<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[unbound not resolving some names]]></title><description><![CDATA[<p dir="auto">Hi,<br />
I'm using pfSense Version 2.4.5-RELEASE-p1 with pfBlockerNG-devel 3.0.0_7 installed. A VPN is configured (nordvpn).</p>
<p dir="auto">I experience some issues that specific names cannot be resolved. The example I use for testing is dennenbos.nl and sometimes it also occurs with daserste.de. If I connect my notebook directly to my ISP router with no pfSense in between, I can access the web sites without any problems.<br />
If I connect using pfSense I get the message <code>DNS_PROBE_FINISHED_NXDOMAIN</code> in the browser.</p>
<p dir="auto">DNS Lookup<br />
<img src="/assets/uploads/files/1609769170933-c721c6f5-66d3-4e34-9b05-a93d32c39441-image.png" alt="c721c6f5-66d3-4e34-9b05-a93d32c39441-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">nslookup from PC<br />
<img src="/assets/uploads/files/1609769222290-fffd26a6-fa6c-4d42-9e60-f7d560880c44-image.png" alt="fffd26a6-fa6c-4d42-9e60-f7d560880c44-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">dig from pfSense router<br />
<img src="/assets/uploads/files/1609769345749-04cfb037-d048-408f-9b4b-a29069e55e4b-image.png" alt="04cfb037-d048-408f-9b4b-a29069e55e4b-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Configuration (General setup)<br />
<img src="/assets/uploads/files/1609769389153-42cd873f-e019-45f1-b2c6-3883deb90cec-image.png" alt="42cd873f-e019-45f1-b2c6-3883deb90cec-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Configuration (DNS Resolver)<br />
<img src="/assets/uploads/files/1609769597628-51c3e389-5425-4f0a-b99e-4e542fe44fa0-image.png" alt="51c3e389-5425-4f0a-b99e-4e542fe44fa0-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><img src="/assets/uploads/files/1609769662767-b6a4e316-5cf3-438d-9b56-4d2e15e2c659-image.png" alt="b6a4e316-5cf3-438d-9b56-4d2e15e2c659-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><img src="/assets/uploads/files/1609769694742-d552932b-5d2e-4349-b3cd-4e297e53b17b-image.png" alt="d552932b-5d2e-4349-b3cd-4e297e53b17b-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">From the unbound logs<br />
<img src="/assets/uploads/files/1609769534509-fd884381-be60-43e9-b0fa-4d2ee50ec540-image.png" alt="fd884381-be60-43e9-b0fa-4d2ee50ec540-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">DNSSEC debugger<br />
<img src="/assets/uploads/files/1609769828777-d80d8543-4746-4640-b4cf-29c5e2391c05-image.png" alt="d80d8543-4746-4640-b4cf-29c5e2391c05-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">There are no log entries from pfBlockerNG in the logs wrt. this issue.</p>
<p dir="auto">What is the best way to follow up on this issue?</p>
<p dir="auto">Regards Andreas</p>
]]></description><link>https://forum.netgate.com/topic/159639/unbound-not-resolving-some-names</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Apr 2026 21:53:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/159639.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 04 Jan 2021 14:18:32 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to unbound not resolving some names on Fri, 08 Jan 2021 14:14:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/an-erd">@<bdi>an-erd</bdi></a> said in <a href="/post/955538">unbound not resolving some names</a>:</p>
<blockquote>
<p dir="auto">Ok, I forwarded this issue to the VPN provider</p>
</blockquote>
<p dir="auto">you will not achieve much with this <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=d00e50224fa" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=":wink:" alt="😉" /></p>
<p dir="auto">(all VPN service providers indicate in their operating conditions (general terms of service) that the use of VPN in many cases causes some websites to be unusable)</p>
<p dir="auto">you have to live with it or you can do tricks</p>
]]></description><link>https://forum.netgate.com/post/955632</link><guid isPermaLink="true">https://forum.netgate.com/post/955632</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Fri, 08 Jan 2021 14:14:42 GMT</pubDate></item><item><title><![CDATA[Reply to unbound not resolving some names on Thu, 07 Jan 2021 19:29:05 GMT]]></title><description><![CDATA[<p dir="auto">In addition, since there are only a few static adresses I'm missing, I use a Firewall / Alias.</p>
]]></description><link>https://forum.netgate.com/post/955543</link><guid isPermaLink="true">https://forum.netgate.com/post/955543</guid><dc:creator><![CDATA[an-erd]]></dc:creator><pubDate>Thu, 07 Jan 2021 19:29:05 GMT</pubDate></item><item><title><![CDATA[Reply to unbound not resolving some names on Thu, 07 Jan 2021 18:46:32 GMT]]></title><description><![CDATA[<p dir="auto">Ok, I forwarded this issue to the VPN provider, and in the meantime I'll use CloudFlare (or just skip the non-working domains)</p>
<p dir="auto">Thanks<br />
Andreas</p>
]]></description><link>https://forum.netgate.com/post/955538</link><guid isPermaLink="true">https://forum.netgate.com/post/955538</guid><dc:creator><![CDATA[an-erd]]></dc:creator><pubDate>Thu, 07 Jan 2021 18:46:32 GMT</pubDate></item><item><title><![CDATA[Reply to unbound not resolving some names on Thu, 07 Jan 2021 17:57:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/an-erd">@<bdi>an-erd</bdi></a> said in <a href="/post/955519">unbound not resolving some names</a>:</p>
<blockquote>
<p dir="auto">For 2) I don't get it resolved with the VPN providers DNS Server</p>
</blockquote>
<p dir="auto">so it is clear that the VPN is causing this behavior...<br />
this also happens to us in some domain cases (ExpVPN), not all web site operators like VPN IPs :-)</p>
<p dir="auto">we use CloudFlare DNS servers because we have a lot of services at CloudFlare (CDN, etc.)</p>
<p dir="auto">no leaks or we just think hahaha <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=d00e50224fa" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=":wink:" alt="😉" /></p>
<p dir="auto">you <strong>do not need to use DoT on the internal network (LAN)</strong>, except if you configured the clients for this (853)</p>
<p dir="auto">try forwarding to 1.1.1.1 with DoT</p>
<p dir="auto"><img src="/assets/uploads/files/1610042118321-04b07fa7-0af9-4dfc-a2bc-0aefa774e521-image.png" alt="04b07fa7-0af9-4dfc-a2bc-0aefa774e521-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/955530</link><guid isPermaLink="true">https://forum.netgate.com/post/955530</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Thu, 07 Jan 2021 17:57:37 GMT</pubDate></item><item><title><![CDATA[Reply to unbound not resolving some names on Thu, 07 Jan 2021 16:46:42 GMT]]></title><description><![CDATA[<p dir="auto">I did tests now with the following scenarios (checked with traceroute):</p>
<ol>
<li>All traffic routed directly to WAN without VPN</li>
<li>Traffic routed through VPN</li>
</ol>
<p dir="auto"><strong>For 1)</strong> I can resolve the domain names correctly, although <code>dig @103.86.96.100 dennenbos.nl</code> shows some issues if used with <code>+trace</code> option.</p>
<pre><code>pi@raspberrypi:~ $ dig @103.86.96.100 dennenbos.nl

