User Tools

Site Tools


infrastructure:opnsense-dns

# OPNsense DNS Architecture

Last updated: 2026-05-28 Status: Active

## Overview

Two DNS services run on OPNsense:

- Unbound — primary resolver on port 53, handles all external DNS with DNSSEC, DoT upstreams - dnsmasq — local DHCP and host resolution on port 5353, handles `kaburu.lan` records

Unbound forwards `kaburu.lan` queries to dnsmasq on 127.0.0.1:5353, so all devices get a single DNS server (OPNsense at 192.168.0.1) for both local and external resolution.

## Unbound Configuration

Setting Value
Port 53
Interface All (listens on all, outgoing locked to Mullvad)
DNSSEC Enabled
Outgoing interface Mullvad_VPN (opt5)
regdhcp Enabled
regdhcpstatic Enabled
regdhcpdomain kaburu.lan

### Upstream Resolvers (DoT) — Active

UUID Name Server Port Verify
48000e06 Mullvad DNS TLS 1 193.138.218.74 853 adblock.dns.mullvad.net
09060f42 Mullvad DNS TLS 2 194.242.2.2 853 adblock.dns.mullvad.net

### Upstream Resolvers — Disabled

UUID Name Server Reason
d53fa713 Cloudflare DoT 1.1.1.1 DNS leak — Cloudflare IPs appeared on mullvad.net/check
8da39e2d Quad9 DoT 9.9.9.9 DNS leak
76093144 Cloudflare Forward 1.1.1.1 DNS leak
08dd7e77 Quad9 Forward 9.9.9.9 DNS leak

### Query Forwarding

Domain Server Port
kaburu.lan 127.0.0.1 5353

## dnsmasq Configuration

Setting Value
DNS port 5353 (not on port 53)
Interface LAN
Domain kaburu.lan
regdhcp Enabled
regdhcpstatic Enabled
DNSSEC Disabled (Unbound handles this)
no_resolv Enabled (does not use upstream resolvers)

## Local Domain

All local hosts resolve under `kaburu.lan` — e.g. `kaburuaibox.kaburu.lan`

Host records are managed in dnsmasq under Services → Dnsmasq DNS → Hosts.

## Key Host Records

Hostname IP Description
kaburuaibox 192.168.0.253 HP Z840 AI Server
TrueNAS 192.168.0.251 TrueNAS MicroServer Gen8
TrueNAS-1gb-1 192.168.0.200 TrueNAS port 1
TrueNAS-1gb-2 192.168.0.201 TrueNAS port 2
KABURU-UM790-MAIN 192.168.0.143 UM790 Pro mini PC
KaburuLINK 192.168.0.250 Unraid box
homeassistant 192.168.0.123 Home Assistant
ILOCZ162000TP 192.168.0.155 HP Z840 iLO4 port
keeplink-sw 192.168.0.10 KeepLink KP-9000 switch
eap653-01 192.168.0.101 TP-Link EAP653 AP1
eap653-02 192.168.0.100 TP-Link EAP653 AP2
eap110-outdoor 192.168.0.102 TP-Link EAP110 Outdoor AP

## VLANs

VLAN Interface DHCP Range Domain
LAN lan 192.168.0.51–250 kaburu.lan
CamerasVLAN opt7 192.168.20.10–100 kaburu.lan
IOTVlan opt8 192.168.30.10–100 kaburu.lan

## Change Log

### 2026-05-28 — DNS Leak Fix

Problem: mullvad.net/check showed DNS requests leaking via Cloudflare (172.70.88.163, 172.70.88.164 and IPv6 equivalents) despite VPN being active.

Root cause: Cloudflare and Quad9 DoT/Forward entries were enabled in Unbound. Even with outgoing_interface set to Mullvad (opt5), these upstream resolvers were resolving outside the VPN tunnel and their IPs appeared in DNS leak tests.

Fix: - Disabled all 4 Cloudflare/Quad9 DoT and Forward entries in Unbound - Enabled both Mullvad DoT entries (193.138.218.74 and 194.242.2.2, both verify adblock.dns.mullvad.net) - Config edited directly via SSH: `perl -i -0pe` on `/conf/config.xml` - Unbound reconfigured via API - Pre-change backup saved to `/conf/config.xml.bak-20260528-prednsfix` on OPNsense

### 2026-05-17 — DNS Architecture Refactor

- Unbound bound to LAN interface only (was listening on all interfaces) - regdhcp and regdhcpstatic enabled on Unbound - dnsmasq moved from port 53 to port 5353 - Unbound query forward added for kaburu.lan → 127.0.0.1:5353 - This resolves the issue where dnsmasq host records were not visible to Unbound

### 2026-05-28 — DoH Browser Leak Fix

Problem: After fixing Unbound upstreams, mullvad.net/check still showed Cloudflare IPs (172.69.193.x) leaking. These are Cloudflare's DNS-over-HTTPS resolver IPs, not plain DNS. The browser (Brave) was bypassing OPNsense entirely and sending DoH queries directly to Cloudflare port 443 over the VPN.

Root cause: Brave and other modern browsers have built-in encrypted DNS (DoH) configured to Cloudflare/Google by default. This traffic goes to port 443 so it's indistinguishable from HTTPS — it bypasses any DNS server the OS/router sets.

Fix — two firewall rules added to LAN (top of ruleset, quick):

UUID Rule Interface Proto Destination Port Action
b1000001 Block DoH providers LAN tcp/udp DoH_Block alias 443 block
b1000002 Block rogue plain DNS LAN tcp/udp !192.168.0.1 53 block

DoH_Block alias (uuid: a1b2c3d4-0000-0000-0000-doh000000001): - 1.1.1.1, 1.0.0.1 (Cloudflare) - 8.8.8.8, 8.8.4.4 (Google) - 9.9.9.9, 149.112.112.112 (Quad9) - 208.67.222.222, 208.67.220.220 (OpenDNS) - 94.140.14.14, 94.140.15.15 (AdGuard)

Result: All three green on mullvad.net/check — Using Mullvad VPN / No DNS leaks / No WebRTC leaks. Confirmed 2026-05-28.

Also: Brave “Use secure DNS” setting disabled in browser settings (Settings → Privacy → Security → Use secure DNS → off). Belt and braces — the firewall block rules handle any device that has it on, but disabling in-browser is cleaner where possible.

Note: The plain-DNS redirect rule (rule b1000002) also prevents any device from using a hardcoded DNS server (e.g. 8.8.8.8 in network settings).

infrastructure/opnsense-dns.txt · Last modified: (external edit)

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki