How do i configure DNS Unbound to use the local Unbound cache and ask root-DNS-Servers only, while at the same time make sure the queries send out to these servers, are all legit and can be trusted using DNSSEC?
@Comet, he did answer your question. It's just that the answer for your question requires a few assumptions to be made, and is more nuanced than "just click that one checkbox".
I see that under System: Settings: General, under "DNS servers" there is a place where you can specify up to five DNS servers, but I'm not quite clear on how that's used.
There is a dropdown next to each DNS server field under "Use gateway" and the choices are "NONE" or "WAN_DHCP - wan - (wan IP address)" - which should I use?
Then at the bottom there are two options, "Allow DNS server list to be overridden by DHCP/PPP on WAN" which is currently checked
and "Do not use the DNS Forwarder/Resolver as a DNS server for the firewall" which is currently not checked
And also, by default when I set this up, under Services: Unbound DNS: General, "Enable DNS Resolver" is checked
Uncheck this. This will disable unbound completely and Google's DNS servers will be assigned to your clients.When it's disabled, all other unbound settings don't matter.
If DNSmasq AND Unbound are disabled, who is going to do the forwarding to the Google DNS?
Quote from: Oxygen61 on April 25, 2018, 08:26:18 pmIf DNSmasq AND Unbound are disabled, who is going to do the forwarding to the Google DNS? There won't be any forwarding because it's not required. If dnsmasq and unbound are disabled, the DHCP server assigns the DNS servers configured on the General page to the clients. So the clients query the Google DNS servers directly. In this scenario OPNsense is not involved in DNS at all.
@everyone but comet: don't get in an argue with comet!!! (!)Just answer his question(s), don't assume, don't ask, don't explain!Just! Answer! His! Questions!Why?The answer lies within his history of posts, topics and answers here, on this forum. If you care to check his profile, you will see comet expects nothing more then ”key, bull-eyed answers”, or else will get into an aggressive arguing; at least three quarters of his history is a continuous arguing.
You were given a perfectly satisfactory reply to your initial question
Your answer to the initial reply could have been phrased a bit more politely and brief, you might then have got the answer you wanted.
Your replies are argumentative, you attack or patronise someone that tries to help you then complain that your under 'personal attack', you need to chill out and be a bit more pleasant to those trying to help you otherwise yopu will alienate more people on these forums.
If you decide to write another one of your essays in response to this post then I, for one, will not be reading or answering it.
I will rephrase your question so that it works the best for you Sorry, not sorry. QuoteHow do i configure DNS Unbound to use the local Unbound cache and ask root-DNS-Servers only, while at the same time make sure the queries send out to these servers, are all legit and can be trusted using DNSSEC?Glad you asked.