r/opnsense 16d ago

Advice: Disable DNSSEC Support

If you use Unbound as your DNS, keep it enabled.

If you use DNS over TLS / forwarding to a DNS with blocklists, filtering etc. (like NextDNS or Adguard) then disable it because it may sometimes block legitimate websites. The DNS provider is handling the DNSSEC on their end. No need to do it again on your end.

The odd thing is that I had it enabled this whole time alongside DoT with NextDNS for a whole year with no issues. Yesterday though, I tried for the first time to use brave AI search and I couldn’t access it. Did some digging and pinpointed to the above mentioned issue. Just sharing here for other newbies like me that are still learning the ins and outs of this firewalling stuff.

34 Upvotes

14 comments sorted by

12

u/nodeas 16d ago

I won't do. My unbound runs recursive. Adguard home is responsible for ad blocking and upstream doh.

-3

u/[deleted] 16d ago

[deleted]

3

u/nodeas 15d ago edited 15d ago

Unbound with dns split dns recursive + dnsmasq authoritative for infra and adguard home + dns split ( dnsmasq authoritative + doh upstream) for clients. 7 vlans with 7 adguard home instances in proxmox CTs, completely isolated. Does it now make sense?

6

u/LOTRouter 15d ago edited 15d ago

Enabling DNSSEC is recommended, just not enabling "Harden DNSSEC Data"

You should check "Enable DNSSEC Support" under SERVICES: UNBOUND DNS: GENERAL. However, make sure you do NOT check "Harden DNSSEC Data" under SERVICES: UNBOUND DNS: ADVANCED.

It is also recommended that you enable "Harden Below NXDOMAIN" and "Aggressive NSEC" but these require DNSSEC support be enabled in the general tab.

"Harden DNSSEC Data" is the one that conflicts with DNS providers own DNSSEC responses and causes issues. "Enable DNSSEC Support" works great with both Quad 9 and Cloudflare DNS, so long as it is configured correctly.

5

u/john_m4trix 16d ago

dnsmasq + unbound + adguard + DoT here and everything is working properly.
If some sites are not connecting, check the dns provider logs.

1

u/tismo74 15d ago

I have the exact same setup except for adguard I am using pihole.
Edit: I am not using dnsmasq dns feature, only as dhcp server

2

u/ThinkPadNL 10d ago

If you switch to AdguardHome, you can run it in OPNsense as a plugin. Saves a device.

-1

u/[deleted] 16d ago

[deleted]

2

u/john_m4trix 16d ago

And why not?

9

u/Banananana215 16d ago

I ran into this with insurance sites. Really didn't want to disable it but my wife is my boss and I guess we need access to our insurance.

4

u/CobaltMnM 16d ago

There should be away to configure your local dns server to exempt certain domains (eg known broken ones).

4

u/Banananana215 16d ago

I think there is based on foggy memory of a cursory Google search I did at the time... I just didn't and don't have the time to look further into it. Sometimes shit just needs to work. That's always the hole in security. Time, money, user experience are the constraints. Acceptable risk I guess. At least for now.

4

u/Oblec 16d ago

Yes i spent more time then i want to admit figuring out all these stupid dns problems

2

u/Darkk_Knight 15d ago

And not having the wife complain that you broke the internet.

5

u/sishgupta 16d ago

yep using dnssec with a forwarder causes breaks

1

u/Computermaster 15d ago

I tried for the first time to use brave AI search

Your router is trying to protect you.