OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • Unbound Problems
« previous next »
  • Print
Pages: [1] 2

Author Topic: Unbound Problems  (Read 9228 times)

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Unbound Problems
« on: February 10, 2018, 09:05:38 am »
Hey guys,

i have strange problems with unbound and domain overrides.
I have configured a local domain override with xxx.local pointing to my domain controller and a reverse override also pointing on my domain controller.
If i check the resolution via Interfaces-Diagnostics-DNS Lookup it resolves the ip only on each 3rd or 4th try.
Attached some screens.
EDIT: I read somewhere that unbound could have problems with domains named *.local?

Thanks for help!
« Last Edit: February 10, 2018, 09:08:07 am by AndyX90 »
Logged

astrandb

  • Newbie
  • *
  • Posts: 15
  • Karma: 5
    • View Profile
Re: Unbound Problems
« Reply #1 on: February 10, 2018, 10:02:03 am »
Try to enter following in Custom options in Unboud settings:
Code: [Select]
server:
domain-insecure: "yourdomain.local"
Logged

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Unbound Problems
« Reply #2 on: February 10, 2018, 10:10:52 am »
I did that, but the same behaviour.
If i click DNS-Lookup it resolves, but if i do it 5 times, it resolves 3 or 4 correct and the rest not.
So it's a ~50% chance...
Logged

astrandb

  • Newbie
  • *
  • Posts: 15
  • Karma: 5
    • View Profile
Re: Unbound Problems
« Reply #3 on: February 10, 2018, 12:17:56 pm »
You could also try to restrict Outgoing network interfaces to LAN only.
Logged

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Unbound Problems
« Reply #4 on: February 10, 2018, 01:23:46 pm »
That would not be my favor. I want to use unbound as dns-resolver for internet-requests too.
Logged

astrandb

  • Newbie
  • *
  • Posts: 15
  • Karma: 5
    • View Profile
Re: Unbound Problems
« Reply #5 on: February 10, 2018, 05:15:25 pm »
When I look deeper I have similar problem.
I also have domain override for a .local domain. DNS lookup never fails when I do it from a connected pc or Linux client. However, when I test from the console on one of my OPNsense boxes I also get intermittent failures.
Code: [Select]
drill host.mydomain.localFails 25-75% of tries
Code: [Select]
drill @192.168.16.1 host.mydomain.local Works every time
Code: [Select]
drill ikea.comWorks every time

Something odd is going on.
Logged

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Unbound Problems
« Reply #6 on: February 10, 2018, 05:21:12 pm »
Yeah i have multiple machines and the problem occurs on each of them..

Btw. my other domains don't end with .local.

Gesendet von meinem Pixel 2 XL mit Tapatalk
« Last Edit: February 10, 2018, 05:23:21 pm by AndyX90 »
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Unbound Problems
« Reply #7 on: February 10, 2018, 05:40:09 pm »
Why don't you configure your DHCP clients (from OPNsense DHCp server, assuming that's what you are using) to use the domain DNS server, and the DNS server on the DC (or wherever it is) to forward queries to OPNsense?
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

advcron

  • Newbie
  • *
  • Posts: 19
  • Karma: 1
    • View Profile
Re: Unbound Problems
« Reply #8 on: February 10, 2018, 06:00:13 pm »
What about configure dnsmasq to forward ad domain to dc?

Wysłane z mojego Mi-4c przy użyciu Tapatalka

Logged

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Unbound Problems
« Reply #9 on: February 10, 2018, 06:10:14 pm »
Quote from: elektroinside on February 10, 2018, 05:40:09 pm
Why don't you configure your DHCP clients (from OPNsense DHCp server, assuming that's what you are using) to use the domain DNS server, and the DNS server on the DC (or wherever it is) to forward queries to OPNsense?
I want the Firewall itself to resolve my internal stuff..
My DC is DHCP and DNS Server.

Gesendet von meinem Pixel 2 XL mit Tapatalk
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Unbound Problems
« Reply #10 on: February 10, 2018, 06:32:00 pm »
Quote from: AndyX90 on February 10, 2018, 06:10:14 pm
I want the Firewall itself to resolve my internal stuff..
My DC is DHCP and DNS Server.

Gesendet von meinem Pixel 2 XL mit Tapatalk

Did you configure the same domain in OPNsense?
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Unbound Problems
« Reply #11 on: February 10, 2018, 06:34:32 pm »


Quote from: elektroinside on February 10, 2018, 06:32:00 pm
Quote from: AndyX90 on February 10, 2018, 06:10:14 pm
I want the Firewall itself to resolve my internal stuff..
My DC is DHCP and DNS Server.

Gesendet von meinem Pixel 2 XL mit Tapatalk

Did you configure the same domain in OPNsense?

Yes.

Gesendet von meinem Pixel 2 XL mit Tapatalk

Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Unbound Problems
« Reply #12 on: February 10, 2018, 06:58:35 pm »
Strange.. I don't have a .local domain (I have another one), and initially I had your setup (which worked perfectly), then I switched to the one I mentioned in my previous comment (also works perfectly, and I actually threw in a Pi-hole as well as an added bonus)... I'm highly dependent on a good DNS chain as I use (and enforce) smart card authentication. It never failed on me.. Sorry to hear you are having problems.
« Last Edit: February 10, 2018, 07:01:54 pm by elektroinside »
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Unbound Problems
« Reply #13 on: February 10, 2018, 07:30:17 pm »
It is domain-name independent. For example on other machines i have domains named *.lan or *.localdomain and the behaviour is the same :-/

Gesendet von meinem Pixel 2 XL mit Tapatalk

Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Unbound Problems
« Reply #14 on: February 10, 2018, 09:21:57 pm »
Windows clients append the domain suffix to hostnames, even if unqualified names are used (this is a feature called DNS devolution). So there are no "domain-name independent" names. Try nslookup from a client.
macOS clients hate .local domains.

If you don't have a DNS server that resolves the FQDN, or if you have multiple DNS servers and you did not configure the chain properly (forward lookups/DNS zones/root hints), or your domains are public domain names, you will have problems exactly as the ones you described (with the clients, can't say for sure if this happens from OPNsense itself). There's no way around that.

From my experience, it's an unrecommended design to override private domains, I personally never do. The right way to do it (IMO) is to query the DNS servers directly and configure correctly the forward lookups/root hints/DNS zones. The local DNS servers in question will also forward queries if they fail (for any reason) to resolve the query, ending up who knows where.

And there's the warning in OPNsense (attached image).
« Last Edit: February 10, 2018, 09:36:31 pm by elektroinside »
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • Unbound Problems
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2