Any benefit to using Unbound DNS with NextDNS already setup on your endpoints?

Comments

3 comments

  • Avatar
    Firewalla

    Unbound is there to replace DNS servers. See this article for details https://help.firewalla.com/hc/en-us/articles/4570608120979-Firewalla-DNS-Services-Introduction

     

    0
    Comment actions Permalink
  • Avatar
    D

    OK, its starting to become clearer.....

    So the unbound is totally separate method of dns resolution and does not work in conjunction and its benefit is that its local to the firewalla, when it forwards it uses multiple upstream revolvers so your requests are spread all over the place as opposed to being centralized.

    I'm wondering if unbound feature is still sending those in queries clear text.....is that better or worse than using a service like nextdns and using an encrypted query over https or tls? Seems to me that the encrypted method would be preferred if available, then unbound? What is firewalla stance?

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    @D If you use Unbound, it is going to ask Authoritative (root) nameservers for anything it doesn't already know and they do not support encryption as far as I know. The idea of unbound is not having any upstream DNS resolver between unbound and authoritative nameservers. 

    0
    Comment actions Permalink

Please sign in to leave a comment.