unbound.conf 1.3 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556
  1. server:
  2. tls-cert-bundle: /usr/local/share/certs/ca-root-nss.crt
  3. verbosity: 1
  4. num-threads: 4
  5. interface: 0.0.0.0
  6. access-control: 192.168.40.0/24 allow
  7. cache-max-ttl: 14400
  8. cache-min-ttl: 900
  9. do-tcp: yes
  10. hide-identity: yes
  11. hide-version: yes
  12. minimal-responses: yes
  13. root-hints: "/usr/local/etc/unbound/root.hints"
  14. logfile: "unbound.log"
  15. log-queries: yes
  16. log-replies: yes
  17. log-tag-queryreply: yes
  18. prefetch: yes
  19. prefetch-key: yes
  20. unblock-lan-zones: yes
  21. insecure-lan-zones: yes
  22. auto-trust-anchor-file: /usr/local/etc/unbound/root.key
  23. include: /var/unbound/service.zones
  24. include: /var/unbound/unblink.zones
  25. #include: /var/unbound/local-void.zones
  26. remote-control:
  27. control-enable: yes
  28. control-interface: 0.0.0.0
  29. control-port: 8953
  30. control-use-cert: no
  31. forward-zone:
  32. name: "."
  33. forward-tls-upstream: yes
  34. # Cloudflare DNS
  35. forward-addr: 2606:4700:4700::1111@853#cloudflare-dns.com
  36. forward-addr: 1.1.1.1@853#cloudflare-dns.com
  37. forward-addr: 2606:4700:4700::1001@853#cloudflare-dns.com
  38. forward-addr: 1.0.0.1@853#cloudflare-dns.com
  39. # Quad9
  40. forward-addr: 2620:fe::fe@853#dns.quad9.net
  41. forward-addr: 9.9.9.9@853#dns.quad9.net
  42. forward-addr: 2620:fe::9@853#dns.quad9.net
  43. forward-addr: 149.112.112.112@853#dns.quad9.net
  44. forward-ssl-upstream: yes