<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DNS not resolving]]></title><description><![CDATA[<p dir="auto">Hello,<br />
I've been having some problems setting up my SG-1100.<br />
The DNS resolver doesn't work, whatever I try.<br />
I've reset everything to the factory defaults, changed nothing (except for WAN -&gt; PPPoE)<br />
In the services everything appears to be running, but when I do a DNS lookup diag, 127.0.0.1: No Repsonse.<br />
Pinging external addresses works, so internet access is fine.<br />
I did notice this error in the logs every time I restart the service:<br />
Mar 17 19:31:24 	php-fpm 	364 	/services_unbound.php: Unbound /var/unbound/root.key file is corrupt, removing and recreating.<br />
I'm probably missing something, but I have no idea what...</p>
]]></description><link>https://forum.netgate.com/topic/151377/dns-not-resolving</link><generator>RSS for Node</generator><lastBuildDate>Tue, 12 May 2026 15:34:13 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/151377.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 17 Mar 2020 18:41:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DNS not resolving on Tue, 24 Mar 2020 13:19:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kiokoman">@<bdi>kiokoman</bdi></a> said in <a href="/post/898888">DNS not resolving</a>:</p>
<blockquote>
<p dir="auto">ahh regitrar are like mafia, most of them ask money to add ...</p>
</blockquote>
<p dir="auto">Not mafia. They are members of the free world. Any one can ask money for their services.<br />
Maybe you a have registrar with real people that actuality answer the phone and think with you ^^ That's worth some €.</p>
<p dir="auto">Most registrars have a web interface to 'admin' your domain yourself. Or an API, or a web interface that uses their own API to update the registrar manipulations. No need to call them for that (and if you tried, you would be waiting for them, they have to answer the guy that bought a domain name before yesterday, uploaded a site yesterday and wanted to know why his site isn't listed rank 1 Google today).</p>
<p dir="auto">I do rotate my KSK's manually every xx months using my registrars web interface because it's somewhat time critical over a several weeks period. ZSK can be done on the DNS server itself - I'm not using my domain registrar facilities. "bind" has been made to that just fine.<br />
<a href="https://dnsviz.net/d/papy-team.org/dnssec/" target="_blank" rel="noopener noreferrer nofollow ugc">Here you have</a> an out-phasing ZSK on one of my domains :  "39459"' : ZSK's are easy to handle.<br />
KSK's, on the other hand, ask for some concentration. An error WILL blow you site of the Internet and a "restart service" will not bring it back.</p>
<p dir="auto">Btw : sorry - went out of subject .... which was<br />
"/var/unbound/root.key" using PPPoE (using SG1100 ?) (using non-public pfSEnse firmware ?) refuses to refresh.</p>
]]></description><link>https://forum.netgate.com/post/898911</link><guid isPermaLink="true">https://forum.netgate.com/post/898911</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 24 Mar 2020 13:19:39 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Tue, 24 Mar 2020 12:15:48 GMT]]></title><description><![CDATA[<p dir="auto">Registars I have don't ask for anything extra, namecheap and dyndot..</p>
<p dir="auto">And even if they did, pretty sure netgate could afford the $40 ;)</p>
]]></description><link>https://forum.netgate.com/post/898894</link><guid isPermaLink="true">https://forum.netgate.com/post/898894</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 24 Mar 2020 12:15:48 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Tue, 24 Mar 2020 12:02:31 GMT]]></title><description><![CDATA[<p dir="auto">ahh regitrar are like mafia, most of them ask money to add dnssec like it's something special they need to do, godaddy ask for 40$ year for that <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44e.png?v=d00e50224fa" class="not-responsive emoji emoji-android emoji---1" style="height:23px;width:auto;vertical-align:middle" title=":-1:" alt="👎" /></p>
]]></description><link>https://forum.netgate.com/post/898888</link><guid isPermaLink="true">https://forum.netgate.com/post/898888</guid><dc:creator><![CDATA[kiokoman]]></dc:creator><pubDate>Tue, 24 Mar 2020 12:02:31 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Tue, 24 Mar 2020 00:38:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/898804">DNS not resolving</a>:</p>
<blockquote>
<p dir="auto">Hey Netgate, Listening ? DNSSEC isn't 'hard' anymore.</p>
</blockquote>
<p dir="auto">I concur, not sure why netgate.com isn't signed..</p>
]]></description><link>https://forum.netgate.com/post/898805</link><guid isPermaLink="true">https://forum.netgate.com/post/898805</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 24 Mar 2020 00:38:20 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Tue, 24 Mar 2020 00:13:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/waxbear_79">@<bdi>WaxBear_79</bdi></a> said in <a href="/post/898733">DNS not resolving</a>:</p>
<blockquote>
<p dir="auto">the anchor is ok</p>
</blockquote>
<p dir="auto">Make a copy of it ! Or know that you can download it yourself from : https://www.iana.org/dnssec/files and as you can see it's  really signed :)<br />
Know that that anchor - root key file can change !<br />
See the root key (anchor) <a href="https://dnsviz.net/d/papy-team.org/dnssec/" target="_blank" rel="noopener noreferrer nofollow ugc">here</a> in action : every DNSSEC  protected domain has this root key (20326) as the starting trusted key. Those who govern that root key can decide to rotate it - but this one is there to stay for a while.</p>
