Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver stops working after unbound service restarts

    Scheduled Pinned Locked Moved DHCP and DNS
    6 Posts 3 Posters 370 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mietz
      last edited by

      I have several VLANs setup. Two of them are using 3 VPN connections as a gateway group for egress. I set up the DNS resolver for those VLANs with the Outgoing Network interfaces set to the 3 VPN interfaces. I'm using OpenVPN Clients with NordVPN.

      Everything was working fine for years without an issue. Since I upgraded to PFsense 2.7.2 I sporadically loose DNS functionallity and am unable to resolve hosts.

      I found out that if the unbound resolver service restarts, the issue happens. Restarting the VPN connections or any other service doesn't help. I have to restart Pfsense. After couple of hours or after days the issue will come up again, starting with restarting of the unbound service.

      Here you find the logs with the restarting unbound service at 23:57:

      dns resolver.pnggateways.png openvpn.png

      What I did so far:

      • changed NordVPN server domain name to server IP in OpenVPN Client
      • tried each VPN interface seperately as Outgoing Network Interfaces
      • checked every setting
      • crawled the internet and this forum for help

      I'm out of ideas how to fix that. Does everyone have an idea?

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @mietz
        last edited by Gertjan

        @mietz said in DNS Resolver stops working after unbound service restarts:

        I'm using OpenVPN Clients with NordVPN.

        Have a look at the other NordVPN thread.
        It starts with "DNS suddenly broken [on some VLANs]" but then it became clear that Nord was used, doing their best to break DNS ? Still not sure yet.
        When done reading, say out-loud : I pay them to do this ?

        Btw : what are these :

        57be0f36-1075-4da7-84c2-2053d46d3ba3-image.png

        edit : check also : Status > DNS Resolver

        and if you really want to see what it (trying to do) is doing, goto level 3 :

        773c1527-d183-4723-8ae5-18b129030594-image.png

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        M 1 Reply Last reply Reply Quote 0
        • M
          mietz @Gertjan
          last edited by

          @Gertjan Thanks for the reply. I read the whole thread you provided and I think I will switch to AirVPN.

          @Gertjan said in DNS Resolver stops working after unbound service restarts:

          Btw : what are these :

          57be0f36-1075-4da7-84c2-2053d46d3ba3-image.png

          edit : check also : Status > DNS Resolver

          These are just Certificates renewal notifications.

          T 1 Reply Last reply Reply Quote 0
          • T
            TampertK @mietz
            last edited by

            @mietz I'm on AirVPN and I face the exact same issue, about once a week. Also see these threads, it really seems like an issue with Unbound:

            pfSense 2.7 DNS Resolver doesn't start

            2.7: unbound does not restart after scheduled PPPoE reconnect

            2.7.0 upgrade - DNS issues

            2.7.0 - DNS Resolver crashes (?)

            Upgraded to 2.7.0, having weird issues with DNS forwarder? upon reboot have to restart it manually

            DNS Resolver seems to crash almost nightly

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @TampertK
              last edited by Gertjan

              @TampertK

              These are all "2.7.0" posts, and 2.7.0 is more then a year old.
              Everybody is using 2.7.2 these days, right ? (as we all love the new bug, if any, not the old bugs ^^)
              unbound itself was upgraded several times since, imho, mostly for small enhancements and other CVE issues.
              That said, I use unbound, the resolver, in the "out of the box" mode, with the setup it has when you Install pfSense from scratch. If worked for me ever since, and that start somewhere in 2012, when unbound was added to pfSense.
              I've been using it using a IPv4 only PPPOE WAN connection, later on succeeded by a 'ISP upstream router' connection, using the pfSense WAN with 'DHCP'.
              I've been using pfSense (unbound) on arm processors, AMD, and Intel - a SG 4100 these days. It was and still is rock solid for me.

              So, let me propose this advice : go Keep It Simple mode : use the out of the box experience. It works well for millions.

              I never had to use a "VPN ISP". Recent forum posts about NrdVPN really don't make me changing my mind about them : they started to brilliantly fck*ng up the DNS (there is a recent big thread about it).

              Be aware : if needed, you can use 'dnsmasq', the ancient forwarder. Just disable the 'resolver', and activate the 'forwarder' :
              45bfa526-e48a-4f19-80e8-ea1ab12a5ad8-image.png

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • M
                mietz
                last edited by

                After switching from NordVPN to AirVPN the issue is gone. I had to disable monitoring the VPN interfaces because AirVPN seems not to like that. But besides that everything works now flawlessly.

                After talking to NordVPN they said that they are aware of that and working on that issue. But I don’t want to wait for them to work on that issue.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.