custom.conf 1.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445
  1. server:
  2. module-config: "validator iterator"
  3. #module-config: "dns64 validator iterator"
  4. #dns64-prefix: 64:ff9b::/96
  5. interface: 0.0.0.0
  6. interface: ::0
  7. interface-automatic: yes
  8. access-control: 0.0.0.0/0 allow
  9. access-control: ::0/0 allow
  10. # Daemon manages keeping this file up to date
  11. root-hints: "/etc/unbound/root.hints"
  12. do-udp: yes
  13. #logfile: /var/log/unbound.log
  14. #log-queries: yes
  15. #log-servfail: yes
  16. #example to allow private records to come from public sources
  17. #private-domain: "plex.direct"
  18. # Forward netflix to a local bind instance that doesn't return AAAA records (for tunnelbroker)
  19. #forward-zone:
  20. #name: "netflix.com"
  21. #forward-addr: 127.0.0.1@10053
  22. # Forward AD domain to DCs
  23. #forward-zone:
  24. # name: "ad.domain.com"
  25. # forward-addr: 10.10.8.2
  26. # forward-addr: 10.10.8.3
  27. # Needed for DNS-over-TLS, path may be different for non-Debian
  28. server:
  29. tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
  30. # Forward all requests to CloudFlare DoT. Commenting all this out forces local resolving with root.hints
  31. forward-zone:
  32. name: "."
  33. forward-ssl-upstream: yes
  34. forward-addr: 1.1.1.1@853#cloudflare-dns.com
  35. forward-addr: 1.0.0.1@853#cloudflare-dns.com
  36. #forward-addr: 2606:4700:4700::1001@853#cloudflare-dns.com
  37. #forward-addr: 2606:4700:4700::1111@853#cloudflare-dns.com