Unbound – OpenWRT

Written by

in

LuCI Web Interface.

PackageVersionPackageVersion
unbound-anchor1.21.0-r1libunbound1.21.0-r1
unbound-checkconf1.21.0-r1luci-app-unbound25.250.61039~923f8d9
unbound-control1.21.0-r1asterisk-res-resolver-unbound20.8.1-r1
unbound-control-setup1.21.0-r1freeradius3-mod-unbound3.2.5-r3
unbound-daemon1.21.0-r1unbound-host1.21.0-r1

Services -> Recursive DNS -> Basic

Configure Unbound (Services → Recursive DNS)

  1. Navigate to Services → Recursive DNS (or Services → Unbound DNS).
  2. Click on the Basic Settings tab:
    • Enabled: Check [x]
    • Listen Port: Set to 5533
    • DHCP Link: Select dnsmasq
    • Local Domain Type: Static (local only)
    • LAN DNS: Hostname, Primary Address
    • WAN DNS: Use Upstream
    • Extra DNS: Host Records
  3. Click Save & Apply at the bottom right.

Route Dnsmasq to Unbound (Network → DHCP and DNS)

  1. Navigate to Network → DHCP and DNS.
  2. General Settings tab:
    • DNS Forwardings: Add 127.0.0.1#5533 (click the + button to save it).
  3. Advanced Settings tab:
    • DNS server port: Ensure this is set to 53 (or left blank, which defaults to 53).
    • Ignore resolve file: Check [x] (This prevents Dnsmasq from using WAN/ISP DNS servers).
  4. Click Save & Apply.

Prevent ISP DNS Leaks (Network → Interfaces)

  1. Navigate to Network → Interfaces.
  2. Click Edit next to your WAN interface.
  3. Select the Advanced Settings tab inside the interface editor.
  4. Use DNS servers advertised by peer: Uncheck [ ].
  5. Ensure the Custom DNS servers field is completely empty.
  6. Click Save, then click Save & Apply.
  7. (Repeat Step 3 for the WAN6 interface if enabled).

Comments

Leave a Reply