<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[unbound client forward to knot-resolver server without recursion desired (RD) bit get status REFUSED.]]></title><description><![CDATA[<p dir="auto">I'm working on a hobby project of setup my private remote resolver with knot-resolver. In knot-resolver documentation by default refuse queries without RD bit set to prevent snooping and able to unload the module right now as a workaround for unbound forward queries.</p>
<p dir="auto">My issue is now I have a DNS over tls port available on the remove server for my and I can't stop anyone from snooping the cache.<br />
What setting should set RD bit on out going queries?</p>
]]></description><link>https://forum.netgate.com/topic/174926/unbound-client-forward-to-knot-resolver-server-without-recursion-desired-rd-bit-get-status-refused</link><generator>RSS for Node</generator><lastBuildDate>Sun, 17 May 2026 19:01:09 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/174926.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 26 Sep 2022 09:43:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to unbound client forward to knot-resolver server without recursion desired (RD) bit get status REFUSED. on Mon, 26 Sep 2022 10:32:24 GMT]]></title><description><![CDATA[<p dir="auto">@sauce<br />
I've found <a href="https://knot-resolver.readthedocs.io/en/stable/modules-refuse_nord.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://knot-resolver.readthedocs.io/en/stable/modules-refuse_nord.html</a><br />
How is this related to pfSense ?</p>
]]></description><link>https://forum.netgate.com/post/1063394</link><guid isPermaLink="true">https://forum.netgate.com/post/1063394</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 26 Sep 2022 10:32:24 GMT</pubDate></item></channel></rss>