Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem with DNS resolver

    Scheduled Pinned Locked Moved General pfSense Questions
    64 Posts 7 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • UnoptanioU
      Unoptanio @fireodo
      last edited by

      @fireodo

      9772306e-8156-418d-b39f-5821e14f1b72-image.png

      pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
      CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
      n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

      fireodoF 1 Reply Last reply Reply Quote 0
      • fireodoF
        fireodo @Unoptanio
        last edited by fireodo

        @Unoptanio said in Problem with DNS resolver:

        @fireodo

        9772306e-8156-418d-b39f-5821e14f1b72-image.png

        Do at the CLI:

        pkg search unbound
        

        what do you get?

        Try:

        pkg install unbound-1.19.1
        

        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
        pfsense 2.8.0 CE
        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

        UnoptanioU 1 Reply Last reply Reply Quote 0
        • D
          darcey @Unoptanio
          last edited by darcey

          @Unoptanio Two things to try. Disable resolution of DHCP leases and Openvpn client hostnames. Also, increase the loglevel, which might give you more clues. One other thing, leave listening/outgoing interfaces as 'all'.
          Obviously not suggesting these as solutions but as a means to getting to the cause/culprit.

          1 Reply Last reply Reply Quote 0
          • UnoptanioU
            Unoptanio @fireodo
            last edited by

            @fireodo

            pkg search unbound
            

            unbound-1.19.1 Validating, recursive, and caching DNS resolver

            pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
            CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
            n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

            fireodoF 1 Reply Last reply Reply Quote 0
            • fireodoF
              fireodo @Unoptanio
              last edited by fireodo

              @Unoptanio said in Problem with DNS resolver:

              @fireodo

              pkg search unbound
              

              unbound-1.19.1 Validating, recursive, and caching DNS resolver

              Now do:

              pkg install unbound-1.19.1
              

              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
              pfsense 2.8.0 CE
              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

              UnoptanioU 1 Reply Last reply Reply Quote 0
              • UnoptanioU
                Unoptanio @fireodo
                last edited by Unoptanio

                @fireodo

                [2.7.2-RELEASE][admin@xxxxxxxxxxxx]/root: pkg install unbound-1.19.1
                Updating pfSense-core repository catalogue...
                Fetching meta.conf: 0%
                Fetching packagesite.pkg: 0%
                pfSense-core repository is up to date.
                Updating pfSense repository catalogue...
                Fetching meta.conf: 0%
                Fetching packagesite.pkg: 0%
                pfSense repository is up to date.
                All repositories are up to date.
                The following 1 package(s) will be affected (of 0 checked):

                Installed packages to be UPGRADED:
                unbound: 1.18.0_1 -> 1.19.1 [pfSense]

                
                [2.7.2-RELEASE][admin@Axxxxxxxxx]/root: pkg search unbound
                unbound-1.19.1                 Validating, recursive, and caching DNS resolver
                
                

                pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                fireodoF 1 Reply Last reply Reply Quote 0
                • fireodoF
                  fireodo @Unoptanio
                  last edited by

                  @Unoptanio said in Problem with DNS resolver:

                  unbound: 1.18.0_1 -> 1.19.1 [pfSense]

                  Lets see if your trouble is gone 🤞 ✊

                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                  pfsense 2.8.0 CE
                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                  UnoptanioU 1 Reply Last reply Reply Quote 1
                  • UnoptanioU
                    Unoptanio @fireodo
                    last edited by Unoptanio

                    @fireodo

                    In your opinion, why didn't I have the latest version before? I also have all the patches installed

                    What version of pfsense is Unbound 1.18.0_1 from?

                    4b68dd33-7c8a-4e44-8f68-085b5d620d98-image.png

                    pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                    CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                    n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                    fireodoF 2 Replies Last reply Reply Quote 0
                    • fireodoF
                      fireodo @Unoptanio
                      last edited by

                      @Unoptanio said in Problem with DNS resolver:

                      @fireodo

                      In your opinion, why didn't I have the latest version before? I also have all the patches installed

                      There are updates that are not shown on the GUI and not with Patches - they are shown only on the CLI.

                      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                      pfsense 2.8.0 CE
                      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                      D 1 Reply Last reply Reply Quote 1
                      • D
                        darcey @fireodo
                        last edited by

                        @fireodo My 2.7.2CE install is also currently on unbound-1.18.0_1

                        [2.7.2-RELEASE][root@fw.local.lan]/root: pkg search unbound
                        unbound-1.19.1                 Validating, recursive, and caching DNS resolver
                        [2.7.2-RELEASE][root@fw.local.lan]/root: pkg info | grep unbound
                        unbound-1.18.0_1               Validating, recursive, and caching DNS resolver
                        

                        When might it pull in the updated package, other than explicit upgrade via the cmdline?

