unbound: prefer IPv4 with private ECS using DoT servers

This commit is contained in:
Aminda Suomalainen 2024-05-07 08:26:20 +03:00
parent afb0801430
commit e4d691f2b1
Signed by: Mikaela
SSH Key Fingerprint: SHA256:CXLULpqNBdUKB6E6fLA1b/4SzG0HvKD19PbIePU175Q
5 changed files with 9 additions and 1 deletions

View File

@ -1,2 +1,3 @@
dot-nextdns.conf
dot-trex.conf dot-trex.conf
cache.conf cache.conf

View File

@ -8,6 +8,9 @@ server:
# Quad9 says pointless performance impact on forwarders. # Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization # https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no qname-minimisation: no
# Private ECS is more accurate with IPv4 than IPv6.
prefer-ip4: yes
prefer-ip6: no
forward-zone: forward-zone:
name: "." name: "."

View File

@ -8,6 +8,9 @@ server:
# Quad9 says pointless performance impact on forwarders. # Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization # https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no qname-minimisation: no
# Private ECS is more accurate with IPv4 than IPv6.
prefer-ip4: yes
prefer-ip6: no
forward-zone: forward-zone:
name: "." name: "."

View File

@ -0,0 +1 @@
dot-dns0.conf

View File

@ -1,7 +1,7 @@
server: server:
# Prefer IPv4 transport for sending DNS queries to internet nameservers. # Prefer IPv4 transport for sending DNS queries to internet nameservers.
# The only case where I can imagine this being useful is when using # The only case where I can imagine this being useful is when using
# upstream nameserver with ECS anonymization that has more accurate IPv4 # upstream nameserver with ECS privatization that has more accurate IPv4
# than IPv6 client-subnet. # than IPv6 client-subnet.
prefer-ip4: yes prefer-ip4: yes
prefer-ip6: no prefer-ip6: no