[Gelöst] Unbound-DNS Erweitert

Started by k0ns0l3, October 07, 2026, 10:05:13 AM

Previous topic - Next topic
October 07, 2026, 10:05:13 AM Last Edit: October 07, 2026, 01:38:33 PM by k0ns0l3
Hallo zusammen,
habe meine Pihole in Rente geschickt und zum OPNSense Unbound mit DNS-Server und DoT(DNS-over-TLS) gewechselt.

Wollte mal sehen ob die zusätzliche Empfehlungen zur Konfiguration haben.

Gibt es weitere Empfehlungen, um die Effektivität, Robustheit, Langlebigkeit usw. zu erhöhen.

Für Eure Hilfe schon mal vielen Dank im Voraus :))



LG k0ns0l3
"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System

Die Default-Konfiguration von Unbound in OPNsense ist effektiv, robust und langlebig. Was willst du denn erreichen?

Wenn du Blocklisten verwenden möchtest, empfehle ich, das nicht in Unbound zu tun, sondern AGH auf der OPNsense zu installieren. Und von DoH und DoT rate ich kategorisch ab, genau so wie von Upstream-Servern, aber das muss jeder für sich selbst definieren. Ich möchte keiner dritten Partei meine DNS-Abfragen geben.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

also einfach alles wieder Entrümpeln
"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System

und dein meinung ist lieber zu telekom direkt,

Server Name:    dns.telekom.de
Port Nummer:   853 (Standardport für DoT)

lg k0ns0l3
"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System

Zu gar keinem Upstream. Einfach Unbound als rekursiven DNS-Server betreiben. DNS braucht keinen Server beim Provider und war auch nie so gedacht.

Hier hab ich mal beschrieben, wie DNS funktioniert:

https://forum.opnsense.org/index.php?topic=24783.msg118859#msg118859
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

THX ;)

lg k0ns0l3
"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System

Quote from: Patrick M. Hausen on October 07, 2026, 10:12:50 AMDie Default-Konfiguration von Unbound in OPNsense ist effektiv, robust und langlebig. Was willst du denn erreichen?

Wenn du Blocklisten verwenden möchtest, empfehle ich, das nicht in Unbound zu tun, sondern AGH auf der OPNsense zu installieren. Und von DoH und DoT rate ich kategorisch ab, genau so wie von Upstream-Servern, aber das muss jeder für sich selbst definieren. Ich möchte keiner dritten Partei meine DNS-Abfragen geben.

Warum keine Blocklisten in Unbound?
Mit AGH meinst Du das Plugin AdguardHome? Was macht das Plugin besser?

Performance - es skaliert besser.
UI.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

DNS-Auflösungszeit nur mit Unbound mit Blockliste ohne AGH und einmal mit Unbound (ohne Blockliste) und AGH mit Blockliste ,zwei sehr große unterschiede.

lg k0ns0l3

"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System

 Habe grade Redirect Target Port (Destination NAT) umgeschaltet auf 5353 und sind jetzt bessere Resultate

lg k0ns0l3

 
   
"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System

Ich hab AGH auf allen Interfaces auf 53 laufen, keine NAT-Regeln.
Unbound lauscht auf 53053 und wird von AGH auf 127.0.0.1:53053 als Upstream benutzt.

5353 sollte man nicht verwenden, das das für mDNS reserviert ist. Evtl. willst du ja mal den multicast-dns-repeater einsetzen.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

ich bleibe vorerst bei 5353 , mit mDNS ich habe nicht vor danke für Hinweis ;))

lg k0ns0l3
"The quieter you become, the more you are able to hear...."

- OS:Debian GNU/Linux sid
- IPU662 System