Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unbound: Do not add forwarding domains to private-domains #8223

Open
2 tasks done
Patrick-Remy opened this issue Jan 17, 2025 · 0 comments
Open
2 tasks done

Unbound: Do not add forwarding domains to private-domains #8223

Patrick-Remy opened this issue Jan 17, 2025 · 0 comments

Comments

@Patrick-Remy
Copy link

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Is your feature request related to a problem? Please describe.

We are using the Unbound service and are forwarding an Active Directory dns zone to the designated samba dns server. Additionally we want to use the Rebind Protection feature of Unbound in Opnsense, to filter a private subnet out of the returned addresses.

Unfortunately all forwarding rules create an entry for private-domain (see:

{% for forward in helpers.toList('OPNsense.unboundplus.dots.dot') %}
)

Describe the solution you like

I would like a checkbox in the /ui/unbound/forward > Edit rule dialog, which can be defaultly enabled (for backwards compatibility), to enable

Describe alternatives you considered

  1. I tried to override the private-address option with a custom config file, but seems not to be possible, as unbound is merging entries
  2. Current workaround is to disable the unbound forward rules inside the UI, and add a custom config file at /usr/local/etc/unbound.opnsense.d/forward.conf containing only the forward rules. Then the generated private_domains.conf file does not include any private-domain entry.

Additional context

I am not sure what the original reason is/was to always add forwarding domains to private-domains. So maybe the default can be discussed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant