Both firewalls run Unbound as the LAN resolver. Point it at opdns as a
forwarder over DNS-over-TLS: Unbound connects to the address and sends the
host name as the TLS server name, which selects your profile.
You need:<resolver-ipv4> (and <resolver-ipv6> if the firewall has
IPv6) from the Setup page, your profile id, and a device name such as
firewall.
System → General Setup → DNS Server Settings: add <resolver-ipv4>
with DNS Hostname<device>-<profile-id>.dns.opdns.net. Repeat for
<resolver-ipv6>. Untick DNS Server Override so the ISP’s servers are
not added.
Services → DNS Resolver → General Settings: tick Enable
Forwarding Mode and Use SSL/TLS for outgoing DNS Queries to
Forwarding Servers.
Screenshot to comepfSense DNS Resolver general settings with forwarding mode and SSL/TLS for outgoing queries enabled.pfSense CE 2.7
Every LAN device appears under the firewall’s device name.
DNSSEC: opdns validates every answer it forwards. If the firewall’s
Unbound validates too, a blocked name in a signed zone fails its check
(a block answer carries no signatures), so clients see SERVFAIL instead
of your block mode’s answer. The name is still blocked. To get the normal
block answer, turn off DNSSEC validation on the firewall and rely on
opdns’s.