<p dir="auto">Btw : for your mental health : try do some DNNSEC yourself on your domain(s) (when just DNS is simply boring) : you'll love it. When you've done that, go for DANE support. Your domain and certs will stand against any possible imaginable Internet fail and hack, as they said ...</p>
<p dir="auto">Also : domains that host critical system update files should be DNSSEC protected. If not, a DNS spoof would get our routers update/upgrade code from .... somewhere else. That would kill that brand instantly. Hey Netgate, Listening ? DNSSEC isn't 'hard' anymore.</p>
]]></description><link>https://forum.netgate.com/post/898804</link><guid isPermaLink="true">https://forum.netgate.com/post/898804</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 24 Mar 2020 00:13:13 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Mon, 23 Mar 2020 16:30:07 GMT]]></title><description><![CDATA[<p dir="auto">uhm maybe a firmware bug on that modem <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=d00e50224fa" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title=":shrug:" alt="🤷" /></p>
]]></description><link>https://forum.netgate.com/post/898734</link><guid isPermaLink="true">https://forum.netgate.com/post/898734</guid><dc:creator><![CDATA[kiokoman]]></dc:creator><pubDate>Mon, 23 Mar 2020 16:30:07 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Mon, 23 Mar 2020 16:24:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> No, I had stumbled upon that thread and removed the certificates to test, but still got the same error.<br />
<a class="plugin-mentions-user plugin-mentions-a" href="/user/kiokoman">@<bdi>kiokoman</bdi></a> Tried it, but no luck, couldn't get the root.key to be verified. But it did somewhat point me in the right direction. Certain things weren't getting through.</p>
<p dir="auto">I had an older router/modem lying around, and I swapped the current one with the one had had lying around. Set it to bridge, started the PPPoE session and  now everything seems to be working fine. Ran the unbound-anchor command and immediately got the response success: the anchor is ok</p>
<p dir="auto">Don't know what causes this this to fail on the newer modem, but now it works and that's all I care about ;)</p>
<p dir="auto">Thanks for your help!</p>
]]></description><link>https://forum.netgate.com/post/898733</link><guid isPermaLink="true">https://forum.netgate.com/post/898733</guid><dc:creator><![CDATA[WaxBear_79]]></dc:creator><pubDate>Mon, 23 Mar 2020 16:24:51 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Mon, 23 Mar 2020 11:18:16 GMT]]></title><description><![CDATA[<p dir="auto">Look also here https://forum.netgate.com/topic/143841/netgate-sg-1100-2-4-4-release-p3-unbound-won-t-start - same issue ?</p>
]]></description><link>https://forum.netgate.com/post/898660</link><guid isPermaLink="true">https://forum.netgate.com/post/898660</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 23 Mar 2020 11:18:16 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Mon, 23 Mar 2020 11:16:26 GMT]]></title><description><![CDATA[<p dir="auto">probably a routing issue, that command download stuff from internet<br />
maybe try with<br />
unbound-anchor -4 -a "/var/unbound/root.key"</p>
<p dir="auto">you can use truss to see what's happening if it does not work<br />
truss unbound-anchor -4 -a "/var/unbound/root.key"</p>
]]></description><link>https://forum.netgate.com/post/898658</link><guid isPermaLink="true">https://forum.netgate.com/post/898658</guid><dc:creator><![CDATA[kiokoman]]></dc:creator><pubDate>Mon, 23 Mar 2020 11:16:26 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Sat, 21 Mar 2020 09:22:46 GMT]]></title><description><![CDATA[<p dir="auto">Ok, I've found some time and restored the factory image I got from netgate support.<br />
I've retried, but did not help.<br />
My modem is configured in bridge mode, and now i've set it to router, and reconfigured my WAN interface, and now I can run the unbound-anchor without any problems!<br />
Does anybody know what could be the cause of this? Or how I could analyze what's blocking the root.key update?</p>
]]></description><link>https://forum.netgate.com/post/898290</link><guid isPermaLink="true">https://forum.netgate.com/post/898290</guid><dc:creator><![CDATA[WaxBear_79]]></dc:creator><pubDate>Sat, 21 Mar 2020 09:22:46 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Tue, 17 Mar 2020 22:46:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kiokoman">@<bdi>kiokoman</bdi></a> said in <a href="/post/897460">DNS not resolving</a>:</p>
<blockquote>
<p dir="auto">unbound-anchor -a "/var/unbound/root.key"</p>
</blockquote>
<p dir="auto">Thanks for the fast reply.<br />
It's the latest version: 2.4.4-RELEASE-p3 (arm64)<br />
Unfortunately, the repair didn't help much.<br />
I did get it to work in forward mode without DNSSEC, so I'm saved for the moment.<br />
I'll put in a ticket to request the factory image to reinstall pfsense.</p>
]]></description><link>https://forum.netgate.com/post/897478</link><guid isPermaLink="true">https://forum.netgate.com/post/897478</guid><dc:creator><![CDATA[WaxBear_79]]></dc:creator><pubDate>Tue, 17 Mar 2020 22:46:41 GMT</pubDate></item><item><title><![CDATA[Reply to DNS not resolving on Tue, 17 Mar 2020 20:13:16 GMT]]></title><description><![CDATA[<p dir="auto">is it pfsense 2.4.4-p3 ? i can find this king of trouble only for old version of pfsense<br />
anyway you can try to repair that file from console with</p>
<pre><code>unbound-anchor -a "/var/unbound/root.key"
</code></pre>
<p dir="auto">if it does not work open a ticket at https://go.netgate.com  and ask for instruction on how to reinstall pfsense</p>
]]></description><link>https://forum.netgate.com/post/897460</link><guid isPermaLink="true">https://forum.netgate.com/post/897460</guid><dc:creator><![CDATA[kiokoman]]></dc:creator><pubDate>Tue, 17 Mar 2020 20:13:16 GMT</pubDate></item></channel></rss>