved DHCP LAN IPs.)


***ETA***: All had been working fine for more than 24 hours, when suddenly again nothing is getting DNS resolved. Unbound DNS reporting showed a sharp drop and 0% of queries resolving.

I tried restarting Unbound service, tried stopping/pause/starting, tried flushing the Unbound cache. Resorted to reboot OPNsense via WebUI menu and all is working again.

If anyone has any ideas on what else I can look at or do, I would really appreciate the help.


***ETA2***: Eight hours ago, I cleared Unbound's cache, disabled Unbound, rebooted, so OPNsense would use the DNS servers in System -> Settings -> General directly. All seems to be working fine so far, will continue to monitor. Did go more than 24 hours with the last change, though, so will check back in tomorrow. Meanwhile please let me know any ideas. Thank you.

It's a week later and everything is still working and stable with Unbound disabled. My setup is about as simple as it gets, so it just seems odd that it's not happening to more people. Not needing to use it is one thing, but being the default install it shouldn't cause problems. I will try again sometime in the next few weeks to enable it and see what happens.

I'm having the same issue. Just installed opnsense for the first time to evaluate it. Couldn't reach opnsense.org to read documentation!. After I disabled Unbound and set dns listen port to blank in dnsmasq I can access this site.
Can I install older non-broken version of opnsense?

You can find them here: https://pkg.opnsense.org/releases/

I installed OPNsense initially on UFS filesystem. I did not know anything about ZFS, or using Proxmox VM for OPNsense. (I am familiar with VMs, I have a dozen+ running under VirtualBox for a variety of uses. Just didn't occur to me for OPNsense.)

I'm sticking with 25.7 for now, in case someone steps up with some ideas for getting Unbound working so I can try them. If I find myself wanting to downgrade, I'll definitely go ZFS filesystem now that I've read more about it, and maybe Proxmox VM as well. Suggest you read up and consider same if you're not familiar, unless you already have an easier recovery than a format and install.

Thanks for posting, I'm sorry it's happened to you but glad to know it's not just me.