Reply
Member
Posts: 128
Registered: ‎06-18-2013
Kudos: 96
Solutions: 2

Add support for Unbound

[ Edited ]

It would be quite nice to have the option of using unbound instead of dnsmasq. Dnsmasq is merely DNS forwarding, whereas unbound will do the actual resolution itself, complete with dnssec verification. This could prove to be extremely nice to have around.

Veteran Member
Posts: 5,061
Registered: ‎03-12-2011
Kudos: 2498
Solutions: 120

Re: Add support for Unbound

Indeed. I run unbound on my home EdgeRouter. Unfortunately the lack of an RTC makes DNSSEC validation after a cold boot difficult...

Highlighted
Member
Posts: 128
Registered: ‎06-18-2013
Kudos: 96
Solutions: 2

Re: Add support for Unbound

I've dealt with this before on the ERL, and indeed, lack of RTC is a pain, but it's possible to work around it by storing the time before shutdown, or by querying the IPs of the NTP servers without DNSSEC.

Member
Posts: 118
Registered: ‎03-24-2013
Kudos: 17
Solutions: 1

Re: Add support for Unbound

@zx2c4 @NVX do either of you have a write up you can share on how to install and configure unbound securely on an EdgeMax device? Maybe something that could be added to the wiki?

New Member
Posts: 32
Registered: ‎03-01-2015
Kudos: 8
Solutions: 2

Re: Add support for Unbound

dnsmasq +1 as a default forwarder. ipset support and domain hijacking is useful for developing and home use. 

 

DNSSEC is useless in China. 

Reply