Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.4.4_1: unbound frequently stops answering domain overrides

    Scheduled Pinned Locked Moved DHCP and DNS
    11 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lnguyen
      last edited by lnguyen

      Unbound was updated to 1.8.1 and has a bug where its single threaded. Enter this in custom options under Services | DNS Resolver

      server:
      so-reuseport: no

      See this thread for the details:
      https://forum.netgate.com/topic/138274/unbound-1-8-1-only-single-thread-processing-dns-requests/5

      M 1 Reply Last reply Reply Quote 0
      • M
        matsan @lnguyen
        last edited by

        @lnguyen
        Thanks. Added that and keeping fingers crossed :-)

        L 1 Reply Last reply Reply Quote 0
        • L
          lnguyen @matsan
          last edited by

          @matsan I had to restart the DNS Resolver service again so that workaround may not be related to this bug.

          1 Reply Last reply Reply Quote 0
          • L
            lnguyen
            last edited by

            @matsan I disabled DNSSEC and that seems to be a workaround but compromises DNS security.

            M 1 Reply Last reply Reply Quote 0
            • M
              matsan @lnguyen
              last edited by

              @lnguyen said in 2.4.4_1: unbound frequently stops answering domain overrides:

              @matsan I disabled DNSSEC and that seems to be a workaround but compromises DNS security.

              Will try that as well. Restarted once this morning already...

              1 Reply Last reply Reply Quote 0
              • L
                lnguyen
                last edited by lnguyen

                @matsan Did disabling DNSSEC work for you?

                M J 2 Replies Last reply Reply Quote 0
                • M
                  matsan @lnguyen
                  last edited by

                  @lnguyen
                  So far so good.

                  1 Reply Last reply Reply Quote 0
                  • J
                    John41 @lnguyen
                    last edited by

                    @lnguyen I am not the original person that started this thread but I had a problem that seems the same. I always had the problem where my Domain Override in DNS Resolver would stop working. With 2.4.3 and older it would happen not very often. With 2.4.4-RELEASE-p2 it happens relatively often. If I simply save/apply settings on the DNS Resolver page (may work for other pages...not sure) it then works for a while. I don't need to change anything. There is nothing in the logs that I can see.

                    I disabled DNSSEC and that seems to have kept things working. I will also try the method referenced where unbound threading config is changed.

                    L 1 Reply Last reply Reply Quote 0
                    • L
                      lnguyen @John41
                      last edited by

                      @john41 I had no issues with domain override (across IPSec VPN) until 2.4.4-p1. It is still an issue with 2.4.4-p2. @jimp Should I open a bug report for this on redmine?

                      1 Reply Last reply Reply Quote 0
                      • L
                        lnguyen
                        last edited by

                        I did notice that only forward zone domain overrides failed with DNSSEC enabled. Reverse zone donain overrides work perfectly fine whether DNSSEC is disabled or enabled.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.