Recursor mode makes (blocked) connections to strange IPs

Hey there!

I try to manage pihole and ipfire in the best way and while doing it, I understood that ipfire also can use unbound (so I can just deactivate unbound on pihole and use ipfire as upstream DNS). But when I activate unbound or recursor mode on ipfire by deactivating the DNS servers I can not get any connection (also if I use ipfire directly as DNS server - no pihole).

FW-logs show me strange dropped connections to external and internal IPs which I did not set ( so they do not exist for me). If I activate some DNS servers and leave the recursor mode, these strange connections seem to be gone.

Does this behavior have to do with the recursor mode? Does recursor mode make some internal virtual random servers for its needs or smth like that? Do I need a firewall rule for that mode?

I can not explain these connections otherwise.

Cheers
fstarter

In recursor mode IPFire is acting as the recursor dns server and contacting the individual name servers itself.
See this blog post for more info.
https://blog.ipfire.org/post/what-you-can-do-with-the-new-dns-features-in-ipfire

It could be that the strange IP’s you see are the names of name servers that IPFire is trying to contact. Why they are getting blocked I don’t know. Are you using the IP Blocklist. Could some of those IP’s be in an IP blocklist.
If you check the source of the IP’s do they resolve to a name server or to what?

For info recursor mode can not run in TLS mode so all the recursor mode traffic is in clear text.
https://community.ipfire.org/t/tls-in-recursor-mode/6005/9

As the first blog post says it is a trade off for the various options and you have to decide what makes best sense for your setup.

Thanks for the infos!

Ah, I forgot that I block outgoing traffic of the ipfire itself and allow it just to the update server and DNS server. So I must make a rule for these outgoing connections. But I suppose that there are a lot of server ipfire connects in recursor mode, isn’t it?

I read about it and read the blog posting above. Difficult question about what is better, to trust the chosen DNS-TLS provider or to trust the com/org/de provider. What is known about the providers of the server for such 1. level domains as org/com/de and so on? Who owns and manages such nameserver?