home.social

#unbounddns — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #unbounddns, aggregated by home.social.

fetched live
  1. Also ein Flat LAN mit Fritz!Box, Pihole und rund 75 Netzwerkgeräten in ein ausgewachsenes Business LAN mit OPNsense, Omada, mehreren Access Points und alles schön getrennt in VLANS umzubauen, ist echt ne Lebensaufgabe, bis alles reibungslos funktioniert....... 😛

    #opnsense #omada #tplink #dnsmasq #unbounddns #selfhosted #network #netzwerk #fritzbox #homeassistant

  2. Also ein Flat LAN mit Fritz!Box, Pihole und rund 75 Netzwerkgeräten in ein ausgewachsenes Business LAN mit OPNsense, Omada, mehreren Access Points und alles schön getrennt in VLANS umzubauen, ist echt ne Lebensaufgabe, bis alles reibungslos funktioniert....... 😛

    #opnsense #omada #tplink #dnsmasq #unbounddns #selfhosted #network #netzwerk #fritzbox #homeassistant

  3. Aufgrund des Videos teste ich gerade den DNS Server von #IPv64 und auch darüber DNS over TLS. Und das unter #OPNsense mit #UnboundDNS . Bis jetzt keine Fehler erkennbar aber das muss nichts heißen. Wie teste ich aber das DNS over TLS?

    youtu.be/eVd3dKDwfIc?si=RpbMXA

  4. Aufgrund des Videos teste ich gerade den DNS Server von #IPv64 und auch darüber DNS over TLS. Und das unter #OPNsense mit #UnboundDNS . Bis jetzt keine Fehler erkennbar aber das muss nichts heißen. Wie teste ich aber das DNS over TLS?

    youtu.be/eVd3dKDwfIc?si=RpbMXA

  5. Zur zeit nutze ich unter #OPNsense #UnboundDNS mit den eingebauten Blocklisten. Was mir aber auffällt dass es keine speziellen Soziale Listen existieren um z.B Facebook zu blockieren. Finde ich schade und nervt. Die Filterlisten als URL eingebunden funktionieren auch nicht wie ich es mag, kann aber auch sein das die Listen einfach nicht UnboundDNS kompatibel sind. Bin etwas genervt.

    #Firewall #DNS #DNSBL

  6. Zur zeit nutze ich unter #OPNsense #UnboundDNS mit den eingebauten Blocklisten. Was mir aber auffällt dass es keine speziellen Soziale Listen existieren um z.B Facebook zu blockieren. Finde ich schade und nervt. Die Filterlisten als URL eingebunden funktionieren auch nicht wie ich es mag, kann aber auch sein das die Listen einfach nicht UnboundDNS kompatibel sind. Bin etwas genervt.

    #Firewall #DNS #DNSBL

  7. Actually it looks like one of my VPS IPv6 changed which I used for Monitoring the IPv6 WAN Gateway in #OPNsense..
    additionally python used nearly 100% CPU.. which was the Netflow. Don’t know why I had this on.
    So I‘m not monitoring the Gateway anymore for now to keep is just running.

    CPU is down again to max 30%.

    And having DNS on that same host is really bad, because my whole HomeLab including HomeAssistant dies even for reaching local systems.

    #ItsAlwaysDNS #HomeLab #UnboundDNS

  8. Actually it looks like one of my VPS IPv6 changed which I used for Monitoring the IPv6 WAN Gateway in #OPNsense..
    additionally python used nearly 100% CPU.. which was the Netflow. Don’t know why I had this on.
    So I‘m not monitoring the Gateway anymore for now to keep is just running.

    CPU is down again to max 30%.

    And having DNS on that same host is really bad, because my whole HomeLab including HomeAssistant dies even for reaching local systems.

    #ItsAlwaysDNS #HomeLab #UnboundDNS

  9. Sometimes it’s just…. DNS.
    #ItsAlwaysDNS

    Connections have being really slow today and some of my scripts reaching local #HomeLab service have been also slow.

    It was #UnboundDNS. A restart of #OPNsense after the latest hotfix update solved the issue.

  10. Sometimes it’s just…. DNS.
    #ItsAlwaysDNS

    Connections have being really slow today and some of my scripts reaching local #HomeLab service have been also slow.

    It was #UnboundDNS. A restart of #OPNsense after the latest hotfix update solved the issue.

  11. Removed the #DNS forwarding in #UnboundDNS and just doing recursive resolution for now.

    Works pretty well since yesterday, nothing really slow or something. Also checked DNS leak tests etc., but only the IPv4 shared across multiple households is showing up. So.. fine.

    I enabled the following settings additionally to the defaults:
    - Enable DNSSEC Support (not sure if that was the default)
    - Hide Identity
    - Hide Version
    - Prefetch DNS Key Support
    - Aggressive NSEC
    - Prefetch Support

  12. Removed the #DNS forwarding in #UnboundDNS and just doing recursive resolution for now.

    Works pretty well since yesterday, nothing really slow or something. Also checked DNS leak tests etc., but only the IPv4 shared across multiple households is showing up. So.. fine.

    I enabled the following settings additionally to the defaults:
    - Enable DNSSEC Support (not sure if that was the default)
    - Hide Identity
    - Hide Version
    - Prefetch DNS Key Support
    - Aggressive NSEC
    - Prefetch Support

  13. #TIL 1/2 Do not use any IP (v4 or v6) as Gateway Monitor IP if you need it somewhere else in #OPNsense.
    OPNSense creates a new route for the monitoring IPs, which make it only usable for this.
    Broke my #UnboundDNS.

  14. #TIL 1/2 Do not use any IP (v4 or v6) as Gateway Monitor IP if you need it somewhere else in #OPNsense.
    OPNSense creates a new route for the monitoring IPs, which make it only usable for this.
    Broke my #UnboundDNS.

  15. Let's say you are hosting a cloud VM for free but changing instances, shutting down etc., make sure to update your DNS records if you are pointing to this VM.

    Public IPs of these VMs are getting reused by others.
    That should be clear.
    But I was suprised to see many DNS queries in my #UnboundDNS to that DNS name...turns out I HAD prometheus monitoring setup to the cloud VM.

    Checking the DNS via https turned to TLS error, because... yeah its a server for role play games now.

    #LessonLearned

  16. Let's say you are hosting a cloud VM for free but changing instances, shutting down etc., make sure to update your DNS records if you are pointing to this VM.

    Public IPs of these VMs are getting reused by others.
    That should be clear.
    But I was suprised to see many DNS queries in my #UnboundDNS to that DNS name...turns out I HAD prometheus monitoring setup to the cloud VM.

    Checking the DNS via https turned to TLS error, because... yeah its a server for role play games now.

    #LessonLearned

  17. @mike #UnboundDNS on #OPNsense

    Works great, also supports many blocklists like AdGuard, Easylist etc. and comes with nice monitoring dashboard.. at least on OPNsense.

  18. @mike #UnboundDNS on #OPNsense

    Works great, also supports many blocklists like AdGuard, Easylist etc. and comes with nice monitoring dashboard.. at least on OPNsense.

  19. I would really like to know what happened to Unbound DNS or my home network yesterday during this time.

    I was using Quad9 with DNS over TLS as my upstream DNS provider.

    Symptoms:
    - Some internal and outbound connections continued to work, I could still load and reload some Web sites
    - Other internal and outbound connections failed, mostly with DNS failures/timeouts
    - Affected Macs (home and work), HomePod minis (streaming stopped)

  20. I would really like to know what happened to Unbound DNS or my home network yesterday during this time.

    I was using Quad9 with DNS over TLS as my upstream DNS provider.

    Symptoms:
    - Some internal and outbound connections continued to work, I could still load and reload some Web sites
    - Other internal and outbound connections failed, mostly with DNS failures/timeouts
    - Affected Macs (home and work), HomePod minis (streaming stopped)

    #opnsense #unbound #unbounddns #dns #network #problem

  21. I recently replaced Pfsense with Opnsense for two main reasons. I had wanted to try out and compare Opnsense. I was also hoping the different integration of DHCP leases with the local Unbound DNS would help my maddening UniFi AP dropout problem, since that seemed to hinge on DNS resolution of the UniFi Inform URL.

  22. I recently replaced Pfsense with Opnsense for two main reasons. I had wanted to try out and compare Opnsense. I was also hoping the different integration of DHCP leases with the local Unbound DNS would help my maddening UniFi AP dropout problem, since that seemed to hinge on DNS resolution of the UniFi Inform URL.

    #Pfsense #Opnsense #DHCP #DNS #Unbound #UnboundDNS #UniFi #UniFiController

  23. Pulling out the little bit of hair I have left 😉

    Swapped by web server DNS entry to a new server & everything was resolving properly EXCEPT when it tried to use IPv6. To be clear, all IPv4 and IPv6 addresses had been updated on all the A/AAAA records and had propagated.

    #UnboundDNS running under #OPNsense seemed to be returning the old IP and for some reason, switching to a public DNS server or disabling DNSSEC support on Unbound fixed it? How does that even happen? Still unclear on the why…

  24. Pulling out the little bit of hair I have left 😉

    Swapped by web server DNS entry to a new server & everything was resolving properly EXCEPT when it tried to use IPv6. To be clear, all IPv4 and IPv6 addresses had been updated on all the A/AAAA records and had propagated.

    #UnboundDNS running under #OPNsense seemed to be returning the old IP and for some reason, switching to a public DNS server or disabling DNSSEC support on Unbound fixed it? How does that even happen? Still unclear on the why…