Zum Hauptinhalt springen
Unix & Linux ServerDistribution Release: Qubes OS 4.3.2(03.10.2026 um 00:03 Uhr)
•
Linux Tipps & HardeningSecurity: Mehrere Probleme in redis (Debian)(03.10.2026 um 01:01 Uhr)
•
Sichere ProgrammierungCopilot code review: API support and new default effort level(02.10.2026 um 21:13 Uhr)
•
Sichere ProgrammierungStateless GitHub App installation tokens rolled out(03.10.2026 um 00:18 Uhr)
•
Sichere ProgrammierungWe Tried ISO-AdamW. AdamW Kept Its Job.(03.10.2026 um 00:08 Uhr)
•
Sichere ProgrammierungClaim Ledger gives a project review a paper trail(03.10.2026 um 00:10 Uhr)
••
Sichere ProgrammierungWhat getting into thirteen database projects' docs actually took(03.10.2026 um 00:11 Uhr)
•
Sichere ProgrammierungYour security gate always passes. Can it actually block a release?(03.10.2026 um 00:11 Uhr)
•
Sichere Programmierung🚀 Starting my Hacktoberfest journey!(03.10.2026 um 00:12 Uhr)
•
Unix & Linux ServerDistribution Release: Qubes OS 4.3.2(03.10.2026 um 00:03 Uhr)
•
Linux Tipps & HardeningSecurity: Mehrere Probleme in redis (Debian)(03.10.2026 um 01:01 Uhr)
•
Sichere ProgrammierungCopilot code review: API support and new default effort level(02.10.2026 um 21:13 Uhr)
•
Sichere ProgrammierungStateless GitHub App installation tokens rolled out(03.10.2026 um 00:18 Uhr)
•
Sichere ProgrammierungWe Tried ISO-AdamW. AdamW Kept Its Job.(03.10.2026 um 00:08 Uhr)
•
Sichere ProgrammierungClaim Ledger gives a project review a paper trail(03.10.2026 um 00:10 Uhr)
••
Sichere ProgrammierungWhat getting into thirteen database projects' docs actually took(03.10.2026 um 00:11 Uhr)
•
Sichere ProgrammierungYour security gate always passes. Can it actually block a release?(03.10.2026 um 00:11 Uhr)
•
Sichere Programmierung🚀 Starting my Hacktoberfest journey!(03.10.2026 um 00:12 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Deploying Unbound Validating DNS Resolver on Ubuntu 24.04

Unbound is a validating, recursive, and caching DNS resolver that performs DNSSEC validation locally and answers queries without relying on third-party…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Unbound is a validating, recursive, and caching DNS resolver that performs DNSSEC validation locally and answers queries without relying on third-party resolvers. This guide deploys Unbound using Docker Compose after freeing the system's port 53, with access controls that restrict who can query the resolver. By the end, you'll have a validating DNS resolver answering queries from approved clients on your server.









Free Port 53



Ubuntu's systemd-resolved binds port 53 by default. Release it before deploying.



1. Stop and disable systemd-resolved:




$ sudo systemctl stop systemd-resolved
$ sudo systemctl disable systemd-resolved






2. Replace the resolver configuration:




$ sudo rm /etc/resolv.conf
$ echo "nameserver 1.1.1.1" | sudo tee /etc/resolv.conf












Set Up the Directory Structure and Configuration



1. Create the project directory:




$ mkdir -p ~/unbound
$ cd ~/unbound






2. Create the Unbound configuration file:




$ nano unbound.conf









server:
interface: 0.0.0.0
interface: ::0
port: 53

access-control: 127.0.0.0/8 allow
access-control: 192.168.0.0/16 allow
access-control: 172.16.0.0/12 allow
access-control: 10.0.0.0/8 allow
access-control: YOUR_CLIENT_IP/32 allow
access-control: 0.0.0.0/0 refuse

hide-identity: yes
hide-version: yes
use-caps-for-id: yes
prefetch: yes

num-threads: 2
msg-cache-slabs: 4
rrset-cache-slabs: 4
infra-cache-slabs: 4
key-cache-slabs: 4
rrset-cache-size: 100m
msg-cache-size: 50m
so-rcvbuf: 1m

remote-control:
control-enable: no






Replace YOUR_CLIENT_IP/32 with the IP allowed to query the resolver.









Deploy with Docker Compose



1. Create the Docker Compose manifest:




$ nano docker-compose.yml









services:
unbound:
image: mvance/unbound:latest
container_name: unbound
restart: unless-stopped
environment:
TZ: UTC
ports:
- "53:53/tcp"
- "53:53/udp"
volumes:
- ./unbound.conf:/opt/unbound/etc/unbound/unbound.conf:ro






2. Start the service:




$ docker compose up -d






3. Verify the service is running:




$ docker compose ps












Test Resolution



From an allowed client, query the resolver:




$ dig @SERVER_IP vultr.com






A valid answer section confirms Unbound is resolving queries.









Next Steps



Unbound is running with DNSSEC validation and tight access controls. From here you can:




  • Point your network's clients at the resolver to gain DNSSEC validation

  • Tune cache sizes and thread counts for your traffic volume

  • Layer block lists into unbound.conf to filter ads and malicious domains



For the full guide with additional tips, visit the original article on Vultr Docs.

🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
1[.]1[.]1[.]1
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
2 Knoten · 1 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Deploying Unbound Validating DNS Resolver on Ubuntu 24.04

Thematisch verwandte Begriffe: Deploying, Unbound, Validating, Resolver · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag