• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Should unbound-control work by default?

Scheduled Pinned Locked Moved DHCP and DNS
15 Posts 4 Posters 5.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    Taz79 @jimp
    last edited by Apr 11, 2019, 7:25 PM

    @jimp said in Should unbound-control work by default?:

    /var/unbound/remotecontrol.conf shouldn't be zero bytes, so it's also possible something corrupted that. Easy test is to rm /var/unbound/remotecontrol.conf and then save/apply in the resolver settings.

    That solved the problem!! What would i do without you guys! I would have tried to add my own settings in that file and that would not have been good i guess.. :)

    EDIT: whops.. it looked good from the beginning.. check my screenshots below.. The file got re-created and it looked good.. But now the unbound service won't start up, i noticed because wife started complain about Netflix not working anymore... HAHA..

    Here is the error message from the General log:
    4b701f3c-d920-4ca6-ba62-955f54935525-image.png

    Status before:
    9c331089-1e32-4771-92eb-a17eb9676ff3-image.png

    After save:
    d540a11b-671b-4e50-b3ee-8acf6b42e370-image.png

    Content of the new file:
    3ee2dafb-5861-41a6-bc50-ef7191f5d13d-image.png

    Anything special about your setup? Any custom options in unbound? DNSBL or other pfBlocker things enabled?

    Only addition im running at the moment is Bandwithd. Before i have changed outgoing network interfaces to my VPN tunnel to internet but i have since then changed it back to "All" again.

    I have enabled "Serve Expired" yesterday and also removed "Enable SSL/TLS Service. But that was after i noticed the file was 0 bytes.

    The pfsense hardware is pretty new. 2 months old SG-1100. I have restored configurations from my old system, or i just restored the VPN part, dont remember wich one i did now :)

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Apr 11, 2019, 7:30 PM

      Something is definitely unhappy in those files. run rm /var/unbound/unbound_*.pem /var/unbound/unbound_*.key and save/apply, see if that helps. That should force unbound to regenerate those files as well.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      T 1 Reply Last reply Apr 11, 2019, 7:39 PM Reply Quote 0
      • R
        RonpfS
        last edited by Apr 11, 2019, 7:31 PM

        @jimp said in Should unbound-control work by default?:

        Something is definitely unhappy in those files

        Files are empty 😌

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • T
          Taz79 @jimp
          last edited by Apr 11, 2019, 7:39 PM

          @jimp said in Should unbound-control work by default?:

          Something is definitely unhappy in those files. run rm /var/unbound/unbound_*.pem /var/unbound/unbound_*.key and save/apply, see if that helps. That should force unbound to regenerate those files as well.

          Holy **** ... That was a fast answer from your side!!! :)

          I tried it. and it works! :) Unbound service is running now and i can do DNS lookups again :)

          Files has been re-created and is not empty anymore.. Strange problem.. And also the file date of those files with 0 bytes were 7th Jan.. That was before i got my SG-1100... I guess the restore i did would not create files that way (with an old date)..

          f3af4b4c-2889-4f72-ac10-ea4ea71ecb1a-image.png

          1 Reply Last reply Reply Quote 0
          • J
            jimp Rebel Alliance Developer Netgate
            last edited by Apr 11, 2019, 7:40 PM

            Did you maybe have a power event or otherwise unclean shutdown? It might have happened when pfSense was writing those files or they hadn't fully synchronized to disk yet. You might want to reboot it and run a disk check to be certain.

            Worst case there you can rm -rf /var/unbound and save/apply and it should generate everything again.

            The older date may be from when the system was initially imaged at the factory.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            T 1 Reply Last reply Apr 11, 2019, 7:47 PM Reply Quote 0
            • T
              Taz79
              last edited by Apr 11, 2019, 7:44 PM

              This also solved other issues i had... Now Status -> DNS Resolver is working

              d474d8de-df7c-42b1-8a4a-31f0d5addeca-image.png

              AND! unbound-control works too! .. I'm a Happy panda now.. Thanks Jimp!!!!

              eb42382d-e136-4b8a-93d4-4e0e7f9b7814-image.png

              J 1 Reply Last reply Apr 11, 2019, 7:45 PM Reply Quote 0
              • R
                RonpfS
                last edited by Apr 11, 2019, 7:44 PM

                The root.key.57361-0 file should not be there.

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                1 Reply Last reply Reply Quote 0
                • J
                  jimp Rebel Alliance Developer Netgate @Taz79
                  last edited by Apr 11, 2019, 7:45 PM

                  @Taz79 said in Should unbound-control work by default?:

                  This also solved other issues i had... Now Status -> DNS Resolver is working

                  Not surprising since that page uses data output from unbound-control :-)

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • T
                    Taz79 @jimp
                    last edited by Apr 11, 2019, 7:47 PM

                    @jimp said in Should unbound-control work by default?:

                    Did you maybe have a power event or otherwise unclean shutdown? It might have happened when pfSense was writing those files or they hadn't fully synchronized to disk yet. You might want to reboot it and run a disk check to be certain.

                    Worst case there you can rm -rf /var/unbound and save/apply and it should generate everything again.

                    The older date may be from when the system was initially imaged at the factory.

                    We very seldom have power fails here.. Last time was 2 years ago actually.. Some power fails are planned work but then i always shutdown stuff first. I will buy a UPS for my router and other equipment soon though since power fails cause a lot of issues for sure! :)

                    Can i schedule a diskcheck at reboot? and see the results later from "remote (web)"? .. or must i have a display connected to the router?

                    1 Reply Last reply Reply Quote 0
                    • T
                      Taz79
                      last edited by Apr 11, 2019, 7:53 PM

                      @jimp can i ask you about the feature "Serve Expired"?

                      5846fdd3-3731-423a-8c33-82996c1c2a09-image.png

                      I'm wondering when a record reach TTL of 0.. How long will it stay in the cache before it gets deleted? I mean how much good does this setting do? .. It seems like a good thing and does not take up any extra DNS traffic.

                      T 1 Reply Last reply Apr 12, 2019, 8:27 PM Reply Quote 0
                      • T
                        tman222 @Taz79
                        last edited by Apr 12, 2019, 8:27 PM

                        @Taz79 said in Should unbound-control work by default?:

                        @jimp can i ask you about the feature "Serve Expired"?

                        5846fdd3-3731-423a-8c33-82996c1c2a09-image.png

                        I'm wondering when a record reach TTL of 0.. How long will it stay in the cache before it gets deleted? I mean how much good does this setting do? .. It seems like a good thing and does not take up any extra DNS traffic.

                        I have had this enabled for some time with no ill effects that I can see. It seems that DNS TTL's are pretty short on major sites these days (I assume for load balancing purposes or because of the usage of CDN's?) so I find that this does speed things up a bit on my own network where there are just a handful of users. If there were a large number of users it might be less useful as the DNS cache would generally be kept hot otherwise (i.e. records would likely not expire before being requested again). Hope this helps.

                        T 1 Reply Last reply Apr 15, 2019, 6:31 AM Reply Quote 0
                        • T
                          Taz79 @tman222
                          last edited by Apr 15, 2019, 6:31 AM

                          @tman222 said in Should unbound-control work by default?:

                          @Taz79 said in Should unbound-control work by default?:

                          @jimp can i ask you about the feature "Serve Expired"?

                          5846fdd3-3731-423a-8c33-82996c1c2a09-image.png

                          I'm wondering when a record reach TTL of 0.. How long will it stay in the cache before it gets deleted? I mean how much good does this setting do? .. It seems like a good thing and does not take up any extra DNS traffic.

                          I have had this enabled for some time with no ill effects that I can see. It seems that DNS TTL's are pretty short on major sites these days (I assume for load balancing purposes or because of the usage of CDN's?) so I find that this does speed things up a bit on my own network where there are just a handful of users. If there were a large number of users it might be less useful as the DNS cache would generally be kept hot otherwise (i.e. records would likely not expire before being requested again). Hope this helps.

                          Seems like i have to create a separate thread for this to get it sorted out :) .. It defenatly helps me though looking at the statistics. Thanks for your reply!

                          1 Reply Last reply Reply Quote 0
                          13 out of 15
                          • First post
                            13/15
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received