Skip to content

Instantly share code, notes, and snippets.

@LucasPlacentino
Created July 29, 2022 10:03
Show Gist options
  • Save LucasPlacentino/259277c31b62147704581c41f051b52a to your computer and use it in GitHub Desktop.
Save LucasPlacentino/259277c31b62147704581c41f051b52a to your computer and use it in GitHub Desktop.
wirehole unbound.conf
server:
cache-max-ttl: 86400
cache-min-ttl: 60
directory: "/opt/unbound/etc/unbound"
edns-buffer-size: 1472
interface: 0.0.0.0@53
rrset-roundrobin: yes
username: "_unbound"
log-local-actions: no
log-queries: no
log-replies: no
log-servfail: no
logfile: /dev/null
verbosity: 0
aggressive-nsec: yes
delay-close: 10000
do-daemonize: no
do-not-query-localhost: no
neg-cache-size: 4M
qname-minimisation: yes
access-control: 127.0.0.1/32 allow
access-control: 192.168.0.0/16 allow
access-control: 172.16.0.0/12 allow
access-control: 10.0.0.0/8 allow
auto-trust-anchor-file: "var/root.key"
chroot: "/opt/unbound/etc/unbound"
harden-algo-downgrade: yes
harden-below-nxdomain: yes
harden-dnssec-stripped: yes
harden-glue: yes
harden-large-queries: yes
harden-referral-path: no
harden-short-bufsize: yes
hide-identity: yes
hide-version: yes
identity: "DNS"
private-address: 10.0.0.0/8
private-address: 172.16.0.0/12
private-address: 192.168.0.0/16
private-address: 169.254.0.0/16
private-address: fd00::/8
private-address: fe80::/10
private-address: ::ffff:0:0/96
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
unwanted-reply-threshold: 10000000
val-clean-additional: yes
msg-cache-size: 260991658
num-queries-per-thread: 4096
outgoing-range: 8192
rrset-cache-size: 260991658
minimal-responses: yes
prefetch: yes
prefetch-key: yes
serve-expired: yes
so-reuseport: yes
so-rcvbuf: 1m
remote-control:
control-enable: no
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment