Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Frequent Unbound restarts with pfsense+ 25.11.1

    Scheduled Pinned Locked Moved DHCP and DNS
    34 Posts 4 Posters 2.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      markster
      last edited by

      I wanted to try DNS resolver on pfsense latest version jut to confirm the old issue. I do not see any changes on my 5100.
      Still get freqent restarts even with DNS Registration disabled.
      Is there any timeframe that we can expect this issue to be completly 100% fixed?

      Screenshot 2026-03-18 at 3.44.16 PM.png Screenshot 2026-03-18 at 3.44.00 PM.png

      SteveITSS GertjanG 2 Replies Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @markster
        last edited by

        @markster seeing that every 5 or 10 minutes seems a bit suspicious. Do you have something running that frequently/frequency? You might install the cron package to look at jobs.

        It doesn’t normally just restart on its own…DNS registration as you mentioned is the most common cause.

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          markster @SteveITS
          last edited by

          @SteveITS Nothing special that I run would affect that.
          Screenshot 2026-03-18 at 5.41.01 PM.png

          But see DHCP log and you see these messages
          Screenshot 2026-03-18 at 5.41.47 PM.png

          So it tells me that the setting DNS Registration is not working at all. and the issue with kea2unbound has been documented. I have few static IP's but all AP devices get dynamic IP.

          SteveITSS 1 Reply Last reply Reply Quote 0
          • SteveITSS Offline
            SteveITS Rebel Alliance @markster
            last edited by

            @markster Hm how long is your DHCP lease time?

            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Only install packages for your version of pfSense.
            Upvote 👍 helpful posts!

            M 1 Reply Last reply Reply Quote 0
            • M Offline
              markster @SteveITS
              last edited by

              @SteveITS Default at 7200 sec.

              M 1 Reply Last reply Reply Quote 0
              • M Offline
                markster @markster
                last edited by markster

                I checked the /var/unbound/leases/leases4.conf and its empty file. That maybe cause I turned DNS Resolver off.

                SteveITSS 1 Reply Last reply Reply Quote 0
                • SteveITSS Offline
                  SteveITS Rebel Alliance @markster
                  last edited by

                  @markster The leases files I think should be empty (95 byte header) if you're not registering the leases in DNS. At least, mine are.

                  Are you using Kea for DHCP? I don't think that should matter but I'll ask.

                  My unbound restarts usually once a day, looks like at pfBlocker's morning update interval. Sometimes when I make other changes. All the ones on March 10 here were when I upgraded to 23.06 RC. Then it's once a day but skipping March 13 and 15.

                  : grep "start of" resolver.log.0
                  Mar 10 19:12:47 pfSense unbound[60115]: [60115:0] info: start of service (unbound 1.24.2).
                  Mar 10 19:24:00 pfSense unbound[27762]: [27762:0] info: start of service (unbound 1.24.2).
                  Mar 10 19:29:49 pfSense unbound[50702]: [50702:0] info: start of service (unbound 1.24.2).
                  Mar 10 19:52:08 pfSense unbound[66040]: [66040:0] info: start of service (unbound 1.24.2).
                  Mar 10 19:52:15 pfSense unbound[3419]: [3419:0] info: start of service (unbound 1.24.2).
                  Mar 10 20:01:07 pfSense unbound[3419]: [3419:0] notice: Restart of unbound 1.24.2.
                  Mar 10 20:01:07 pfSense unbound[3419]: [3419:0] info: start of service (unbound 1.24.2).
                  Mar 10 20:01:11 pfSense unbound[20361]: [20361:0] info: start of service (unbound 1.24.2).
                  Mar 10 20:01:46 pfSense unbound[20361]: [20361:0] notice: Restart of unbound 1.24.2.
                  Mar 10 20:01:46 pfSense unbound[20361]: [20361:0] info: start of service (unbound 1.24.2).
                  Mar 10 20:01:52 pfSense unbound[88828]: [88828:0] info: start of service (unbound 1.24.2).
                  Mar 11 05:15:24 pfSense unbound[9197]: [9197:0] info: start of service (unbound 1.24.2).
                  Mar 12 05:15:17 pfSense unbound[68338]: [68338:0] info: start of service (unbound 1.24.2).
                  Mar 14 05:15:18 pfSense unbound[19185]: [19185:0] info: start of service (unbound 1.24.2).
                  Mar 16 05:15:22 pfSense unbound[43014]: [43014:0] info: start of service (unbound 1.24.2).
                  Mar 17 05:15:18 pfSense unbound[51419]: [51419:0] info: start of service (unbound 1.24.2).
                  

