different DNS servers for different gateways

Howard Spindel howard at sci1.com
Fri Mar 29 21:22:06 UTC 2024


I have unbound configured under pfSense+ on a Netgate 8200.  I also have 
a Wireguard VPN configured under pfSense.

I have DNS forwarding configured under pfSense/DNS Resolver/General 
Settings.  That caused unbound to forward to the two DNS server 
configured under pfSense General Setup.  The two DNS servers I have 
configured there are 10.255.255.2 (the DNS server recommended by my VPN 
provider) and 9.9.9.9 (Quad 9 public server).

What I want is that when the VPN is up for unbound to forward solely to 
10.255.255.2 and for unbound to fall back to using 9.9.9.9 only when the 
VPN is down.

What happens now, is that unbound is free to choose either DNS server, 
and therefore sometimes chooses 9.9.9.9 when the VPN is up. When the VPN 
is down now, I presume that unbound still tries to forward to 
10.255.255.2 but since that is not a routable address when the VPN is 
down the lookup will fail and unbound will use 9.9.9.9 instead.

Is there a way to tell unbound to use 10.255.255.2 if and only if the 
VPN is up?  I can't find it.

Thank you.

Howard





More information about the Unbound-users mailing list