Temat: Unbound zamiast dnsmasq
Witam
Próbowałem przejść z dnsmasq na unbound i poległem zrobiłem konfig tak jak w poradnikach lecz net nie działa
kto pomoże?
mój konfig
config zone
option enabled '0'
option fallback '1'
option resolv_conf '1'
option zone_type 'forward_zone'
list zone_name 'isp-bill.example.com.'
list zone_name 'isp-mail.example.net.'
config zone
option enabled '0'
option fallback '1'
option url_dir 'https://www.internic.net/domain/'
option zone_type 'auth_zone'
list server 'lax.xfr.dns.icann.org'
list server 'iad.xfr.dns.icann.org'
list zone_name '.'
list zone_name 'arpa.'
list zone_name 'in-addr.arpa.'
list zone_name 'ip6.arpa.'
config unbound
option add_extra_dns '0'
option add_local_fqdn '1'
option add_wan_fqdn '1'
option dhcp_link 'odhcpd'
option dhcp4_slaac6 '1'
option dns64 '0'
option domain 'lan'
option domain_type 'static'
option edns_size '1280'
option hide_binddata '1'
option listen_port '53'
option localservice '1'
option manual_conf '0'
option num_threads '1'
option protocol 'default'
option rebind_localhost '0'
option rebind_protection '1'
option recursion 'default'
option resource 'default'
option root_age '9'
option extended_luci '1'
option ttl_min '120'
option unbound_control '1'
option validator '1'
option validator_ntp '1'
option verbosity '1'
option enabled '1'
option extended_stats '1'
list trigger_interface 'lan'
list trigger_interface 'wan'
---------------------------------------------
wpis w /etc/unbound/unbound.conf
ssl-upstream: yes
access-control: 127.0.0.0/8 allow
#Adjust the line below for your own subnet
access-control: 192.168.0.0/24 allow
port: 53
cache-min-ttl: 900
cache-max-ttl: 14400
do-ip4: yes
do-ip6: yes
do-tcp: yes
hide-identity: yes
hide-version: yes
qname-minimisation: yes
use-caps-for-id: yes
prefetch: yes
rrset-roundrobin: yes
minimal-responses: yes
#This is setup for Cloudflare, change to another DNS provider that support TLS if you want
forward-zone:
name: "."
forward-addr: 1.1.1.1@853
forward-addr: 1.0.0.1@853
forward-addr: 2606:4700:4700::1111@853
forward-addr: 2606:4700:4700::1001@853
forward-ssl-upstream: yes
oraz
unbound.ext.conf
forward-zone:
name: "."
forward-addr: 1.1.1.1@853
forward-addr: 1.0.0.1@853
forward-addr: 2606:4700:4700::1111@853
forward-addr: 2606:4700:4700::1001@853
forward-ssl-upstream: yes