Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is it what you should expect from unbound in full resolver mode?

    Scheduled Pinned Locked Moved DHCP and DNS
    8 Posts 3 Posters 492 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? Offline
      A Former User
      last edited by A Former User

      No forwarding, no TLS, no DNS server in general setup. pfblockerng in python mode.
      When I try the diagnostic/DNS lookup tool for say, www.ford.com,, the first uncached response in often around 100ms. The second (cached) is near 0).
      I'm not impressed.
      Should I?

      edit: Ok, I changed the settings "DNS Resolution Behavior" back to default. Let's see if it improves things a bit.

      NollipfSenseN johnpozJ 2 Replies Last reply Reply Quote 0
      • NollipfSenseN Offline
        NollipfSense @Guest
        last edited by

        @marchand-guy said in Is it what you should expect from unbound in full resolver mode?:

        no DNS server in general setup.

        So, what you have here?

        Screenshot 2023-06-16 at 1.01.57 PM.png

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        ? 1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator @Guest
          last edited by

          @marchand-guy not impressed with what.. That you resolved from roots in 100 ms ford.com..

          That is actually pretty good.. But keep in mind that was from a standing start.. Going forward you don't have to ask roots for the .com NSes, and looking up anything from ford.com any more you don't have to ask the gltd servers for NS for ford.com.

          What did you think it was going to be? Shoot asking google.com takes

          Asking the ford NS directly is faster ;)

          ;; QUESTION SECTION:
          ;ford.com.                      IN      A
          
          ;; ANSWER SECTION:
          ford.com.               1800    IN      A       19.12.113.37
          ford.com.               1800    IN      A       19.12.97.37
          
          ;; Query time: 12 msec
          ;; SERVER: 19.12.97.134#53(19.12.97.134)
          

          And I get the full ttl, not whatever is left in the cache that is going to make me query yet again sooner..

          ;; QUESTION SECTION:
          ;ford.com.                      IN      A
          
          ;; ANSWER SECTION:
          ford.com.               332     IN      A       19.12.113.37
          ford.com.               332     IN      A       19.12.97.37
          
          ;; Query time: 19 msec
          ;; SERVER: 8.8.8.8#53(8.8.8.8)
          

          if your worried about a few ms here or there when doing dns - you need to do some research how dns is designed to work, you going to notice 0.1 second - really??

          Keep in mind again that resolve time is from standing still all the way down from roots.. Turn prefetch on, turn serve 0 on.. Who cares how long it takes to resolve from stand still..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

          ? 1 Reply Last reply Reply Quote 0
          • ? Offline
            A Former User @NollipfSense
            last edited by

            @NollipfSense I changed the settings "DNS Resolution Behavior" back to default. It was Use local DNS 127.0.0.1, Ignore remote.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator @Guest
              last edited by

              @marchand-guy said in Is it what you should expect from unbound in full resolver mode?:

              Use local DNS 127.0.0.1, Ignore remote.

              That really should be default if you ask me.. I am resolving I don't want to ever forward to anything.. Not some dhcp server I got from dhcp, etc.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

              ? 1 Reply Last reply Reply Quote 0
              • ? Offline
                A Former User @johnpoz
                last edited by

                @johnpoz That's what I thought. Trying to gauge my performance under full resolver vs forwarding. You seem to thinks it's ok from stand still.
                Which is comforting.
                Thank you.

                1 Reply Last reply Reply Quote 0
                • ? Offline
                  A Former User @johnpoz
                  last edited by

                  @johnpoz said in Is it what you should expect from unbound in full resolver mode?:

                  Turn prefetch on, turn serve 0 on

                  Already did.
                  I selected:
                  Prefetch Support
                  Prefetch DNS Key Support
                  Harden DNSSEC Data
                  Serve Expired
                  Aggressive NSEC

                  Maybe that's too much?

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator @Guest
                    last edited by

                    @marchand-guy too much? No..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.