Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Enabling SSL/TLS in unbound, results in error SSL_write

    Scheduled Pinned Locked Moved DHCP and DNS
    3 Posts 2 Posters 446 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tigo
      last edited by Tigo

      Hi,

      Can someone please give me a bit of guidance on how to solve or where to look at to solve this error that I'm finding in the DNS Resolver log file.

      Error is:
      Screen Shot 2023-01-30 at 16.10.17 pm.png

      It started to happen after I enabled "Use SSL/TLS for outgoing DNS Queries to Forwarding Servers" in DNS resolver. Disabling it resolves the issue, but that's not ideal. I'm using cloudfare & opendns for upstream DNS servers, and both support it. Also, according to the states log, all DNS queries are going to 853. I don't have any traffic for port 53 going out.

      Currently running ver 22.05, and pfblockerng-devel _11.

      Many thanks,

      1 Reply Last reply Reply Quote 0
      • T
        Tigo
        last edited by

        (solved)
        Not sure how it was solved, but I no-longer have this error showing up. Upgraded to 23.01 & pfblockerng_devel_20, and noticed that DNSSEC Support is unchecked. Perhaps, I had it checked, and it wasn't playing nicely with pfblocker & resolver. But, all is sorted now, working without any errors.

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @Tigo
          last edited by

          @tigo said in Enabling SSL/TLS in unbound, results in error SSL_write:

          noticed that DNSSEC Support is unchecked. Perhaps, I had it checked, and it wasn't playing nicely with pfblocker & resolver

          DNSSEC can be only be done if unbound is resolving.
          When you forward, you have to trust the upstream revolvers (in your case : cloudfare & opendn).

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.