Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS: Plain Unbound works, Quad9 almost...

    Scheduled Pinned Locked Moved DHCP and DNS
    12 Posts 5 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @furom
      last edited by

      @furom if forwarding, disable DNSSEC. 23.01 seems to have more issues I didn’t see in prior versions.
      https://support.quad9.net/hc/en-us/articles/4433380601229-Setup-pfSense-and-DNS-over-TLS

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      F J 2 Replies Last reply Reply Quote 1
      • F
        furom @SteveITS
        last edited by

        @steveits said in DNS: Plain Unbound works, Quad9 almost...:

        @furom if forwarding, disable DNSSEC. 23.01 seems to have more issues I didn’t see in prior versions.
        https://support.quad9.net/hc/en-us/articles/4433380601229-Setup-pfSense-and-DNS-over-TLS

        Thanks, Yes, I tried that, but as mentioned, it kept nagging about it in the log. Not sure that was the cause to why sites fails to resolve fully though. Both sites work partially using Quad9, and I know the webmail want's to redirect, it may be same for Netflix...?

        F S 2 Replies Last reply Reply Quote 0
        • F
          furom @furom
          last edited by furom

          @furom I did forget to disable Strict Query Name Minimization when not using forwarder... Editing above. Still not gotten the other one to work well again..

          1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @furom
            last edited by

            @furom I don’t have a great answer…have seen multiple threads about DNS in 23.01 but I’ve had no issues forwarding to Quad9 after disabling DNSSEC. Which we had enabled on several routers in 22.05 and earlier. Maybe the new unbound is more sensitive?

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            F 1 Reply Last reply Reply Quote 1
            • C
              Cylosoft @furom
              last edited by

              @furom Switch to Cloudflare DNS, no DNSSEC, TLS enabled.

              Or Quad9 no DNSSEC, no TLS.

              We are testing Quad9, no DNSSEC, TLS, both pre-fetch options on.

              1 Reply Last reply Reply Quote 1
              • C
                Cylosoft
                last edited by

                If you want a Quad9 equivalent on Cloudflare use these instead of 1.1.1.1

                1.1.1.2
                1.0.0.2
                security.cloudflare-dns.com

                F 1 Reply Last reply Reply Quote 1
                • F
                  furom @SteveITS
                  last edited by

                  @steveits said in DNS: Plain Unbound works, Quad9 almost...:

                  @furom I don’t have a great answer…have seen multiple threads about DNS in 23.01 but I’ve had no issues forwarding to Quad9 after disabling DNSSEC. Which we had enabled on several routers in 22.05 and earlier. Maybe the new unbound is more sensitive?

                  I think you may be right. Perhaps it was tolerating what was restored from backup, but reconfiguring may be something else... Anyways, with the last edit I got it to work well with no forwarders at least. Only minor issue I had was forgetting to turn on the fw rules before deactivating the NAT rule I had in place... lol. So a little bummed for a few minutes (while Netfix were running great, almost all else lacked DNS) until I thought of trying the console... And it totally saved the day! Overall I am soooo happy with pfSense/Netgate!!

                  1 Reply Last reply Reply Quote 1
                  • F
                    furom @Cylosoft
                    last edited by

                    @cylosoft said in DNS: Plain Unbound works, Quad9 almost...:

                    If you want a Quad9 equivalent on Cloudflare use these instead of 1.1.1.1

                    1.1.1.2
                    1.0.0.2
                    security.cloudflare-dns.com

                    Thanks! I will give that a go as well to see if it behaves differently :)

                    1 Reply Last reply Reply Quote 0
                    • J
                      JasonAU @SteveITS
                      last edited by

                      @steveits said in DNS: Plain Unbound works, Quad9 almost...:

                      https://support.quad9.net/hc/en-us/articles/4433380601229-Setup-pfSense-and-DNS-over-TLS

                      Something in this blog caught my eye

                      If your network does not have IPv6, which you can test here, then IPv6 addresses should not be added, as it may result in a percentage of your DNS requests failing.
                      

                      Whilst I don't have IPv6 or the address listed, this did trigger me to go into pfsese / System /Advanced /Networking and unchecked Allow IP6

                      I am getting some query's dropped from Windows devices seemingly at random, restarting unbound can sometimes help.

                      Brisbane Queensland Australia

                      F 1 Reply Last reply Reply Quote 1
                      • F
                        furom @JasonAU
                        last edited by

                        @jasonau said in DNS: Plain Unbound works, Quad9 almost...:

                        @steveits said in DNS: Plain Unbound works, Quad9 almost...:

                        https://support.quad9.net/hc/en-us/articles/4433380601229-Setup-pfSense-and-DNS-over-TLS

                        Something in this blog caught my eye

                        If your network does not have IPv6, which you can test here, then IPv6 addresses should not be added, as it may result in a percentage of your DNS requests failing.
                        

                        Whilst I don't have IPv6 or the address listed, this did trigger me to go into pfsese / System /Advanced /Networking and unchecked Allow IP6

                        I am getting some query's dropped from Windows devices seemingly at random, restarting unbound can sometimes help.

                        Thanks for trying! Unfortunately no IPv6 involved. Lookup to destinations work, what is failing is their redirects to the target after logging in

                        1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @furom
                          last edited by

                          @furom said in DNS: Plain Unbound works, Quad9 almost...:

                          Unbound Resolver with quad9 through TLS
                          Unbound Resolver with no forwarder

                          I've been using the resolver as a resolver for .... 10 years or so.
                          Never had an issue.

                          Just for the fun, I'm forwarding to 1.1.1.1 and 2606:4700:4700::1111, as I use IPv6 and IPv4 for the old stuff), and because why not : over TLS using port 853.
                          No issues neither.

                          Btw : 1.1.1.1 (or 8.8.8.8 or 9.9.9.69) are all resolver.
                          What they can do, so can unbound, the pfSense's resolver.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 1
                          • GertjanG Gertjan referenced this topic on
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.