2 # Unbound configuration file for IPFire
4 # The full documentation is available at:
5 # https://www.unbound.net/documentation/unbound.conf.html
9 # Common Server Options
11 directory: "/etc/unbound"
19 do-not-query-localhost: yes
22 include: "/etc/unbound/tuning.conf"
31 statistics-interval: 86400
32 statistics-cumulative: yes
33 extended-statistics: yes
39 # Randomise any cached responses
45 qname-minimisation: yes
46 minimal-responses: yes
49 auto-trust-anchor-file: "/var/lib/unbound/root.key"
50 val-permissive-mode: no
51 val-clean-additional: yes
56 harden-short-bufsize: no
57 harden-large-queries: yes
58 harden-dnssec-stripped: yes
59 harden-below-nxdomain: yes
60 harden-referral-path: yes
61 harden-algo-downgrade: no
66 tls-cert-bundle: /etc/ssl/certs/ca-bundle.crt
68 # EDNS Buffer Size (#12240)
69 edns-buffer-size: 1232
71 # Harden against DNS cache poisoning
72 unwanted-reply-threshold: 1000000
74 # Listen on all interfaces
75 interface-automatic: yes
78 # Allow access from everywhere
79 access-control: 0.0.0.0/0 allow
81 # Bootstrap root servers
82 root-hints: "/etc/unbound/root.hints"
85 include: "/etc/unbound/dhcp-leases.conf"
87 # Include any forward zones
88 include: "/etc/unbound/forward.conf"
90 # Include safe search settings
91 include: "/etc/unbound/safe-search.conf"
96 control-interface: 127.0.0.1
98 # Import any local configurations
99 include: "/etc/unbound/local.d/*.conf"