# Unbound and IPv6 DNS

**URL:** <https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784>\
**Category:** Help\
**Created:** [May 23, 2018, 12:05pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784 "2018-05-23T12:05:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 12:05pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/1 "2018-05-23T12:05:08Z")

</div>

#### Please follow the below template, it will help us to help you!

## Expected Behaviour:

\_IPv6 DNS workng

Using this guide: [Redirecting...](https://docs.pi-hole.net/guides/unbound/)

my conf:

`server:  
verbosity: 1  
port: 5353  
do-ip4: yes  
do-udp: yes  
do-tcp: yes

```
# May be set to yes if you have IPv6 connectivity
do-ip6: yes

# Use this only when you downloaded the list of primary root servers!
root-hints: "/var/lib/unbound/root.hints"

# Trust glue only if it is within the servers authority
harden-glue: yes

# Require DNSSEC data for trust-anchored zones, if such data is absent, the zone becomes BOGUS
harden-dnssec-stripped: yes

# Don't use Capitalization randomization as it known to cause DNSSEC issues sometimes
# see https://discourse.pi-hole.net/t/unbound-stubby-or-dnscrypt-proxy/9378 for further details
use-caps-for-id: no

# Reduce EDNS reassembly buffer size.
# Suggested by the unbound man page to reduce fragmentation reassembly problems
edns-buffer-size: 1472

# TTL bounds for cache
cache-min-ttl: 3600
cache-max-ttl: 86400

# Perform prefetching of close to expired message cache entries
# This only applies to domains that have been frequently queried
prefetch: yes

# One thread should be sufficient, can be increased on beefy machines
num-threads: 1

# Ensure kernel buffer is large enough to not loose messages in traffic spikes
so-rcvbuf: 1m

# Ensure privacy of local IP ranges
private-address: 192.168.0.0/16
private-address: 172.16.0.0/12
private-address: 10.0.0.0/8

```

`\_

## Actual Behaviour:

\_IPv6 DNS is not working

if i change to Cloudflare IPv6 DNS its works, very odd\_

## Debug Token:

_[Replace this text with the debug token provided from running `pihole -d` (or running the debug script through the web interface]_

---

<div class="post-metadata">

**Author:** ![RamSet](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/ramset/32/3497_2.png) [@RamSet](https://discourse.pi-hole.net/u/RamSet)\
**Post date:** [May 23, 2018, 3:38pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/2 "2018-05-23T15:38:02Z")

</div>

> [@Tntdruid](#):
>
> do-ip6: yes

Do you have this in your unbound config file?

---

<div class="post-metadata">

**Author:** ![RamSet](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/ramset/32/3497_2.png) [@RamSet](https://discourse.pi-hole.net/u/RamSet)\
**Post date:** [May 23, 2018, 3:43pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/3 "2018-05-23T15:43:10Z")

</div>

Oh it highlighted only a small part of the conf. I do see it’s enabled 🙂

What’s the output of  
`ping6 flurry.com`

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 3:51pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/4 "2018-05-23T15:51:34Z")

</div>

> [@RamSet](#):
>
> do-ip6: yes

Yes i do.

ping6 flurry.com  
PING flurry.com(raspberrypi (2a00:7660:xxx::96)) 56 data bytes  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=1 ttl=64 ti me=0.134 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=2 ttl=64 ti me=0.115 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=3 ttl=64 ti me=0.115 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=4 ttl=64 ti me=0.114 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=5 ttl=64 ti me=0.118 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=6 ttl=64 time=0.111 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=7 ttl=64 time=0.140 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=8 ttl=64 time=0.111 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=9 ttl=64 time=0.118 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=10 ttl=64 time=0.113 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=11 ttl=64 time=0.121 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=12 ttl=64 time=0.111 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=13 ttl=64 time=0.131 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=14 ttl=64 time=0.115 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=15 ttl=64 time=0.113 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=16 ttl=64 time=0.113 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=17 ttl=64 time=0.130 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=18 ttl=64 time=0.114 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=19 ttl=64 time=0.128 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=20 ttl=64 time=0.113 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=21 ttl=64 time=0.131 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=22 ttl=64 time=0.106 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=23 ttl=64 time=0.118 ms  
q64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=24 ttl=64 time=0.127 ms

64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=25 ttl=64 time=0.124 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=26 ttl=64 time=0.125 ms  
q64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=27 ttl=64 time=0.142 ms  
uit  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=28 ttl=64 time=0.119 ms  
quit64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=29 ttl=64 time=0.127 ms

64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=30 ttl=64 time=0.128 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=31 ttl=64 time=0.127 ms  
64 bytes from raspberrypi (2a00:7660:xxx::96): icmp\_seq=32 ttl=64 time=0.121 ms

---

<div class="post-metadata">

**Author:** ![RamSet](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/ramset/32/3497_2.png) [@RamSet](https://discourse.pi-hole.net/u/RamSet)\
**Post date:** [May 23, 2018, 4:06pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/5 "2018-05-23T16:06:10Z")

</div>

what's the output of:

`dig AAAA ipv6.google.com @127.0.0.1 -p 5353`

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 4:20pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/6 "2018-05-23T16:20:09Z")

</div>

dig AAAA ipv6.google.com @127.0.0.1 -p 5353

; \<\<\>\> DiG 9.10.3-P4-Raspbian \<\<\>\> AAAA ipv6.google.com @127.0.0.1 -p 5353  
;; global options: +cmd  
;; Got answer:  
;; -\>\>HEADER\<\<- opcode: QUERY, status: NOERROR, id: 696  
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:  
; EDNS: version: 0, flags:; udp: 1472  
;; QUESTION SECTION:  
;ipv6.google.com. IN AAAA

;; ANSWER SECTION:  
ipv6.google.com. 604800 IN CNAME ipv6.l.google.com.  
ipv6.l.google.com. 3600 IN AAAA 2a00:1450:400e:80b::200e

;; Query time: 47 msec  
;; SERVER: 127.0.0.1#5353(127.0.0.1)  
;; WHEN: Wed May 23 18:19:46 CEST 2018  
;; MSG SIZE rcvd: 93

---

<div class="post-metadata">

**Author:** ![RamSet](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/ramset/32/3497_2.png) [@RamSet](https://discourse.pi-hole.net/u/RamSet)\
**Post date:** [May 23, 2018, 4:25pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/7 "2018-05-23T16:25:11Z")

</div>

The query ran an IPV6 request via unbound and it was resolved. Unbound IS responding and resolving IPV6 requests.

Do you have `AAAA_QUERY_ANALYSIS=no` in `/etc/pihole/pihole-FTL.conf` ?

Is your Pi-hole interface set-up to block ads via IPV6 ? If yes, if you `cat /etc/pihole/setupVars.conf` do you see an IPV6 under `IPV6_ADDRESS=` ?

If yes, does it match with what your clients have as your IPV6 DNS server?

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 4:37pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/8 "2018-05-23T16:37:00Z")

</div>

pihole-FTL.conf  
TIMEFRAME=today  
RESOLVE\_IPV6=yes  
RESOLVE\_IPV6=yes  
MAXDBDAYS=1  
IGNORE\_LOCALHOST=yes

setupVars.conf  
WEBPASSWORD=  
PIHOLE\_INTERFACE=eth0  
IPV4\_ADDRESS=10.10.1.2/24  
IPV6\_ADDRESS=2a00:7660:xxx::96  
QUERY\_LOGGING=true  
INSTALL\_WEB\_SERVER=true  
INSTALL\_WEB\_INTERFACE=true  
LIGHTTPD\_ENABLED=1  
TEMPERATUREUNIT=C  
WEBUIBOXEDLAYOUT=traditional  
DHCP\_START=10.10.1.2  
DHCP\_END=10.10.1.251  
DHCP\_ROUTER=10.10.1.1  
DHCP\_LEASETIME=24  
PIHOLE\_DOMAIN=mydoman.lan  
DHCP\_IPv6=false  
DHCP\_ACTIVE=false  
DNSMASQ\_LISTENING=local  
PIHOLE\_DNS\_1=127.0.0.1#5353  
DNS\_FQDN\_REQUIRED=false  
DNS\_BOGUS\_PRIV=false  
DNSSEC=false  
CONDITIONAL\_FORWARDING=false  
API\_EXCLUDE\_DOMAINS=  
API\_EXCLUDE\_CLIENTS=  
API\_QUERY\_LOG\_SHOW=all  
API\_PRIVACY\_MODE=false

---

<div class="post-metadata">

**Author:** ![RamSet](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/ramset/32/3497_2.png) [@RamSet](https://discourse.pi-hole.net/u/RamSet)\
**Post date:** [May 23, 2018, 4:40pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/9 "2018-05-23T16:40:17Z")

</div>

> [@Tntdruid](#):
>
> TIMEFRAME=today

This is deprecated (no longer in use).

> [@Tntdruid](#):
>
> IPV6\_ADDRESS=2a00:7660:xxx::96

try a `nslookup flurry.com 2a00:7660:xxx::96`

This will execute nslookup for the domain via the IPV6.  
It should resolve to your raspberry.

Your web interface will show a blocked AAAA request to that domain.

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 5:00pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/10 "2018-05-23T17:00:28Z")

</div>

nslookup flurry.com 2a00:7660:xxx::96  
Server: 2a00:7660:xxx::96  
Address: 2a00:7660:xxx::96#53

Name: flurry.com  
Address: 10.10.1.2

---

<div class="post-metadata">

**Author:** ![RamSet](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/ramset/32/3497_2.png) [@RamSet](https://discourse.pi-hole.net/u/RamSet)\
**Post date:** [May 23, 2018, 5:07pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/11 "2018-05-23T17:07:58Z")

</div>

> [@Tntdruid](#):
>
> nslookup [flurry.com](http://flurry.com) 2a00:7660:xxx::96  
> Server: 2a00:7660:xxx::96  
> Address: 2a00:7660:xxx::96#53
> 
> Name: [flurry.com](http://flurry.com)  
> Address: 10.10.1.2

Looks like it's working 🙂

a `dig AAAA flurry.com` will resolve to your 2a00:7660:xxx::96 (and it should show up as blocked in your Query logs on your admin)

![image](https://discourse.pi-hole.net/uploads/default/original/2X/0/000d1cc62da819b82d1d04fcb8a022281db31905.png)

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 5:09pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/12 "2018-05-23T17:09:38Z")

</div>

Bit odd my IPv6 DNS server fail the test on [https://test-ipv6.com](https://test-ipv6.com) and [http://ipv6-test.com](http://ipv6-test.com)

---

<div class="post-metadata">

**Author:** ![mibere](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/mibere/32/18057_2.png) [@mibere](https://discourse.pi-hole.net/u/mibere)\
**Post date:** [May 23, 2018, 5:12pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/13 "2018-05-23T17:12:33Z")

</div>

Is IPv6 enabled on your client?

I have IPv6 disabled on my Mac, and therefore the IPv6 test on test-ipv6.com fails for me.  
On other clients I have IPv6 enabled, and the test is ok.

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 5:16pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/14 "2018-05-23T17:16:51Z")

</div>

All my clients got it on.

---

<div class="post-metadata">

**Author:** ![mibere](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/mibere/32/18057_2.png) [@mibere](https://discourse.pi-hole.net/u/mibere)\
**Post date:** [May 23, 2018, 7:04pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/16 "2018-05-23T19:04:28Z")

</div>

Is it possible that one has a IPv6 in the local net, but not outside of it (as the outside address is assigned by the provider)?

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 23, 2018, 7:09pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/17 "2018-05-23T19:09:50Z")

</div>

My USG does the IPv6 dhcp and get it from the IPv6 is static range /48

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [May 24, 2018, 6:43am UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/18 "2018-05-24T06:43:12Z")

</div>

[here](https://en.internet.nl/connection/) is a better IPv6 test site, if something is NOK, there is a brief explanation.

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 24, 2018, 7:23am UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/19 "2018-05-24T07:23:21Z")

</div>

Fail on DNS

Verdict:  
Your DNS resolver is not able to reach name servers over IPv6.

---

<div class="post-metadata">

**Author:** ![Tntdruid](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/tntdruid/32/773_2.png) [@Tntdruid](https://discourse.pi-hole.net/u/Tntdruid)\
**Post date:** [May 26, 2018, 3:06pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/20 "2018-05-26T15:06:20Z")

</div>

Getting 100% at [Connection test](http://en.conn.internet.nl/connection/)

Did a clear install and it works now.

---

<div class="post-metadata">

**Author:** ![system](https://discourse.pi-hole.net/uploads/default/original/3X/7/c/7c8792f649eeb921c5d2b4c41564ffa873d9a2b8.png) [@system](https://discourse.pi-hole.net/u/system)\
**Post date:** [June 16, 2018, 3:06pm UTC](https://discourse.pi-hole.net/t/unbound-and-ipv6-dns/9784/21 "2018-06-16T15:06:25Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
