Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSSEC and NextDNS

    Scheduled Pinned Locked Moved DHCP and DNS
    7 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic
      last edited by

      By NextDNS instructions should put in custom options of DNS resolver :

      server:
      forward-zone:
      name: "."
      forward-tls-upstream: yes
      forward-addr: XXXXX
      forward-addr: XXXXX

      But in this case should be DNSSEC to OFF in DNS resolver or keep it default?

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      1 Reply Last reply Reply Quote 0
      • juanzelliJ
        juanzelli
        last edited by

        AFAIK, you don't need DNSSEC if you're forwarding queries to a service like NextDNS, Quad9, etc. Since the resolver you're choosing to use should already be doing DNSSEC tasks, you'd only be attempting to confirm DNSSEC between you and your chosen resolver which is unnecessary.

        Netgate 4100 and HPE InstantOn network at home

        A S 3 Replies Last reply Reply Quote 0
        • A
          Antibiotic @juanzelli
          last edited by

          @juanzelli Ok, thanks'

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          1 Reply Last reply Reply Quote 0
          • A
            Antibiotic @juanzelli
            last edited by

            @juanzelli One more question, what about Harden DNSSEC Data in advanced settings, should as well to OFF?

            pfSense plus 24.11 on Topton mini PC
            CPU: Intel N100
            NIC: Intel i-226v 4 pcs
            RAM : 16 GB DDR5
            Disk: 128 GB NVMe
            Brgds, Archi

            juanzelliJ 1 Reply Last reply Reply Quote 0
            • juanzelliJ
              juanzelli @Antibiotic
              last edited by

              @antibiotic Yes, I would leave it off too. I believe you'd only concern yourself with that if you were not forwarding and, instead, were allowing Unbound to resolve on its own. If that were the case, it would be best to enable DNSSEC and (possibly) the hardening setting. But, best to leave them off if you're forwarding to NextDNS.

              Netgate 4100 and HPE InstantOn network at home

              A 1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @juanzelli
                last edited by

                @juanzelli
                Actually prefer default settings , but in my country some news sites are blocking if using ISP DNS. When do DNS forwarding to external DNS , its possible to enter blocking sites!

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @juanzelli
                  last edited by

                  @juanzelli said in DNSSEC and NextDNS:

                  don't need DNSSEC if you're forwarding queries

                  I'd go a step farther...per Quad9 forwarding with DNSSEC may cause failures. And in pfSense 23.01 it seems way more problematic than older versions where I saw no failures.

                  @Antibiotic If those instructions are generically how to enable forwarding, which it seems, pfSense has a checkbox for that:
                  452edca0-9101-4092-a66b-5a9e63200f9d-image.png

                  ref: Quad9 doc saying to uncheck DNSSEC: https://support.quad9.net/hc/en-us/articles/4433380601229-Setup-pfSense-and-DNS-over-TLS

                  thread about Quad9 and several others, where DNSSEC and/or DNS over TLS is causing problems in 23.01: https://forum.netgate.com/topic/178413/major-dns-bug-23-01-with-quad9-on-ssl/

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.