Project

General

Profile

Actions

Bug #9189

closed

Broken host overrides in DNS resolver (sometimes)

Added by Taras Savchuk over 5 years ago. Updated over 4 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
DNS Resolver
Target version:
-
Start date:
12/10/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.4.4
Affected Architecture:
All

Description

Expected behavior:
If we have host override in pfSense "DNS resolver", pfSense should never ever return public IP for overriden host.

Actual behavior:
Sometimes pfSense returns external IP of overriden host in additional section of reply to MX-type query (i.e. Unbound do not respect own host overrides when inserts additional info in replies). May be it's Unbound's bug.

How to solve:
Add "minimal-responses: yes" to default Unbound config and prevent Unbount from returning additional info in replies.

Details:
https://forum.netgate.com/topic/107354/dns-resolver-host-overrides-don-t-work-sometimes

Actions

Also available in: Atom PDF