Created by: ston1th 2019-06-14 12:45:07
Updated by: daniel 2023-01-05 11:21:28
Visibility: Public

OpenBSD DNS Resolver

Config

Download root hints: ftp -o /var/unbound/db/root.hints https://www.internic.net/domain/named.root

Optional: DNS based ADs filtering Unbound Updater Script

resolv.conf:

echo "nameserver 127.0.0.1" > /etc/resolv.conf

unbound.conf

cat <<EOF> /var/unbound/etc/unbound.conf
server:
        interface: 127.0.0.1
        interface: 172.17.0.1
        access-control: 172.17.0.0/30 allow
        private-address: 10.0.0.0/8
        private-address: 172.16.0.0/12
        private-address: 192.168.0.0/16
        private-address: 169.254.0.0/16
        # private-address: fd00::/8
        # private-address: fe80::/10
        # private-address: ::ffff:0:0/96
        tls-cert-bundle: /etc/ssl/cert.pem
        auto-trust-anchor-file: "/var/unbound/db/root.key"
        root-hints: "/var/unbound/db/root.hints"
        do-not-query-localhost: no
        qname-minimisation-strict: yes
        # max-udp-size: 1024
        # rrset-roundrobin: yes
        # rrset-cache-size: 30m
	so-reuseport: no
        rrset-roundrobin: yes
        use-caps-for-id: yes
        hide-identity: yes
        hide-version: yes
        identity: "DNS"
        # tcp-upstream: yes
        # tls-upstream: yes
        num-threads: 2
        aggressive-nsec: yes
        neg-cache-size: 4M
        deny-any: yes
        harden-algo-downgrade: yes
        harden-below-nxdomain: yes
        harden-dnssec-stripped: yes
        harden-glue: yes
        harden-large-queries: yes
        harden-short-bufsize: yes
        val-clean-additional: yes
        # val-permissive-mode: yes
        minimal-responses: yes
        prefetch: yes
        prefetch-key: yes
        infra-cache-slabs: 4
        key-cache-slabs: 4
        msg-cache-size: 128525653
        msg-cache-slabs: 4
        rrset-cache-size: 257051306
        rrset-cache-slabs: 4
        # ip-ratelimit: 10
        # ip-ratelimit-slabs: 2
        # ip-ratelimit-factor: 2
include: "/var/unbound/etc/unbound_ads_filter.conf"

remote-control:
        control-enable: yes

forward-zone:
        name: "."
        forward-tls-upstream: yes
        forward-addr: 1.1.1.1@853#cloudflare-dns.com
        forward-addr: 1.0.0.1@853#cloudflare-dns.com
        # forward-addr: 2606:4700:4700::1111@853#cloudflare-dns.com
        # forward-addr: 2606:4700:4700::1001@853#cloudflare-dns.com
        forward-addr: 9.9.9.9@853#dns.quad9.net
        forward-addr: 149.112.112.112@853#dns.quad9.net
        # forward-addr: 2620:fe::fe@853#dns.quad9.net
        # forward-addr: 2620:fe::9@853#dns.quad9.net
        # forward-addr: 8.8.8.8@853#dns.google
        # forward-addr: 8.8.4.4@853#dns.google
EOF

Setup control: unbound-control-setup

If you are using the DNS filter lists on slow machines (like home routers) you need to increase the daemon start timeout:

echo "unbound_timeout=500" >>/etc/rc.conf.local

Start unbound:

rcctl enable unbound
rcctl start unbound