                        fireodoF 1 Reply Last reply Reply Quote 0
                        • fireodoF
                          fireodo @Unoptanio
                          last edited by fireodo

                          @Unoptanio said in Problem with DNS resolver:

                          What version of pfsense is Unbound 1.18.0_1 from?

                          I guess 2.7.1 (not shure)

                          I have a script (see attachment - change .zip to .php) that looks via cronjob if there are some updates. (The script is from @Gertjan if I remember well) pkg_check.zip
                          The cronjob looks loke this:

                          /usr/bin/nice -n20 /usr/local/bin/php -q /root/bin/pkg_check.php | logger
                          

                          Edit: In my case the location of the script is in /root/bin (directory I have created) - put the script in your case where you wish ...

                          Tanti auguri :-)

                          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                          pfsense 2.8.0 CE
                          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                          UnoptanioU 2 Replies Last reply Reply Quote 1
                          • UnoptanioU
                            Unoptanio @fireodo
                            last edited by

                            @fireodo
                            So is it a bug in 2.7.2 that doesn't update unbound DNS?

                            pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                            CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                            n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                            fireodoF 1 Reply Last reply Reply Quote 0
                            • fireodoF
                              fireodo @Unoptanio
                              last edited by fireodo

                              @Unoptanio said in Problem with DNS resolver:

                              So is it a bug in 2.7.2 that doesn't update unbound DNS?

                              No thats not a bug - if some changes where needed in unbound that occure AFTER release of 2.7.2 thats the only way to handle it - as far as I know!

                              PS.: Is unbound still restarting?

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.8.0 CE
                              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                              1 Reply Last reply Reply Quote 0
                              • UnoptanioU
                                Unoptanio @fireodo
                                last edited by Unoptanio

                                @fireodo

                                during my lunch break in about two hours I will reboot the system

                                pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                                CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                                n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                                fireodoF 1 Reply Last reply Reply Quote 0
                                • fireodoF
                                  fireodo @Unoptanio
                                  last edited by

                                  @Unoptanio said in Problem with DNS resolver:

                                  during my lunch break in about two hours I will reboot the system

                                  👍

                                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                  pfsense 2.8.0 CE
                                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                  UnoptanioU 1 Reply Last reply Reply Quote 0
                                  • fireodoF
                                    fireodo @darcey
                                    last edited by

                                    @darcey said in Problem with DNS resolver:

                                    When might it pull in the updated package, other than explicit upgrade via the cmdline?

                                    See my answer with the script inside - this kind of upgrade you have to do manually.

                                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                    pfsense 2.8.0 CE
                                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                    D 1 Reply Last reply Reply Quote 0
                                    • D
                                      darcey @fireodo
                                      last edited by

                                      @fireodo Thanks, I'd completely forgotten about this. It seems on my system, unbound and curl have updates available.
                                      Still I think I am going to leave it as is as things are running very smoothly for me of late.

                                      fireodoF 1 Reply Last reply Reply Quote 0
                                      • fireodoF
                                        fireodo @darcey
                                        last edited by fireodo

                                        @darcey said in Problem with DNS resolver:

                                        Still I think I am going to leave it as is as things are running very smoothly for me of late.

                                        Never change a running system ... old wisdom 😀
                                        (curl has a security issue so I recommend to upgrade)

                                        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                        pfsense 2.8.0 CE
                                        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                        1 Reply Last reply Reply Quote 1
                                        • UnoptanioU
                                          Unoptanio @fireodo
                                          last edited by

                                          @fireodo

                                          After restart system

                                          1b69725c-d044-4d74-80fc-215d75b1fe68-image.png

                                          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                                          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                                          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                                          GertjanG fireodoF 2 Replies Last reply Reply Quote 0
                                          • GertjanG
                                            Gertjan @Unoptanio
                                            last edited by

                                            @Unoptanio

                                            That's unbound in permanent restart mode !
                                            You can stop that now, as the test succeeded.

                                            To stop the testing :
                                            Uncheck :

                                            1f41ac53-2bb6-431e-8c5a-dccf4c3d70f0-image.png

                                            Save, and Apply.

                                            ( I'm trying a new solution to a 10+ year old question )

                                            No "help me" PM's please. Use the forum, the community will thank you.
                                            Edit : and where are the logs ??

                                            UnoptanioU 1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.