Last adaptation to the version: 14.0.1 (01.2025)
New:
- The handling of old EDNS values has been uploaded
- Individual domains can be excluded from DNSSEC verification
The EDNS option is removed in favor of the option to ignore domains during DNSSEC verification - Client names can be resolved if the host is in a DHCP-Pool with a domain name
- The setting Use provider's DNS server is now included in [UTM/APP/Nameserver-DNS_Forwarding#Provider-DNS
This article refers to a Beta version
General Settings | |||
| General settings are made under Area General. | |||
| Caption | Value | Description | UTMuser@firewall.name.fqdnAnwendungen Tab General
|
|---|---|---|---|
| DNSSEC validation in resolver: | Off | notempty Caution! If DNSSEC Validation is enabled alongside Forward-Zones, it must be ensured that the domains corresponding to the forward zones can be validated within the global DNS or that they are added to the ignore domains list below. Replies corresponding to not globally registered domains are refused and lead to SERVFAIL replies for the domain in question. When this function is activated, all DNS entries are resolved with DNSSEC without exception. This would also attempt a validation in the DNS hierarchy for only local addresses. However, due to the lack of uniqueness of the local address, it cannot be registered with higher-level DNS servers. An error message appears, the address is not resolved and the zone is therefore not accessible (using DNS). This applies, for example, to .local domains! Further information on the implementation of DNSSEC can be found here. | |
| Allow DNS queries only from routed and VPN networks: | On Default |
By default, only DNS queries from the following sources are answered:
| |
| Off | If DNS queries are to be answered from other external networks as well, this option must be disabled | ||
| Ignore Domains during DNSSEC Verificationnotempty New as of v14.0 |
Domains that should not be validated with DNSSEC | ||
| Resolve DHCP Domain names: notempty New as of v14.0 |
anyideas.local (Pool: Local-Pool1 | If a domain is specified in the DHCP pool configuration these domains are selectable here. When a domain is selected, the DHCP hosts can be resolved either by the assigned name of the static lease or, if none is defined, by the client name with which the client registers with the DHCP server. | |
| Disable EDNS for the following servers notempty New as of v14.0 Update v14.0.1 |
The EDNS option is omitted in favor of the option Ignore domains during DNSSEC verification
Inhalte in der extc-Variablen EDNS_SERVERS_OFF
Don't forget to save!
However, the message will appear again at the next login. |
![]() UTMuser@firewall.name.fqdnApplications Example of invalid IP addresses from previous configuration
| |
| Use DNS server specified by the provider: This setting is applied in the section DNS-Forwarding | |||





