DNS Best practices

Started by Zayan5117, Today at 12:34:19 PM

Previous topic - Next topic
I've recently setup my OPNsense firewall with DNS failover, currently it goes
1. Pi-Hole (Running on a primary server)
2. AdGuard (Running on a separate server)
3. Google DNS
4. Quad9
5. Cloudflare
I'm wondering though if there are any issue that can arise or if there's a best practice as I'm using the "Use System Nameservers" in Unbound DNS instead of unbound itself
Any tips or recommendations would be appreciated

It's a bit overkill. But there are no specific problems with it.

Quote from: Zayan5117 on Today at 12:34:19 PMI've recently setup my OPNsense firewall with DNS failover
May I ask how exactly ?

The reason I am asking is that a lot of people seem to think that configuring a device with multiple DNS Servers will give them DNS Redundancy in theory while it does not work like that in the real world !!

A well known example :
- Primary DNS = Pi-Hole/AdGuard
- Secondary DNS = Google/Quad9/CloudFlare

And then people wonder why their adblocking does not always work, because they expect the Secondary DNS to be used only when the Primary DNS is DOWN and not all the time at random moments...
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)