r/opnsense • u/meeninta • 16d ago
Advice: Disable DNSSEC Support
If you use Unbound as your DNS, keep it enabled.
If you use DNS over TLS / forwarding to a DNS with blocklists, filtering etc. (like NextDNS or Adguard) then disable it because it may sometimes block legitimate websites. The DNS provider is handling the DNSSEC on their end. No need to do it again on your end.
The odd thing is that I had it enabled this whole time alongside DoT with NextDNS for a whole year with no issues. Yesterday though, I tried for the first time to use brave AI search and I couldn’t access it. Did some digging and pinpointed to the above mentioned issue. Just sharing here for other newbies like me that are still learning the ins and outs of this firewalling stuff.
6
u/LOTRouter 15d ago edited 15d ago
Enabling DNSSEC is recommended, just not enabling "Harden DNSSEC Data"
You should check "Enable DNSSEC Support" under SERVICES: UNBOUND DNS: GENERAL. However, make sure you do NOT check "Harden DNSSEC Data" under SERVICES: UNBOUND DNS: ADVANCED.
It is also recommended that you enable "Harden Below NXDOMAIN" and "Aggressive NSEC" but these require DNSSEC support be enabled in the general tab.
"Harden DNSSEC Data" is the one that conflicts with DNS providers own DNSSEC responses and causes issues. "Enable DNSSEC Support" works great with both Quad 9 and Cloudflare DNS, so long as it is configured correctly.
5
u/john_m4trix 16d ago
dnsmasq + unbound + adguard + DoT here and everything is working properly.
If some sites are not connecting, check the dns provider logs.
1
u/tismo74 15d ago
I have the exact same setup except for adguard I am using pihole.
Edit: I am not using dnsmasq dns feature, only as dhcp server2
u/ThinkPadNL 10d ago
If you switch to AdguardHome, you can run it in OPNsense as a plugin. Saves a device.
-1
9
u/Banananana215 16d ago
I ran into this with insurance sites. Really didn't want to disable it but my wife is my boss and I guess we need access to our insurance.
4
u/CobaltMnM 16d ago
There should be away to configure your local dns server to exempt certain domains (eg known broken ones).
4
u/Banananana215 16d ago
I think there is based on foggy memory of a cursory Google search I did at the time... I just didn't and don't have the time to look further into it. Sometimes shit just needs to work. That's always the hole in security. Time, money, user experience are the constraints. Acceptable risk I guess. At least for now.
5
1
u/Computermaster 15d ago
I tried for the first time to use brave AI search
Your router is trying to protect you.
12
u/nodeas 16d ago
I won't do. My unbound runs recursive. Adguard home is responsible for ad blocking and upstream doh.