Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server:
- #log-queries: yes
- #log-replies: yes
- #log-serviced-queries: yes
- #logfile: "/var/log/unbound.log"
- #verbosity: 1
- interface: 127.0.0.1
- interface: ::1
- port: 5335
- access-control: 127.0.0.1/32 allow
- access-control: ::1/128 allow
- access-control: ::0/0 refuse
- access-control: 0.0.0.0/0 refuse
- num-threads: 2
- rrset-cache-slabs: 2
- msg-cache-slabs: 2
- infra-cache-slabs: 2
- key-cache-slabs: 2
- do-ip4: yes
- do-ip6: yes
- prefer-ip6: no
- do-udp: yes
- do-tcp: yes
- hide-identity: yes
- hide-version: yes
- harden-glue: yes
- harden-dnssec-stripped: yes
- use-caps-for-id: yes
- harden-algo-downgrade: yes
- harden-below-nxdomain: yes
- harden-referral-path: no
- minimal-responses: yes
- qname-minimisation: yes
- qname-minimisation-strict: no
- fast-server-permil: 900
- fast-server-num: 3
- max-query-restarts: 11
- rrset-roundrobin: yes
- rrset-cache-size: 256m
- msg-cache-size: 128m
- key-cache-size: 34m
- cache-min-ttl: 300
- cache-max-ttl: 86400
- infra-cache-numhosts: 50000
- neg-cache-size: 4m
- serve-expired: yes
- serve-expired-ttl: 86400
- serve-expired-ttl-reset: yes
- serve-expired-reply-ttl: 30
- serve-expired-client-timeout: 1000
- prefetch: yes
- prefetch-key: yes
- edns-buffer-size: 1232
- max-udp-size: 1232
- so-rcvbuf: 8m
- so-sndbuf: 8m
- incoming-num-tcp: 100
- outgoing-num-tcp: 100
- so-reuseport: yes
- aggressive-nsec: yes
- ratelimit: 1000
- ip-ratelimit: 1000
- outgoing-range: 8192
- num-queries-per-thread: 4096
- jostle-timeout: 200
- infra-host-ttl: 600
- delay-close: 10000
- target-fetch-policy: "3 2 1 1 1"
- auto-trust-anchor-file: "/var/lib/unbound/root.key"
- trust-anchor-signaling: yes
- val-clean-additional: yes
- val-permissive-mode: no
- unwanted-reply-threshold: 10000
- root-hints: "/var/lib/unbound/root.hints"
- module-config: "validator cachedb iterator"
- private-address: 10.0.0.0/8
- private-address: 172.16.0.0/12
- private-address: 192.168.0.0/16
- private-address: 169.254.0.0/16
- private-address: fd00::/8
- private-address: fe80::/10
- cachedb:
- backend: "redis"
- redis-server-host: 127.0.0.1
- redis-server-port: 6379
- redis-logical-db: 0
- redis-expire-records: no
- remote-control:
- control-enable: yes
- control-interface: 127.0.0.1
- control-port: 8953
- server-key-file: "/etc/unbound/unbound_server.key"
- server-cert-file: "/etc/unbound/unbound_server.pem"
- control-key-file: "/etc/unbound/unbound_control.key"
- control-cert-file: "/etc/unbound/unbound_control.pem"
Advertisement
Add Comment
Please, Sign In to add comment