<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Netgate 2100 dns resolver reconfiguration takes very long]]></title><description><![CDATA[<p dir="auto">Hi there,</p>
<p dir="auto">it seems to me that every tiny change of DNS related configurations triggers a full restart of unbound. That takes up 2 minutes where complete DNS resolution (internal and external) isn't working. Some of my services are not amused about that.</p>
<p dir="auto">Is there a tweakable to fix that, or is this behavior works as designed?<br />
I can understand that it's mandatory to restart service for bigger changes in configuration. But absolutely not, if I only want to create a DNS-Record or add a DHCP-Reservation.</p>
<ul>
<li>Firmware: 22.01-RELEASE (arm64)</li>
<li>My Unbound is running in Forward-Mode (Resolver-Mode isn't working with my ISP) to official DNS-Resolvers and used as internally LAN-DNS-Resolver.</li>
<li>Static-DHCP Clients will be registered automatically. Dynamic-DHCP Clients not.</li>
<li>pfBlockerNG is enabled in quite basic configuration</li>
<li>Tried both modes, Python Modul und default Mode. Can't see any different behaviour.</li>
</ul>
<p dir="auto">Are there any suggestions?</p>
]]></description><link>https://forum.netgate.com/topic/172204/netgate-2100-dns-resolver-reconfiguration-takes-very-long</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 04:23:34 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/172204.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 16 May 2022 11:33:18 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Netgate 2100 dns resolver reconfiguration takes very long on Tue, 17 May 2022 06:58:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/keyser">@<bdi>keyser</bdi></a> Ok. But if I disable pfblockerNG (not uninstalling it), it's not significantly faster? I also don't have many subscriptions. Only the basic/default Blacklist is enabled.</p>
]]></description><link>https://forum.netgate.com/post/1042484</link><guid isPermaLink="true">https://forum.netgate.com/post/1042484</guid><dc:creator><![CDATA[n300]]></dc:creator><pubDate>Tue, 17 May 2022 06:58:58 GMT</pubDate></item><item><title><![CDATA[Reply to Netgate 2100 dns resolver reconfiguration takes very long on Mon, 16 May 2022 21:39:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/n300">@<bdi>n300</bdi></a> said in <a href="/post/1042439">Netgate 2100 dns resolver reconfiguration takes very long</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a></p>
<p dir="auto">WAN port was up as far I can see.<br />
<img src="/assets/uploads/files/1652729974504-049a754e-c626-4f1e-9b5a-01f244f93f95-image.png" alt="049a754e-c626-4f1e-9b5a-01f244f93f95-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I think it's unbound related, because also internal DNS resolving from all my clients/servers isn't possible while applying changes.</p>
</blockquote>
<p dir="auto">pfBlockerNG with a bunch of DNSBL feeds active causes this because of the huge block lists that is added to unbound - optionally via python integration. The SG-2100 CPU is not exactly powerfull, so it takes quite a while to load large feeds on that platform.</p>
]]></description><link>https://forum.netgate.com/post/1042447</link><guid isPermaLink="true">https://forum.netgate.com/post/1042447</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Mon, 16 May 2022 21:39:28 GMT</pubDate></item><item><title><![CDATA[Reply to Netgate 2100 dns resolver reconfiguration takes very long on Mon, 16 May 2022 19:41:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a></p>
<p dir="auto">WAN port was up as far I can see.<br />
<img src="/assets/uploads/files/1652729974504-049a754e-c626-4f1e-9b5a-01f244f93f95-image.png" alt="049a754e-c626-4f1e-9b5a-01f244f93f95-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I think it's unbound related, because also internal DNS resolving from all my clients/servers isn't possible while applying changes.</p>
]]></description><link>https://forum.netgate.com/post/1042439</link><guid isPermaLink="true">https://forum.netgate.com/post/1042439</guid><dc:creator><![CDATA[n300]]></dc:creator><pubDate>Mon, 16 May 2022 19:41:05 GMT</pubDate></item><item><title><![CDATA[Reply to Netgate 2100 dns resolver reconfiguration takes very long on Mon, 16 May 2022 19:38:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/n300">@<bdi>n300</bdi></a> Is Internet active at that time?<br />
https://redmine.pfsense.org/issues/12985 looks to be in the upcoming 22.05.</p>
]]></description><link>https://forum.netgate.com/post/1042438</link><guid isPermaLink="true">https://forum.netgate.com/post/1042438</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Mon, 16 May 2022 19:38:08 GMT</pubDate></item><item><title><![CDATA[Reply to Netgate 2100 dns resolver reconfiguration takes very long on Mon, 16 May 2022 19:33:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a></p>
<p dir="auto">Hi Steve,</p>
<p dir="auto">No interesting things in unbound log. OK its only about 1 min. But that's also much to long if I only add a dns alias.<br />
There is only a time hole in log.</p>
<p dir="auto"><img src="/assets/uploads/files/1652729465298-77be4a33-08b9-4190-8eda-26ab260ecb57-image.png" alt="77be4a33-08b9-4190-8eda-26ab260ecb57-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">concerning your question about forwarding:<br />
I only use the server "DNS Resolver". DNS-Forwarder is disabled.<br />
But in DNS Resolver DNS Query Forwarding is enabled.<br />
<img src="/assets/uploads/files/1652729555220-1d8ebb58-3873-4f3e-82b6-22b60456edab-image.png" alt="1d8ebb58-3873-4f3e-82b6-22b60456edab-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Otherwise I'm unable to resolve anything outside my LAN.</p>
]]></description><link>https://forum.netgate.com/post/1042436</link><guid isPermaLink="true">https://forum.netgate.com/post/1042436</guid><dc:creator><![CDATA[n300]]></dc:creator><pubDate>Mon, 16 May 2022 19:33:28 GMT</pubDate></item><item><title><![CDATA[Reply to Netgate 2100 dns resolver reconfiguration takes very long on Mon, 16 May 2022 19:35:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/n300">@<bdi>n300</bdi></a> 2 minutes seems absurdly long.  Do the logs show anything useful?</p>
<p dir="auto">To be clear are you suing DNS Resolver and forwarding, or using DNS Forwarder?</p>
]]></description><link>https://forum.netgate.com/post/1042423</link><guid isPermaLink="true">https://forum.netgate.com/post/1042423</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Mon, 16 May 2022 19:35:55 GMT</pubDate></item></channel></rss>