From 70ae6b36a5621c1031ff4a024b645271ab05f0ed Mon Sep 17 00:00:00 2001 From: Aminda Suomalainen Date: Wed, 31 Jul 2024 10:23:09 +0300 Subject: [PATCH] systemd-resolved & unbound: let's not pretend I am not using Quad9 ECS --- etc/systemd/resolved.conf.d/10-dot-quad9.conf | 10 +++--- etc/unbound/unbound.conf.d/dot-quad9.conf | 32 +++++++++---------- 2 files changed, 21 insertions(+), 21 deletions(-) diff --git a/etc/systemd/resolved.conf.d/10-dot-quad9.conf b/etc/systemd/resolved.conf.d/10-dot-quad9.conf index 12ab5073..15328640 100644 --- a/etc/systemd/resolved.conf.d/10-dot-quad9.conf +++ b/etc/systemd/resolved.conf.d/10-dot-quad9.conf @@ -3,14 +3,14 @@ # encryption, but host a Quad9 node and giving these addresses instead. [Resolve] # Secure -DNS=2620:fe::9#dns.quad9.net 2620:fe::fe#dns.quad9.net [2620:fe::9]:8853#dns.quad9.net [2620:fe::fe]:8853#dns.quad9.net -DNS=149.112.112.112#dns.quad9.net 9.9.9.9#dns.quad9.net 149.112.112.112:8853#dns.quad9.net 9.9.9.9:8853#dns.quad9.net +#DNS=2620:fe::9#dns.quad9.net 2620:fe::fe#dns.quad9.net [2620:fe::9]:8853#dns.quad9.net [2620:fe::fe]:8853#dns.quad9.net +#DNS=149.112.112.112#dns.quad9.net 9.9.9.9#dns.quad9.net 149.112.112.112:8853#dns.quad9.net 9.9.9.9:8853#dns.quad9.net # No Threat Blocking #DNS=2620:fe::10#dns10.quad9.net 2620:fe::fe:10#dns10.quad9.net [2620:fe::10]:8853#dns10.quad9.net [2620:fe::fe:10]:8853#dns10.quad9.net #DNS=149.112.112.10#dns10.quad9.net 9.9.9.10#dns10.quad9.net 149.112.112.10:8853#dns10.quad9.net 9.9.9.10:8853#dns10.quad9.net -# Secure + ECS -#DNS=2620:fe::11#dns11.quad9.net 2620:fe::fe:11#dns11.quad9.net [2620:fe::11]:8853#dns11.quad9.net [2620:fe::fe:11]:8853#dns11.quad9.net -#DNS=149.112.112.11#dns11.quad9.net 9.9.9.11#dns11.quad9.net 149.112.112.11:8853#dns11.quad9.net 9.9.9.11:8853#dns11.quad9.net +# Secure + ECS. IPv4 first so it gets preferred as my Unbound likely prefers IPv6 anyway. +DNS=149.112.112.11#dns11.quad9.net 9.9.9.11#dns11.quad9.net 149.112.112.11:8853#dns11.quad9.net 9.9.9.11:8853#dns11.quad9.net +DNS=2620:fe::11#dns11.quad9.net 2620:fe::fe:11#dns11.quad9.net [2620:fe::11]:8853#dns11.quad9.net [2620:fe::fe:11]:8853#dns11.quad9.net # No Threat Blocking + ECS #DNS=2620:fe::12#dns12.quad9.net 2620:fe::fe:12#dns12.quad9.net [2620:fe::12]:8853#dns12.quad9.net [2620:fe::fe:12]:8853#dns12.quad9.net #DNS=9.9.9.12#dns12.quad9.net 149.112.112.12#dns12.quad9.net 9.9.9.12:8853#dns12.quad9.net 149.112.112.12:8853#dns12.quad9.net diff --git a/etc/unbound/unbound.conf.d/dot-quad9.conf b/etc/unbound/unbound.conf.d/dot-quad9.conf index d15b6f4f..61c117b5 100644 --- a/etc/unbound/unbound.conf.d/dot-quad9.conf +++ b/etc/unbound/unbound.conf.d/dot-quad9.conf @@ -17,14 +17,14 @@ forward-zone: name: "." forward-tls-upstream: yes ## Secure - forward-addr: 2620:fe::fe@853#dns.quad9.net - forward-addr: 2620:fe::fe@8853#dns.quad9.net - forward-addr: 2620:fe::9@853#dns.quad9.net - forward-addr: 2620:fe::9@8853#dns.quad9.net - forward-addr: 9.9.9.9@853#dns.quad9.net - forward-addr: 9.9.9.9@8853#dns.quad9.net - forward-addr: 149.112.112.112@853#dns.quad9.net - forward-addr: 149.112.112.112@8853#dns.quad9.net + #forward-addr: 2620:fe::fe@853#dns.quad9.net + #forward-addr: 2620:fe::fe@8853#dns.quad9.net + #forward-addr: 2620:fe::9@853#dns.quad9.net + #forward-addr: 2620:fe::9@8853#dns.quad9.net + #forward-addr: 9.9.9.9@853#dns.quad9.net + #forward-addr: 9.9.9.9@8853#dns.quad9.net + #forward-addr: 149.112.112.112@853#dns.quad9.net + #forward-addr: 149.112.112.112@8853#dns.quad9.net ## No Threat Blocking #forward-addr: 2620:fe::fe:10@853#dns10.quad9.net #forward-addr: 2620:fe::fe:10@8853#dns10.quad9.net @@ -35,14 +35,14 @@ forward-zone: #forward-addr: 9.9.9.10@853#dns10.quad9.net #forward-addr: 9.9.9.10@8853#dns10.quad9.net ## Secure + ECS - #forward-addr: 2620:fe::fe:11@853#dns11.quad9.net - #forward-addr: 2620:fe::fe:11@8853#dns11.quad9.net - #forward-addr: 9.9.9.11@853#dns11.quad9.net - #forward-addr: 9.9.9.11@8853#dns11.quad9.net - #forward-addr: 2620:fe::11@853#dns11.quad9.net - #forward-addr: 2620:fe::11@8853#dns11.quad9.net - #forward-addr: 149.112.112.11@853#dns11.quad9.net - #forward-addr: 149.112.112.11@8853#dns11.quad9.net + forward-addr: 2620:fe::fe:11@853#dns11.quad9.net + forward-addr: 2620:fe::fe:11@8853#dns11.quad9.net + forward-addr: 9.9.9.11@853#dns11.quad9.net + forward-addr: 9.9.9.11@8853#dns11.quad9.net + forward-addr: 2620:fe::11@853#dns11.quad9.net + forward-addr: 2620:fe::11@8853#dns11.quad9.net + forward-addr: 149.112.112.11@853#dns11.quad9.net + forward-addr: 149.112.112.11@8853#dns11.quad9.net ## No Threat Blocking + ECS #forward-addr: 2620:fe::fe:12@853#dns12.quad9.net #forward-addr: 2620:fe::fe:12@8853#dns12.quad9.net