On 14-06-28 01:54 PM, Robert Edmonds wrote: > Ralf Hildebrandt wrote: >> * Simon Deziel <simon+unbound at sdeziel.info>: >>> On 14-06-19 09:27 AM, Ralf Hildebrandt wrote: >>>> Forwarding works OK, but on 22.214.171.124 I'm seeing queries in the >>>> query.log: >>>> >>>> 19-Jun-2014 15:23:05.172 client 126.96.36.199#18055: query: 188.8.131.52.b.baRRACudACEnTRal.org IN A +EDC (184.108.40.206) >>>> 19-Jun-2014 15:23:05.342 client 220.127.116.11#51273: query: 18.104.22.168.B.bARRACuDAcENtrAL.ORg IN A +EDC (22.214.171.124) >>>> 19-Jun-2014 15:23:05.422 client 126.96.36.199#61743: query: 188.8.131.52.b.BarracUDaCentraL.ORG IN A +EDC (184.108.40.206) >>>> 19-Jun-2014 15:23:05.582 client 220.127.116.11#47007: query: 18.104.22.168.b.BArRACudAceNtraL.ORg IN A +EDC (22.214.171.124) >>>> >>>> Why are these queries forwarded without any explicit forward-zone >>>> statement? >>> >>> If you are on Debian/Ubuntu you should check if /etc/default/unbound has >>> RESOLVCONF_FORWARDERS set to true as this would instruct Unbound to use >>> the nameservers from resolv.conf as forwarders. > > No, this is incorrect. Nothing in the unbound package reads forwarders > from /etc/resolv.conf. If RESOLVCONF_FORWARDERS is set, and the > resolvconf package is installed, then the non-loopback IPs provided to > the resolvconf facility will be configured as forwarders for Unbound at > runtime. I stand corrected, thanks for the precision.