"New" DNS lookups are often failing once for me ??!
-
I'm seeing the following on multiple endpoints.
I am NOT seeing it in my crucial email server.
Thus, this could be some weird interaction of Windows 10 and the DNS Resolver in pfSense...Reasonably often, a local windows app (browser or otherwise) will tell me that a domain could NOT be found. Yet when I tell it to retry, all is well.
I checked my /var/unbound/access_lists.conf and it is fine.
I assume I have something misconfigured.
Is there some kind of parameter or ??? I need to check?
(Note: I've now enabled server: log-servfail: yes in case that will reveal anything...)
-
What are your pfSense System -> General Settings -> DNS Server Settings?
You might need to disable "DNS Override" and "Use Local DNS (127.0.0.1), fall back on remote DNS (default)". -
@mrpete if you are forwarding, disable DNSSEC. Possibly, DNS over TLS, some have said that helps.
Is unbound restarting often? Consider disabling DHCP registration.
-
@mrpete said in "New" DNS lookups are often failing once for me ??!:
I assume I have something misconfigured.
Might just be some delay in getting an answer and not really a misconfiguration - some details of your unbound config, you say this happens somewhat regular? Is it specific domains your having trouble with that you have noticed?
Your machine your having issues with - its only pointing to pfsense for dns? You don't have multiple dns setup on it? Its not doing or attempting to do doh? etc..
if you are having issues with a specific domain(s).. An example of these could be helpful in tracking down what might be going on.
-
Sorry for the delays... family RL kicked in.
Lots of helpful suggestions... looking into it! THANKS