                  One of the things Kea added was to be able to make DNS changes without fully restarting unbound.

                  To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                  Only install packages for your version of pfSense.
                  Upvote 👍 helpful posts!

                  1 Reply Last reply Reply Quote 0
                  • GertjanG Offline
                    Gertjan @markster
                    last edited by

                    @markster

                    pfBlockerng can (will ?) restart unbound on when one or more of the DNSBL feeds was updated.
                    If you update these "every hour" then changes are great that unbound will get restarted every hour.
                    Easy solution : select 'every week'.

                    There are more reasons why unbound restarts. And not only unbound.
                    Look at the main system pfSense log, and you'll see the reasons. You only have to recognize them as such ^^

                    Example : hook up your PC directly to the (a) pfSense LAN interface - without using a switch.
                    Every time you PC goes into power down or sleep mode, it will change the network settings, like going to a more 'green' power friendly 10Mbit/sec. This will introduce a LAN interface DOWN and UP event.
                    And this event will trigger all, not only unbound, processes to restart.

                    You want unbound to 'never' restarted ?
                    That's possible.
                    Solution : create the situation where all pfSense interfaces (WAN, LAN etc) never go down or switch modes. I use an UPS for my pfSense, the upstream ISP router, and all downstream pfSense LANs are powered with this UPS, so they rarely go down.

                    Btw : the new DHCP server kea will, if you want, collect lease info that contains a host name, and communicate that to unbound over a 'pipe', so it can registerer new hostnames into the local DNS (unbound), or removing them. This doesn't need a unbound restart anymore. That's what kea2unbound is all about.

                    So : look at the system log, and tell us what the reason is why your unbound, and many other processes restarted ?

                    [26.03-RC][root@pfSense.bhf.tld]root: grep "start of service" /var/log/resolver.log | wc -l
                         175
                    

                    My /var/log/resolver.log file oldest entries are from December 2025.
                    About 90 days, 175 restarts, that's 2 restarts a day.
                    I do mess around a lot with my pfSense.
                    I do have to reboot it for new updates, etc.
                    Nearly all my devices on all my LANs uses static DHCP leases, for v4 and V6, about 80. These are all registered. This happens ones, so lease renewals won't trigger kea12unbound anymore, as the leases are 'static' thus already present in the DNS even when the device is powered down or unavailable.

                    The DHCP leases of the devices on my captive portal network are not registered, as I don't care about their hostname : I'm don't want to connect to the device of a visitor ^^

                    No "help me" PM's please. Use the forum, the community will thank you.

                    M 1 Reply Last reply Reply Quote 0
                    • M Offline
                      markster @Gertjan
                      last edited by

                      @Gertjan I am using KEA DHCP but I do not have pfBlocker installed.
                      I run Unbound in a docker container on Synology and this guy never restarts. I refesh my rpz files daily but only do reload if there are changes.
                      I just wanted to try and see if the issue was resolved on pfsense so it does not affect my prodcution but it does look like the issue is still there.

                      SteveITSS 1 Reply Last reply Reply Quote 0
                      • SteveITSS Offline
                        SteveITS Rebel Alliance @markster
                        last edited by

                        @markster Any chance an(y) interface is going down and up? That triggers restart of many services.

                        I'm still stuck on "what happens every 5 or 10 minutes" but not other intervals.

