@cyberminion said in DNS dies periodically (due to unbound crashing?):
pfBlockerNG is running for both subnets
pfBlockerNG can restart unbound regularly. Do a manual reload of pfBlockerNG and see for yourself.
This option :
3c497c02-4cf0-48c5-b677-fd5012978728-image.png
will also restart unbound when a new DHCP lease comes in.
Although, checking that option and using pfBlockerNG will make it complaining about it :
ceb9c807-4d57-4fe8-a6dc-93fdd7cc6066-image.png
That is : the Python mode doesn't 'like' this "DHCP Registration" setting, so, if set, it (pfBlockerNG ) will default to the older "unbound mode" This mode uses more resources and is slower to restart.
@cyberminion said in DNS dies periodically (due to unbound crashing?):
when needed to a pair of defined public DNS severs.
Are you sure ?
unbound should be used as a resolver. With "public DNS" you mean you're forwarding ?
@cyberminion said in DNS dies periodically (due to unbound crashing?):
When DNS service drops out, I can wait about 20 minutes for it to come back by itself
This is the real issue : it did not crash, it was just restarting, and this shouldn't take that long.
Or it does so on your system.
Bring your system back to default settings (remove or de activate pfBlockerNG and other packages) and add them back again step by step. Restart unbound with the GUI :
3bc2cdff-5f81-4157-80d9-457f7b1bfef4-image.png
and check with the unbound logs how long it took.
Do this for each step, each feed you add to pfBlockerNG.
The Firewall > pfBlockerNG > Update : Reload > All
also shows you how much time it took for unbound to restart :
19ee308d-b97a-45ac-b79b-a36072585ff3-image.png