High memory consumption: DNS Proxy Server

Try 12 lists.

ipFire DNSBL plus some of the Haghezi for different specific areas (specific phone model, specific smarttv/OS) and then just leave it running until some of the background refresh takes place and reloads the daemon.

In 3 weeks my box started with 1,4 GB RAM solely for unbound and reached 3,4 GB - nothing touched, just normal refresh precesses.

I usually check the box when a new & Major version is released so the uptime is sometines around 90-100 days. That was until unbound eats all memory.

Reboot: needs 5 minutes for down and 6 for up because of large ipsets I blocked - loading 200 CC ipsets in memory is not easy…

Funny part: all those Ipsets consume far less memory than 1-2 DNS blocklist. And swapping IPSets in kernel (updating them) is achieved with zero downtime for the FW. Plus I can run in paralel the update of CC ipsets and ASN ipsets and swapping them when ready with no race condition (list name stays the same, just change the content)

I would like that to happen witz RPZ list in the future - security services update their memory “databases” with minimum if not zero downtime for that protection.

It seems that everybody has a different approach on using this solution (and that is normal!) therefore each will evaluate the solution against delivering personalized needs.