Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unbound requests: IPv6 features enabled and update to 1.4.10

    Scheduled Pinned Locked Moved pfSense Packages
    20 Posts 4 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      Yeah the package upgrade HUNG the web gui, it would not even restart.  I finally just rebooted, and package was there and everything seems to be working.. Thanks for the update to 1.4.10, but still had to manually edit unbound.inc to get ipv6 working.  See you added variable for do ipv6, etc.

      And just have not had time to add it to the gui so can turn on I guess..

      Clearly understand real life, and clearly was not expecting all the added advanced config items which is GREAT, thanks.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • W
        wagonza
        last edited by

        finally! IPv6 support is added. I removed the IPv6 checkbox as there was no point for it (unless someone says otherwise). So it will automatically set Unbound to listen on the v6 address and answer for v6 dns queries. It will also setup the relevant ACLs for the v6 clients. The only thing left to do is the ACL section in case you want to add other v6 networks but for now it should be fine.

        By the way those munin graphs are cool, it has been on my to do list for awhile now. As I have mentioned before, the devs want to replace dnsmasq with unbound which I'll be working on in the v6 branch - so expect to see some work there and the addition of graphs similar to the below.

        Otherwise let me know if you have any problems.

        Follow me on twitter http://twitter.com/wagonza
        http://www.thepackethub.co.za

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Well just updated the package, when really smooth this time.  And yup working on ipv6 without any need to modify any config.

          Looking forward to having some built in RRD graphs in the future though, munin is working - but much rather have it part of the distro vs having to add stuff.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • AhnHELA
            AhnHEL
            last edited by

            Failed again for me, reinstalling seems to get forwarding mode enabled even though i had it disabled.  Unchecking and hitting save has no effect, always remains enabled.  Deleted package, then downloaded the backup config file and edited it to remove all Unbound entries and then restored the config, reinstalled Unbound but same thing, forwarding mode remains enabled.

            AhnHEL (Angel)

            1 Reply Last reply Reply Quote 0
            • W
              wagonza
              last edited by

              @onhel:

              Failed again for me, reinstalling seems to get forwarding mode enabled even though i had it disabled.  Unchecking and hitting save has no effect, always remains enabled.  Deleted package, then downloaded the backup config file and edited it to remove all Unbound entries and then restored the config, reinstalled Unbound but same thing, forwarding mode remains enabled.

              You mean the DNS Forwarder i.e. dnsmasq remains enabled?

              Follow me on twitter http://twitter.com/wagonza
              http://www.thepackethub.co.za

              1 Reply Last reply Reply Quote 0
              • AhnHELA
                AhnHEL
                last edited by

                No, the enable forwarding mode in the Unbound settings page.  That check box will not go unchecked.

                AhnHEL (Angel)

                1 Reply Last reply Reply Quote 0
                • G
                  GLR
                  last edited by

                  Yes, same issue on mainstream 2.0 RC3 Unbound 1.4.10_02 either with Firefox or Chrome (Iron)
                  Those boxes stay checked :

                  • Enable DNSSEC
                  • Enable forwarding mode
                  • Private Address support
                  • TXT Comment Support
                  1 Reply Last reply Reply Quote 0
                  • W
                    wagonza
                    last edited by

                    @GLR:

                    Yes, same issue on mainstream 2.0 RC3 Unbound 1.4.10_02 either with Firefox or Chrome (Iron)
                    Those boxes stay checked :

                    • Enable DNSSEC
                    • Enable forwarding mode
                    • Private Address support
                    • TXT Comment Support

                    So you can uncheck the box - but after you click save it is still checked? Or you cant uncheck the box at all?

                    Follow me on twitter http://twitter.com/wagonza
                    http://www.thepackethub.co.za

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Yeah I just checked on the forwarding one.. I do not want it to doing forwarding requests.  I should look up on its own, I uncheck the box click save and then box is still checked.  Seems I might have to change it in the config by hand for now.

                      Ok I just took a look at the config and I don't see forwarding setup..  So not sure why the check mark is set on the web gui interface for unbound?

                      I also verified by doing a few packet captures on the wan to see where dns was going.. And did not see any packets to what I have setup for pfsense to use in general 4.2.2.2

                      09:01:43.491932 IP 24.13.xxx.xxx.48910 > 192.5.6.30.53: UDP, length 55
                      09:01:43.564438 IP 192.5.6.30.53 > 24.13.xxx.xxx.48910: UDP, length 382
                      09:01:43.565179 IP 24.13.xxx.xxx.15487 > 216.69.185.26.53: UDP, length 55
                      09:01:43.565470 IP 24.13.xxx.xxx.7590 > 216.69.185.35.53: UDP, length 51
                      09:01:43.565709 IP 24.13.xxx.xxx.25867 > 216.69.185.35.53: UDP, length 51
                      09:01:43.603711 IP 216.69.185.26.53 > 24.13.xxx.xxx.15487: UDP, length 126
                      09:01:43.604282 IP 24.13.xxx.xxx.50531 > 216.69.185.26.53: UDP, length 51

                      192.5.6.30 =  a.gtld-servers.net.

                      And then others are clearly dns servers themselves – so clearly its not forwarding to the 4.2.2.2 address I have setup in general.. But odd why the check mark in the gui is stuck in place.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • W
                        wagonza
                        last edited by

                        Ok i just managed to replicate the problem. Let me investigate why…

                        Follow me on twitter http://twitter.com/wagonza
                        http://www.thepackethub.co.za

                        1 Reply Last reply Reply Quote 0
                        • W
                          wagonza
                          last edited by

                          Ok there was a change in pfSense a few days ago, I have reverted that change so upgrade to the next snap (which will probably be only available tomorrow). This will fix these checkboxes from been enabled when they shouldn't be. In the meantime, you can uncheck them and save. Unbound will still operate correctly in the background with the options you selected.

                          Follow me on twitter http://twitter.com/wagonza
                          http://www.thepackethub.co.za

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Do you have link to the commit, guess I could look it up but wondering when it will merge with the ipv6 line.  So I can run just run a gitsync

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • AhnHELA
                              AhnHEL
                              last edited by

                              gitsynced and reinstalled package, all is good now, thank you.

                              AhnHEL (Angel)

                              1 Reply Last reply Reply Quote 0
                              • W
                                wagonza
                                last edited by

                                @johnpoz:

                                Do you have link to the commit, guess I could look it up but wondering when it will merge with the ipv6 line.  So I can run just run a gitsync

                                https://github.com/bsdperimeter/pfsense/commit/91c31339104f424dad3de75f815697994b68a7c3

                                Follow me on twitter http://twitter.com/wagonza
                                http://www.thepackethub.co.za

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  Thanks for that, I ran a gitsync and now that forwarder is unchecked.  I also show RC3 now ;)

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • W
                                    wagonza
                                    last edited by

                                    Yeah the IPv6 branch was updated yesterday. Also note there was a bug in the interface handling on the latest Unbound package, which I have just fixed and bumped the version number. It wouldn't have affected you unless you were selecting multiple interfaces.

                                    Follow me on twitter http://twitter.com/wagonza
                                    http://www.thepackethub.co.za

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.