DNS resolver

Caching Unbound resolver for devices on your network.

{{#DRIFT_BADGE}}{{#B_UNSAVED}}Unsaved edits{{/B_UNSAVED}}{{#B_DRIFT}}{{B_LABEL}}{{/B_DRIFT}}{{#B_ERROR}}Drift state unknown{{/B_ERROR}}{{#B_OK}}In sync{{/B_OK}}{{/DRIFT_BADGE}}
{{#ERROR}}
{{ERROR}}
{{/ERROR}} {{#FLASH}}
{{FLASH}}
{{/FLASH}} {{#PENDING}}

Confirm DNS change

A live DNS change by {{PENDING_ACTOR}} is awaiting confirmation and reverts automatically in {{PENDING_REMAINING}} seconds unless you keep it.

A bad resolver configuration cannot lock you out of management — this window simply lets a mistaken change revert itself if you do nothing.

{{#PENDING_REVERT_FAILED}}
Automatic revert failed — the resolver may be in an inconsistent state. The change keeps retrying in the background; if it persists, restart the DNS service from the console.
{{/PENDING_REVERT_FAILED}} {{#WRITE}} {{/WRITE}}
{{/PENDING}} {{#ADOPTION}}

Existing Unbound configuration detected

This router has an Unbound configuration that OgmaProtect does not manage. Applying from this page replaces it with the settings below. The current file is preserved to unbound.conf.preadopt before the first overwrite, and shown read-only here — it is never imported automatically.

{{#LIVE_PREVIEW_TRUNCATED}}

Preview truncated — the full file is preserved on adoption.

{{/LIVE_PREVIEW_TRUNCATED}}
{{/ADOPTION}}
Configured {{ENABLED_LABEL}} Resolver {{RUNNING_LABEL}} {{#HEALTH_CHIP}} Resolution {{HEALTH_LABEL}} {{/HEALTH_CHIP}}
{{#HEALTH_GUIDE}}

{{HEALTH_GUIDE}}

{{/HEALTH_GUIDE}} {{#ENABLED_DRIFT}}

The resolver's service state does not match the configuration — applying re-synchronizes it.

{{/ENABLED_DRIFT}} {{#CONFIG_DRIFT}}

The live unbound.conf differs from the saved configuration (hand-edited, or never applied) — applying overwrites it with the settings below.

{{/CONFIG_DRIFT}}
{{#UPSTREAM_DRIFT}}

Upstream DNS changed (lease renewal) — a DHCP lease now lists different DNS servers than the resolver was applied with. Refresh re-applies from the current lease without changing your configuration.

{{#WRITE}}
{{/WRITE}}
{{/UPSTREAM_DRIFT}}

DNS server

{{#ADOPTION}} {{#WRITE}} {{/WRITE}} {{/ADOPTION}} {{#WAN_CONFIRM}} {{/WAN_CONFIRM}} {{#DISABLE_CONFIRM}} {{/DISABLE_CONFIRM}} {{#WRITE}} {{/WRITE}} {{#WRITE}} {{/WRITE}}
{{#CLIENT_ADOPTION}}

Point your devices at this resolver

Enabling the resolver does not by itself change what your devices use. Devices must be told to use this router for DNS — set your DHCP server's DNS option to {{ROUTER_IPS}}, or configure devices manually.

{{/CLIENT_ADOPTION}} {{#PF_HINT}}

Firewall

Ensure your firewall passes UDP and TCP port 53 from {{HINT_SUBNETS}} to this router. This page never changes firewall rules — manage them on the Firewall page.

{{/PF_HINT}}

Router's own DNS

How this router itself resolves names — separate from the resolver above and managed by resolvd(8); OgmaProtect never edits /etc/resolv.conf. The per-interface Use DHCP DNS toggle lives on each interface page.

{{#ROUTER_DNS_ROWS}}
{{ROUTER_DNS_ROWS}}
{{/ROUTER_DNS_ROWS}} {{#ROUTER_DNS_EMPTY}}

No interface uses DHCP — the router's nameservers are whatever /etc/resolv.conf was set to by hand.

{{/ROUTER_DNS_EMPTY}}