Paul Taylor
Fri Feb 10 14:28:27 CET 2012

On the original topic of this thread, I have another incident to report.
After experiencing some strangeness with my NAS (where unbound was
running previously), I moved Unbound to an installation of pfSense
running on an old net4801.  I believe pfSense is still on version 1.4.14
of Unbound.  I configured it pretty much identically to my NAS
installation of Unbound.  By that, I mean that I have numerous
forwarders added for various CDNs, with a "." forwarder pointing to
OpenDNS.  DNSSEC validation is disabled.  About two weeks had passed
with no further problems, until this morning. 

Just before I was about to leave home for work (just after 7 AM), my
daughter told me that the internet was down.  I checked my router and
saw that the internet connection went down last night for a little over
an hour..  It recovered about 3:15 AM.  So, it had been up and
operational for almost 4 hours by the time I started looking at the
issue.  A quick nslookup showed SERVFAIL replies.  Since I had to leave
for work, I didn't have time to do much in the way of troubleshooting.
I recycled the service via pfSense's Services page (I think it just
kills and restarts the service), and DNS was resolving properly again.

Unfortunately, since it's on an embedded box, I didn't have logging
enabled, and I don't know what commands, if any, I could run that let
you see the "state" Unbound is stuck in when this happens.