Ok - fair enough.. I can tell you I point to windows DNS with an domain override just fine and have no issues.
Let me vpn in and will post some examples
edit: Ok took me a bit longer than I thought, freaking real work getting in way of my helping people on the forums ;) heheh
Anyhoo – so see I created a mydomain.com domain on my Windows 2k8r2 box... And as you can see when I query pfsense at first the .253 address he doesn't find anything and returns SOA since he was asking the internet for that domain.
I ask my windows box at .19 and he says sure here you go I have a A record for host as 192.168.42.42, I then created a domain override and ask pfsense again at .253 and boom get the answer..
If I had to guess why your getting servfail is you are not allowing unbound to query on the interface to get to your AD box? See where I added the LAN interface in my outgoing interfaces so that pfsense can query the 192.168.9.19 address I pointed that mydomain.com too. If I uncheck that and then ask pfsense I get servfail like you. So check what interfaces your allowing unbound to query out from..
BTW the long query times, I am having problems with the network here, and running off hotspot on my phone currently, with a vpn to my work, and then vpn off a proxy in my work network in tx, from memphis to my home in schaumburg ;) Working latency is a bit high...
[image: domainoverride.png]
[image: domainoverride.png_thumb]