2023-02-22 09:58:04 +01:00
|
|
|
server:
|
|
|
|
# Debian ca-certificates location
|
2024-04-17 15:01:38 +02:00
|
|
|
#tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
|
2024-05-14 14:07:11 +02:00
|
|
|
# Fedora
|
2023-02-22 09:58:04 +01:00
|
|
|
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
|
2024-04-17 15:01:38 +02:00
|
|
|
# Use system certificates no matter where they are
|
|
|
|
tls-system-cert: yes
|
|
|
|
# Quad9 says pointless performance impact on forwarders.
|
|
|
|
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
|
|
|
|
qname-minimisation: no
|
2024-05-07 07:26:20 +02:00
|
|
|
# Private ECS is more accurate with IPv4 than IPv6.
|
|
|
|
prefer-ip4: yes
|
|
|
|
prefer-ip6: no
|
2023-02-22 09:58:04 +01:00
|
|
|
|
|
|
|
forward-zone:
|
|
|
|
name: "."
|
|
|
|
forward-tls-upstream: yes
|
2023-12-30 14:46:22 +01:00
|
|
|
# Default
|
2023-02-22 09:58:04 +01:00
|
|
|
forward-addr: 2a0f:fc80::@853#dns0.eu
|
|
|
|
forward-addr: 193.110.81.0@853#dns0.eu
|
|
|
|
forward-addr: 2a0f:fc81::@853#dns0.eu
|
|
|
|
forward-addr: 185.253.5.0@853#dns0.eu
|
2023-12-30 14:46:22 +01:00
|
|
|
# # Unfiltered
|
|
|
|
# forward-addr: 193.110.81.254@853#open.dns0.eu
|
|
|
|
# forward-addr: 185.253.5.254@853#open.dns0.eu
|
|
|
|
# forward-addr: 2a0f:fc80::ffff@853#open.dns0.eu
|
|
|
|
# forward-addr: 2a0f:fc81::ffff@853#open.dns0.eu
|
|
|
|
# # Heavier filtering
|
|
|
|
# forward-addr: 2a0f:fc80::9@853#zero.dns0.eu
|
|
|
|
# forward-addr: 193.110.81.9@853#zero.dns0.eu
|
|
|
|
# forward-addr: 2a0f:fc81::9@853#zero.dns0.eu
|
|
|
|
# forward-addr: 185.253.5.9@853#zero.dns0.eu
|
2024-04-19 08:14:32 +02:00
|
|
|
|
|
|
|
# vim: filetype=unbound.conf
|