Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server:
- interface: 127.0.0.1
- port: 5335
- access-control: 127.0.0.0/8 allow
- access-control: 100.*.*.*/32 allow #This is for tailscale but it isnt working
- # IPv4 / IPv6-settings
- do-ip6: yes
- do-ip4: yes
- do-udp: yes
- do-tcp: yes
- # Set number of threads to use
- num-threads: 2
- # Hide DNS Server info
- hide-identity: yes
- hide-version: yes
- # Limit DNS Fraud and use DNSSEC
- harden-glue: yes
- harden-dnssec-stripped: yes
- harden-referral-path: yes
- use-caps-for-id: yes
- harden-algo-downgrade: yes
- qname-minimisation: yes
- trust-anchor-file: "/usr/share/dns/root.key"
- # Add an unwanted reply threshold to clean the cache and avoid when possible a DNS Poisoning
- unwanted-reply-threshold: 10000000
- # Minimum lifetime of cache entries in seconds
- cache-min-ttl: 300
- # Maximum lifetime of cached entries
- cache-max-ttl: 28800
- # Prefetch
- prefetch: yes
- prefetch-key: yes
- # Optimisations
- msg-cache-slabs: 4
- rrset-cache-slabs: 4
- infra-cache-slabs: 4
- key-cache-slabs: 4
- serve-expired: yes
- serve-expired-ttl: 900
- # Increase memory size of the cache
- rrset-cache-size: 256m
- msg-cache-size: 128m
- # Increase buffer size so that no messages are lost in traffic spikes
- so-rcvbuf: 1m
- # Private addresses
- private-address: 192.168.0.0/16
- private-address: 169.254.0.0/16
- private-address: 172.16.0.0/12
- private-address: 10.0.0.0/8
- private-address: fd00::/8
- private-address: fe80::/10
Advertisement
Add Comment
Please, Sign In to add comment