Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ##########################
- # Unbound Configuration
- ##########################
- ##
- # Server configuration
- ##
- server:
- chroot: /var/unbound
- username: "unbound"
- directory: "/var/unbound"
- pidfile: "/var/run/unbound.pid"
- use-syslog: yes
- port: 53
- verbosity: 3
- hide-identity: yes
- hide-version: yes
- harden-glue: yes
- do-ip4: yes
- do-ip6: yes
- do-udp: yes
- do-tcp: yes
- do-daemonize: yes
- module-config: "validator iterator"
- unwanted-reply-threshold: 0
- num-queries-per-thread: 512
- jostle-timeout: 200
- infra-host-ttl: 900
- infra-cache-numhosts: 5000
- outgoing-num-tcp: 10
- incoming-num-tcp: 10
- edns-buffer-size: 512
- cache-max-ttl: 86400
- cache-min-ttl: 0
- harden-dnssec-stripped: yes
- msg-cache-size: 4m
- rrset-cache-size: 8m
- num-threads: 2
- msg-cache-slabs: 2
- rrset-cache-slabs: 2
- infra-cache-slabs: 2
- key-cache-slabs: 2
- outgoing-range: 4096
- #so-rcvbuf: 4m
- auto-trust-anchor-file: /var/unbound/root.key
- prefetch: no
- prefetch-key: no
- use-caps-for-id: no
- serve-expired: no
- aggressive-nsec: no
- # Statistics
- # Unbound Statistics
- statistics-interval: 0
- extended-statistics: yes
- statistics-cumulative: yes
- # TLS Configuration
- tls-cert-bundle: "/etc/ssl/cert.pem"
- # Interface IP(s) to bind to
- interface-automatic: yes
- interface: 0.0.0.0
- interface: ::0
- # DNS Rebinding
- # Access lists
- include: /var/unbound/access_lists.conf
- # Static host entries
- include: /var/unbound/host_entries.conf
- # dhcp lease entries
- include: /var/unbound/dhcpleases_entries.conf
- # Domain overrides
- include: /var/unbound/domainoverrides.conf
- ###
- # Remote Control Config
- ###
- include: /var/unbound/remotecontrol.conf
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement