Skip to content

pfSense and OPNsense

Both firewalls run Unbound as the LAN resolver. Point it at opdns as a forwarder over DNS-over-TLS: Unbound connects to the address and sends the host name as the TLS server name, which selects your profile.

You need: <resolver-ipv4> (and <resolver-ipv6> if the firewall has IPv6) from the Setup page, your profile id, and a device name such as firewall.

  1. Services → Unbound DNS → General: make sure Unbound is enabled.

  2. Services → Unbound DNS → DNS over TLS: add one entry per address:

    Field Value
    Server IP <resolver-ipv4>
    Server Port 853
    Verify CN <device>-<profile-id>.dns.opdns.net

    Repeat with <resolver-ipv6> if you use IPv6.

  3. Apply, then check it works.

  • Every LAN device appears under the firewall’s device name.
  • DNSSEC: opdns validates every answer it forwards. If the firewall’s Unbound validates too, a blocked name in a signed zone fails its check (a block answer carries no signatures), so clients see SERVFAIL instead of your block mode’s answer. The name is still blocked. To get the normal block answer, turn off DNSSEC validation on the firewall and rely on opdns’s.