                        Bottom line is, it's not supposed to restart outside of the above conditions (interface, pfBlocker, something restarting it, DHCP registration...maybe others?) so isn't just "a bug" that needs fixing, it's something specific that you're encountering on this router/config.

                        I missed your image showing Kea on my phone, sorry.

                        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                        Only install packages for your version of pfSense.
                        Upvote 👍 helpful posts!

                        M 1 Reply Last reply Reply Quote 0
                        • M Offline
                          markster @SteveITS
                          last edited by

                          @SteveITS I think for use cases like mine where I want to have a complete independence between Unbound and KEA DHCP is to make this file (kea2unbound) read-only. This would resolve the issue.

                          SteveITSS 1 Reply Last reply Reply Quote 0
                          • SteveITSS Offline
                            SteveITS Rebel Alliance @markster
                            last edited by

                            @markster It's a program, and is read only except for root:
                            -rwxr-xr-x 1 root wheel 22491 Jan 19 11:24 /usr/local/bin/kea2unbound

                            I don't know why it seems to run a lot, even if not using Kea and/or DNS registration IIRC, but it's purpose is to not have to restart unbound.

                            I would check your other logs at the above times e.g. 13:37.

                            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                            Only install packages for your version of pfSense.
                            Upvote 👍 helpful posts!

                            M 1 Reply Last reply Reply Quote 0
                            • M Offline
                              markster @SteveITS
                              last edited by markster

                              @SteveITS Unfortunatly this solution did not work. There are other programs that interract with DNS resolver.
                              I noticed in the general log that everytime DNS resolver stops and starts is at the same time as /rc.newwanip: rc.newwanip are run on my 5100 box.
                              I will stay with what I have - Unbound runing in docker on Synology. Rock solid.

                              SteveITSS 1 Reply Last reply Reply Quote 0
                              • SteveITSS Offline
                                SteveITS Rebel Alliance @markster
                                last edited by

                                @markster said in Frequent Unbound restarts with pfsense+ 25.11.1:

                                everytime DNS resolver stops and starts is at the same time as /rc.newwanip

                                yep there it is.

                                interface is going down and up

                                That will trigger restart of many/most services to pick up the "new IP."

                                So what is triggering that? It's not logging a "link down" and up again is it?

                                Technically I think that script triggers on any interface change...for instance if a PC is plugged directly into a router port, and going to sleep/waking, or rebooting.

                                To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                                Only install packages for your version of pfSense.
                                Upvote 👍 helpful posts!

                                M 1 Reply Last reply Reply Quote 0
                                • M Offline
                                  markster @SteveITS
                                  last edited by

                                  @SteveITS Yes, which is very strange implementation. Adding new IP should not under any case restart DNS. I dont know the thinking behind this was in the past, but to me DNS should not be involved.
                                  This is a large change so I do think it will take a long time to figure it out and do all changes. Meantime (for me) I will stay with the architecture I have had for past few years now and keep my DNS separate from pfsense.

                                  SteveITSS GertjanG 2 Replies Last reply Reply Quote 0
                                  • SteveITSS Offline
                                    SteveITS Rebel Alliance @markster
                                    last edited by

                                    @markster It’s because it has to bind to listen on the new IP.

                                    To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                                    Only install packages for your version of pfSense.
                                    Upvote 👍 helpful posts!

                                    1 Reply Last reply Reply Quote 0
                                    • GertjanG Offline
                                      Gertjan @markster
                                      last edited by

                                      @markster said in Frequent Unbound restarts with pfsense+ 25.11.1:

                                      very strange implementation

                                      Get another router (firewall). The low bud stuff, the high end ones.
                                      You'll discover something. They all do this.
                                      If the router(firewall) is just a dumb dns forwarder, you wouldn't notice anything.
                                      And this might be part of a solution : de activate unbound. Activate dnsmasq, called "DNS Forwarder". I guess the forwarder still also restart if network interfaces disappears, or become active, but as it is much smaller, this will happen way faster.

