Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unbound restarting more frequently?

    pfBlockerNG
    3
    8
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RyanMR
      RyanM
      last edited by

      I just changed the updates to run daily instead of hourly. It seemed that unbound was restarting pretty regularly and this caused DNS lookups to fail for a few minutes while it did. After making this change, it seems like unbound is still restarting more than daily, any idea why this is? I might need to let it take a few days too, not sure.

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by Gertjan

        Hi,

        It's easy to make a restart bomb out of unbound. If you add packages that add a lot of setup info, unbound can even be slow to start.

        So, the question is : what's your (unbound) setup ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • RyanMR
          RyanM
          last edited by

          What is the pertinent info? I haven't had this issue until I updated pfBlockerNG to the 'devel' branch and version 2.2.5_19. When I did that, I added a bunch of feeds (IP and Host). I just went and removed some that were large lists and did not appear to be blocking any of my requests. I will see if that makes a difference, but I wanted to ask on the forum what could be causing this?

          GertjanG 1 Reply Last reply Reply Quote 0
          • chrismacmahonC
            chrismacmahon
            last edited by

            What is the pertinent info?

            The more you can get the better, Let's start out with basics, what version of pfSense are you running, what is the hardware specs, what packages are installed.

            Anything else would be great.... the more you get to us, the faster we can assist.

            Need help fast? Our support is available 24/7 https://www.netgate.com/support/

            Do Not PM For Help!

            RyanMR 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @RyanM
              last edited by

              @ryanm said in Unbound restarting more frequently?:

              What is the pertinent info?

              This

              I haven't had this issue until I updated pfBlockerNG to the 'devel' branch and version 2.2.5_19. When I did that, I added a bunch of feeds (IP and Host).

              and with these words you answered your question.

              Packages can put a big load on the DNS system. The overall winner is probably pfBlockerNG.

              Take a look at this page (example) : pfBlockerNG and have a look at the feeds.
              Huge files, and these files are all read into the DNS's daemon's memory every time it (re)starts.
              Also : something on an interface changes ? DNS restarts.
              You have DHCP leases registered into DNS ? On every incoming DHCP lease, DNS restarts ....
              Etc.
              Cum them up together, and it very possible (== easy) to create a situation where you real notice that the "DNS is down".

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              RyanMR 1 Reply Last reply Reply Quote 1
              • RyanMR
                RyanM @chrismacmahon
                last edited by

                @chrismacmahon said in Unbound restarting more frequently?:

                What is the pertinent info?

                The more you can get the better, Let's start out with basics, what version of pfSense are you running, what is the hardware specs, what packages are installed.

                Anything else would be great.... the more you get to us, the faster we can assist.

                Hopefully screenshots work.

                System Info:
                0_1544114152357_pfSense-System Info.png

                Installed Packages:
                0_1544114162289_pfSense-Installed Packages.png

                DNS Resolver Settings:
                0_1544114176680_pfSense-DNS Resolver Settings.png

                The Custom options box is set to:

                server:  
                private-domain: "plex.direct"
                server:include: /var/unbound/pfb_dnsbl.*conf
                

                I don't think I have changed any advanced settings. Let me know if those are important.

                I made 2 big changes recently.

                1. I enabled TLS in DNS Resolver by checking the checkboxes in the "DNS Query Forwarding" section.
                2. I updated pfBlockerNG to the devel branch and added some feeds (IP and Domain).

                Here are the pfBlockerNG settings for IPv4 filters:
                0_1544114425612_pfSense-pfBlockerNG IPv4.png

                And the feeds:
                0_1544114436576_pfSense-pfBlockerNG DNSBL Feeds.png

                Note that while some of these entries are "Disabled" with a "Frequency" of "Never", that was a change I made this morning to reduce the items pfBlockerNG was filtering. This reduced the number of items for several hundred thousand entries (possibly close to 1M since BBC is around 600k entries and hpHosts is around 350K entries). I am hoping that disabling some of these feeds will keep resolver from restarting, but to be honest I don't know if that was the issue.

                1 Reply Last reply Reply Quote 0
                • RyanMR
                  RyanM @Gertjan
                  last edited by

                  @gertjan said in Unbound restarting more frequently?:

                  You have DHCP leases registered into DNS ? On every incoming DHCP lease, DNS restarts ....

                  I think this might be a bigger factor regarding this issue. I forgot to mention that while setting up the TLS support for DNS I saw this option and it sounded like a good idea. Whoops. I am going to turn this off.

                  1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan
                    last edited by

                    Exact.
                    Static ones are ok, they are known - and when the lease is renewed, DNS doesn't restart.
                    Classic DHCP, if checked, will restart DNS.
                    This is a known subject (I won't call it an issue, but if unbound has a lot of work to do at startup, like rowing through all these pfBlockerNG 's feeds files; and you have a 'light' system (processor, disk, whatever) then yes, it starts to take time).

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.