; &lt;&lt;&gt;&gt; DiG 9.10.3-P4-Raspbian &lt;&lt;&gt;&gt; @103.86.96.100 dennenbos.nl
; (1 server found)
;; global options: +cmd
;; Got answer:
;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 31645
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 3

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;dennenbos.nl.                  IN      A

;; ANSWER SECTION:
dennenbos.nl.           3600    IN      A       167.71.67.196

;; AUTHORITY SECTION:
dennenbos.nl.           3600    IN      NS      ns2.mundofy.com.
dennenbos.nl.           3600    IN      NS      ns1.mundofy.com.

;; ADDITIONAL SECTION:
ns1.mundofy.com.        172800  IN      A       104.248.90.27
ns2.mundofy.com.        172800  IN      A       134.209.88.180

;; Query time: 52 msec
;; SERVER: 103.86.96.100#53(103.86.96.100)
;; WHEN: Thu Jan 07 16:45:07 GMT 2021
;; MSG SIZE  rcvd: 136
</code></pre>
<p dir="auto">and</p>
<pre><code>pi@raspberrypi:~ $ dig @103.86.96.100 dennenbos.nl +trace

; &lt;&lt;&gt;&gt; DiG 9.10.3-P4-Raspbian &lt;&lt;&gt;&gt; @103.86.96.100 dennenbos.nl +trace
; (1 server found)
;; global options: +cmd
.                       328448  IN      NS      g.root-servers.net.
.                       328448  IN      NS      k.root-servers.net.
.                       328448  IN      NS      c.root-servers.net.
.                       328448  IN      NS      i.root-servers.net.
.                       328448  IN      NS      e.root-servers.net.
.                       328448  IN      NS      b.root-servers.net.
.                       328448  IN      NS      h.root-servers.net.
.                       328448  IN      NS      f.root-servers.net.
.                       328448  IN      NS      m.root-servers.net.
.                       328448  IN      NS      a.root-servers.net.
.                       328448  IN      NS      l.root-servers.net.
.                       328448  IN      NS      j.root-servers.net.
.                       328448  IN      NS      d.root-servers.net.
.                       518400  IN      RRSIG   NS 8 0 518400 20210120050000 20210107040000 42351 . JD5rhQdUsJ9zkDTJl/FOgKg4azCLthLFBkKAVu8ABX0ZAjhdVYt6QK42 sKyttJZJ7iRwFXrbSzzdJmTZDeoKUGYNkr13gx8XTUSMxWmoXTUzpM2B +KAGmGtLu0bHAmY+jmvTbTxfns9BLHVVO2j3xd4Rb76Tg5EhSUSUItgt f+Kqd/cnjybmCUU2xAUpNRFB37cehu12tv2O6u39sZBKyAl6pJ4mXzXL qdQ76HpMQm52zUtaZEZH0+dxVD4itXpnrBtobVKImKKTa7Au6ICFk4I2 /VTp3GAgUaqUYF5J0DZ0YXlFVCW7qd3ql0emr0slHt7Shkfmk9gr3Zf8 ci5uKA==
;; Received 775 bytes from 103.86.96.100#53(103.86.96.100) in 10 ms

nl.                     172800  IN      NS      ns1.dns.nl.
nl.                     172800  IN      NS      ns2.dns.nl.
nl.                     172800  IN      NS      ns3.dns.nl.
nl.                     86400   IN      DS      34112 8 2 3C5B5F9B3557455C50751A9BE9EBE9238C88E19F5F07F930976917B5 1B95CD22
nl.                     86400   IN      RRSIG   DS 8 1 86400 20210120050000 20210107040000 42351 . Z8mHfWrJmJ8MlcJ6UxhecqFuVfs4/h2iSX6yHhyboAnFyJo4fBIyYvsL +c87YBmHTVcd+oL2vx+H7DYdSrJ+lQOhn+TvcnmFq949c9Bngyq2jY+g z6+w6/G9WOnguKyVtTaWWLyRBuJB8TpvvqUO7w3xrCpTm6QSXia2u95f G6BvSLa6InnONo4yLluamSYHKR3yvF2ZGQ0X7hYduVYiDPP7HooCO21d WMrKLkWf+y8ix0PSiExJVwkUlReKl3eoyn36wP4fTC72CeAzg575feP2 rYWwJRgUms0Zt11Y2FJt5QWRGb0qN3xQsZ4/eYBFMUC7bsLhaxT+3tet dMBd7Q==
;; Received 566 bytes from 199.9.14.201#53(b.root-servers.net) in 22 ms

dennenbos.nl.           3600    IN      NS      ns1.mundofy.com.
dennenbos.nl.           3600    IN      NS      ns2.mundofy.com.
4q39dndh55ru1qmltiugutcm8cpm9jud.nl. 600 IN NSEC3 1 1 5 673E58266D988DA4 4Q39F5H7MJI61GVNA77NCDJU3BVMJP6P NS SOA TXT RRSIG DNSKEY NSEC3PARAM
4q39dndh55ru1qmltiugutcm8cpm9jud.nl. 600 IN RRSIG NSEC3 8 2 600 20210110175349 20201227124017 4309 nl. o9QZnT62dPI+F4mDl2DU5t/cvy5+g1fTMCWHAc2VSCk+D+k9x9vT9Yha H9iNthkUWQYyZIEdWMR6qwY+sbSUmPVrrR5m8mcztaZwWTOrjvrRxUFp EcW/qMnW9zNeQW67XW7UslFun1AnIdrnZI2Etov8C/vkFpCC0D8l+uJc EjE=
3qvg9ojtik95bbmoa0rhrbegl132i8g4.nl. 600 IN NSEC3 1 1 5 673E58266D988DA4 3QVGT9NIGUKCAUJTSMCKNB4ARGJ2R6Q8 NS DS RRSIG
3qvg9ojtik95bbmoa0rhrbegl132i8g4.nl. 600 IN RRSIG NSEC3 8 2 600 20210110205953 20201227164014 4309 nl. QZ8ZsYwu30mqc5mH5DLMZ4Gu+DwedilPpU+uajKlFE8hRJ8hdkOh56oq acWhcI5nfzPSPsWxUdDjpNmBYk1Xjwgcbs3y6klHTQ2500fBuQ59GwbF 5rOssFEKJCasFt3XyIZeki+9Jotzifew/+pMEKvJ8FsY3bqO1hxvg3nN kSg=
couldn't get address for 'ns1.mundofy.com': failure
couldn't get address for 'ns2.mundofy.com': failure
dig: couldn't get address for 'ns1.mundofy.com': no more
pi@raspberrypi:~ $

