unbound and packet filter

Gerben Wierda gerben.wierda at rna.nl
Sun Jan 26 14:57:33 UTC 2020

Slightly OT. Apologies.

I have started tightening the packet filter screws on a server. This server runs an unbound resolver (two actually, one that does forwarding to quad9 and one that doesn’t do forwarding for rspamd).

In the pf logs, I notice the following logs about blocked packets: 64101 29989 53 40022

That is either unbound forwarding or the server itself asking the resolver directly (which is possible as it is set as a fallback in case unbound has died).

If either unbound or another resolver (say mDNS) forwards to, how do I set the packet filter to accept this traffic?


