3 ms·
It seems to be the default for Unbound, at least on OPNSense. Though the POC allowed me to discover that my phone had been bypassing my local resolver because I
by Stephen304 8y ago
It seems to be the default for Unbound, at least on OPNSense. Though the POC allowed me to discover that my phone had been bypassing my local resolver because I tried to put 1.1.1.1 as a fallback in pihole as second option to my router, but for some reason pihole had been preferring CF over my local router.
Edit: To clarify, it seems that unbound by default blocks all RFC1918 addresses in DNS queries unless you specifically allow it for a specific domain (eg. plex.direct). OPNSense doesn't seem to expose an option to allow RFC1918 addresses in all dns responses.
- crtasm 8y agoPihole doesn't fallback, it spreads DNS requests between all the upstream servers you specify. Your router well may do the same.
- Stephen304 8y agoI have OPNSense configured not to forward queries so it uses root servers directly, but it's of no consequence because like I said above, Unbound on OPNSense blocks RFC1918 responses by default anyways. As long as my devices are using my router as a resolver, I'll only get public IPs as responses to DNS queries. My misconfiguration in pihole just temporarily bypassed that.