</code></pre>
<p dir="auto">I get the same results when using DNS 1.1.1.1.</p>
<p dir="auto"><strong>For 2)</strong> I don't get it resolved with the VPN providers DNS Server</p>
<p dir="auto">But when using 1.1.1.1 or 8.8.8.8 or so everything works (with the issue shown above when using <code>+trace</code> option.</p>
<pre><code>pi@raspberrypi:~ $ dig @103.86.96.100 dennenbos.nl

; &lt;&lt;&gt;&gt; DiG 9.10.3-P4-Raspbian &lt;&lt;&gt;&gt; @103.86.96.100 dennenbos.nl
; (1 server found)
;; global options: +cmd
;; Got answer:
;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: SERVFAIL, id: 11892
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;dennenbos.nl.                  IN      A

;; Query time: 33 msec
;; SERVER: 103.86.96.100#53(103.86.96.100)
;; WHEN: Thu Jan 07 16:43:44 GMT 2021
;; MSG SIZE  rcvd: 41

pi@raspberrypi:~ $ dig @1.1.1.1 dennenbos.nl

; &lt;&lt;&gt;&gt; DiG 9.10.3-P4-Raspbian &lt;&lt;&gt;&gt; @1.1.1.1 dennenbos.nl
; (1 server found)
;; global options: +cmd
;; Got answer:
;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 45472
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;dennenbos.nl.                  IN      A

;; ANSWER SECTION:
dennenbos.nl.           2926    IN      A       167.71.67.196

;; Query time: 23 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Thu Jan 07 16:43:49 GMT 2021
;; MSG SIZE  rcvd: 57

pi@raspberrypi:~ $
</code></pre>
<p dir="auto">I do have this issue not only for this site, sometimes I get it for amazon.de, daserste.de and other frequently used sites.</p>
<p dir="auto">I don't want to use 1.1.1.1 as an additional DNS server to not provide any DNS leaks.</p>
<p dir="auto">(I unchecked DoT again, I did some tests whether the problem was caused by this option.)</p>
<p dir="auto">Any ideas?</p>
<p dir="auto">Regards Andreas</p>
]]></description><link>https://forum.netgate.com/post/955519</link><guid isPermaLink="true">https://forum.netgate.com/post/955519</guid><dc:creator><![CDATA[an-erd]]></dc:creator><pubDate>Thu, 07 Jan 2021 16:46:42 GMT</pubDate></item><item><title><![CDATA[Reply to unbound not resolving some names on Thu, 07 Jan 2021 12:40:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/an-erd">@<bdi>an-erd</bdi></a> said in <a href="/post/954945">unbound not resolving some names</a>:</p>
<blockquote>
<p dir="auto">What is the best way to follow up on this issue?</p>
</blockquote>
<p dir="auto">Hi,</p>
<p dir="auto">I would do this as a first debugging step:</p>
<p dir="auto">Try without VPN, - through the pfSense... to ISP<br />
(since you can see the domain in question is resolved , -Lookup on BOX)<br />
set an interface where there is no VPN as outbound interface</p>
<p dir="auto"><em>like here:</em><br />
LAN w/o VPN<br />
VPNPT w ExpVPN</p>
<p dir="auto"><img src="/assets/uploads/files/1610023083963-8a4da72b-3964-4262-9b5a-605ba2694eda-image.png" alt="8a4da72b-3964-4262-9b5a-605ba2694eda-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">BTW:</p>
<p dir="auto">why are you using DoT on your internal network?</p>
<p dir="auto"><img src="/assets/uploads/files/1610022945656-9514c25e-2e45-47bd-95ca-00a1461ece9f-image.png" alt="9514c25e-2e45-47bd-95ca-00a1461ece9f-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/955488</link><guid isPermaLink="true">https://forum.netgate.com/post/955488</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Thu, 07 Jan 2021 12:40:12 GMT</pubDate></item></channel></rss>