aports/software-configs/unbound-redxen-config/base.conf

39 lines
1002 B
Plaintext

server:
access-control: 0.0.0.0/0 refuse_non_local
access-control: ::/0 refuse_non_local
# Local Host
access-control: 127.0.0.0/8 allow
#log-replies: yes
interface: 0.0.0.0
interface: ::0
extended-statistics: yes
rrset-roundrobin: yes
root-hints: /usr/share/dns-root-hints/named.root
trust-anchor-file: /usr/share/dnssec-root/trusted-key.key
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
port: 53
prefetch: yes
prefetch-key: yes
do-daemonize: yes
pidfile: "/run/unbound.pid"
minimal-responses: no
logfile: ""
cache-min-ttl: 60
harden-glue: yes
aggressive-nsec: yes
serve-expired: yes
serve-expired-ttl: 86400
serve-expired-ttl-reset: yes
remote-control:
control-enable: yes
control-use-cert: no
control-interface: 127.0.0.1
forward-zone:
name: "."
forward-tls-upstream: yes
forward-addr: 2620:fe::fe@853#dns.quad9.net
forward-addr: 9.9.9.9@853#dns.quad9.net
forward-addr: 2606:4700:4700::1111@853#cloudflare-dns.com
forward-addr: 1.1.1.1@853#cloudflare-dns.com