Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unbound Error

    General pfSense Questions
    4
    10
    651
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jconnors
      last edited by

      I know this issue has been around for a bit but I've not seen a solid answer for it.

      alt text

      What is the work around here? This system is fully updated btw.

      List of services running: alt text

      Works great on a clean install, but this FW has been up for a bit.

      Any thoughts?

      Thank You.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        This thread had a few suggestions, like disabling DNSSEC.

        Were you running pfBlocker at some point?

        1 Reply Last reply Reply Quote 0
        • J
          jconnors
          last edited by jconnors

          @kom No, we've never run anything of the sort on this machine. Pretty much any advice I've seen online I've tried and ruled out thus far.

          The only way I've seen it work is with a fresh install and this is a core router, which I can't really do that with.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            I just checked my config and I don't have any test folder with root.key inside. Take a look in /var/unbound/unbound.conf. Look at all the included files and check them for references to /test/root.key. It's got to be there somewhere.

            You could also try the nuclear option:

            • disable resolver
            • enable forwarder
            • take a config.xml backup
            • manually edit it and remove everything between the <unbound></unbound> tags
            • install fresh, restore your config then disable forwarder and enable resolver
            1 Reply Last reply Reply Quote 0
            • J
              jconnors
              last edited by

              I would love to enable Forwarder, but I can't..that error pops up preventing it from starting.

              I'll check the rest here. Let you know what I find.

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                Try to run this command and see if that fixes it:

                unbound-anchor -a /var/unbound/root.key
                

                If not, In the /var/unbound/ folder, delete these four files and reboot:

                unbound_control.key
                unbound_control.pem
                unbound_server.key
                unbound_server.pem
                

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  You appear to have the DNS Forwarder (dnsmasq) running in the screenshot above. You cannot enabled the DNS Resolver at the same time unless one is not listening on port 53.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • J
                    jconnors
                    last edited by jconnors

                    @BBcan177

                    I had tried that previously and it didn't work. There is a upgrade/reboot planned for next Sunday

                    @stephenw10

                    In the screenshot it may have been running, but I assure you that when I tried the change, I did have it turned off.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Ok, so you're using the Forwarder just because the Resolver won't start currently?

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • J
                        jconnors
                        last edited by jconnors

                        Correct. It works on the other FW's just fine, but this one, because it's the main, can't just be taken down when wanted. Too many other services behind it that can break and all teams need to be on board when a reboot is required in case those services really bork.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.