                                      See a router as a main traffic intersection point. Every time you remove or add a road to it, the traffic lights system has to 'restart' to take in account the new situation.
                                      That's why I suggested to keep the interfaces on a router as 'always on' - they never should go down (or up). Switches are the devices that handle devices that come and go.
                                      Not routers.
                                      And I've a good example : go visit a data center. For many reasons, routers etc are not (like never) to but shut down.
                                      Keeping all interfaces up and running all the time will solve, amongst others :
                                      "Frequent Unbound restarts with pfsense+ 25.11.1".

                                      @SteveITS said in Frequent Unbound restarts with pfsense+ 25.11.1:

                                      It’s because it has to bind to listen on the new IP.

                                      The new interface (IP ?) can also be a WAN type interface. Which means this would impact the routing table. Etc.

                                      No "help me" PM's please. Use the forum, the community will thank you.

                                      M 1 Reply Last reply Reply Quote 0
                                      • M Offline
                                        markster @Gertjan
                                        last edited by markster

                                        @Gertjan No idea what this is all about.
                                        I use netagte SB-5100 firewall. Ports are independent not switched.
                                        I run Unbund as resolver and using rpz zones for DNS blocking.
                                        I refresh rpz files every day. You can think of this as a light implementation of pfBlocker.
                                        DNS Resolver does not need to be aware of any local network IP changes etc. That is not its job. Its only job is to resolve names to IP addresses. Keep it simple.
                                        In pfsense we have this DNS registration and other stuff that is not necessary and in fact makes thiusng worst, hence DNS Resiolver restarts issues. The code to restart unbound seems to be in many places which makes things difficult to fix. I get it.
                                        My solution is just that. Separate DHCP from DNS. It never fails.

                                        You dont have to educate me about this. I have been there for many, many years in various roles. You can run your DNS on pfsense but I will stick to my architecture for now. I do not see the reasons to run DNS Resolver on pfsense untill it is properly running as a separate code or I have more control over when and who is restarting it.

                                        bmeeksB GertjanG 2 Replies Last reply Reply Quote 0
                                        • bmeeksB Offline
                                          bmeeks @markster
                                          last edited by bmeeks

                                          @markster said in Frequent Unbound restarts with pfsense+ 25.11.1:

                                          DNS Resolver does not need to be aware of any local network IP changes etc. That is not its job. Its only job is to resolve names to IP addresses. Keep it simple.

                                          I think you may be missing how things work internally down at the network interface and kernel level. The restart has nothing to do with looking up IP addresses for domain names. Instead, it is required due to how Unbound needs to talk to the network kernel in order to even receive requests for domain lookups.

                                          When starting up, Unbound makes a system call to "bind" to all interfaces it is configured to listen on for incoming DNS requests. The default configuration in pfSense is for Unbound to listen and bind to ALL interfaces.

                                          Anytime an IP address is added or removed from an interface, the kernel will in essence "bounce" that interface and all processes that had previously issued a "bind" call on that interface must repeat their call to obtain a new bind handle so they can listen for incoming requests on the new IP address. Unbound only issues bind requests when starting up, thus in order to re-establish a bind request, Unbound must be restarted. That's why the pfSense code restarts it each time an IP address is added or removed from an interface that Unbound is "bound" to.

                                          You can minimize Unbound restarts by being selective about which interfaces you bind Unbound to.

                                          SteveITSS 1 Reply Last reply Reply Quote 1
                                          • SteveITSS Offline
                                            SteveITS Rebel Alliance @bmeeks
                                            last edited by

                                            I think the core of OP's problem is to find out why the newwanip is triggering so often...what interface is changing at those times.

                                            (@bmeeks All of that is right but it is mildly confusing to read a description of unbound with the word bind (BIND program) throughout. ;) )

                                            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                                            Only install packages for your version of pfSense.
                                            Upvote 👍 helpful posts!

                                            bmeeksB 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                            Privacy Policy · Cookie Policy