Caching Unbound resolver for devices on your network.
A live DNS change by {{PENDING_ACTOR}} is awaiting confirmation and reverts automatically in {{PENDING_REMAINING}} seconds unless you keep it.
A bad resolver configuration cannot lock you out of management — this window simply lets a mistaken change revert itself if you do nothing.
{{#PENDING_REVERT_FAILED}}
This router has an Unbound configuration that OgmaProtect does not manage.
Applying from this page replaces it with the settings below.
The current file is preserved to unbound.conf.preadopt
before the first overwrite, and shown read-only here — it is never imported automatically.
Preview truncated — the full file is preserved on adoption.
{{/LIVE_PREVIEW_TRUNCATED}}{{HEALTH_GUIDE}}
{{/HEALTH_GUIDE}} {{#ENABLED_DRIFT}}The resolver's service state does not match the configuration — applying re-synchronizes it.
{{/ENABLED_DRIFT}} {{#CONFIG_DRIFT}}The live unbound.conf differs from the saved configuration (hand-edited, or never applied) — applying overwrites it with the settings below.
Upstream DNS changed (lease renewal) — a DHCP lease now lists different DNS servers than the resolver was applied with. Refresh re-applies from the current lease without changing your configuration.
{{#WRITE}} {{/WRITE}}Enabling the resolver does not by itself change what your devices use. Devices must be told to use this router for DNS — set your DHCP server's DNS option to {{ROUTER_IPS}}, or configure devices manually.
Ensure your firewall passes UDP and TCP port 53 from {{HINT_SUBNETS}} to this router. This page never changes firewall rules — manage them on the Firewall page.
How this router itself resolves names — separate from the resolver above and
managed by resolvd(8); OgmaProtect never edits
/etc/resolv.conf. The per-interface
Use DHCP DNS toggle lives on each interface page.
No interface uses DHCP — the router's nameservers are whatever /etc/resolv.conf was set to by hand.