ON
← Back to feed
IPFire: Knot Resolver replaced by Unbound
Germany💻 Technology17 days ago

IPFire: Knot Resolver replaced by Unbound

IPFire, a security-focused Linux distribution commonly used as a firewall andVPN gateway, has released a major update (Core Update 203) that replaces its previous DNS resolver, Unbound, with Knot Resolver. This change aims to enhance functionality by enabling encrypted DNS traffic via DNS over TLS, implementing DNS-based filtering rules, and introducing a persistent cache. The new resolver also supports modern Wi-Fi standards such as Wi-Fi 6E and Wi-Fi 7 through the integrated WLAN access point. Knot Resolver offers a more modular architecture, allowing for custom scripting and integration features like DHCP lease binding and DNS filter lists. Additionally, the update introduces a network-wide DNS firewall to block malicious domains and enables SafeSearch enforcement across supported search engines and YouTube. However, administrators using existing DNS forwarding configurations will need to adjust their settings since fully qualified domain names (FQDNs) configured as forward zones are no longer supported.

IPFire has announced that its upcoming Core Update 203 will replace the previously used DNS resolver Unbound with Knot Resolver. This change marks a fundamental shift in the distribution’s DNS infrastructure, aimed at enhancing security, performance, and flexibility. The update introduces several new features, including support for encrypted DNS over TLS, network-wide DNS filtering, and a persistent resolver cache. Additionally, the integrated WLAN access point now supports the 6-GHz band of Wi-Fi 6E and Wi-Fi 7, offering improved performance in densely populated environments. The transition from Unbound to Knot Resolver represents a strategic move by the IPFire developers to modernize their core networking capabilities. According to the release notes, this replacement is part of a broader effort to make the system more adaptable and scalable. Knot Resolver operates in a modular fashion, allowing for script-based customization. IPFire leverages this modularity to extend functionality, such as integrating with DHCP leases and DNS filter lists. These enhancements enable administrators to manage network resources more efficiently while maintaining a high level of control and security. One of the key improvements introduced with Knot Resolver is the ability to securely forward DNS queries using DNS over TLS. This ensures that data transmitted between clients and upstream resolvers remains confidential and protected against interception or tampering. Administrators can now deploy external resolvers without exposing sensitive information through unencrypted channels. This feature aligns with growing concerns around privacy and data integrity in internet communications. In addition to enhanced encryption and forwarding capabilities, IPFire is introducing a DNS firewall that blocks domains associated with malware, advertising, and other undesirable categories during name resolution. The system uses the zone-sync tool to download zone files and filter data securely, updating them incrementally rather than transferring complete lists each time. This reduces bandwidth usage and improves efficiency. The SafeSearch feature, which forces searches to use safe search variants of supported search engines and YouTube, further strengthens content filtering within the network. IPFire also enhances local DNS management by preserving user-defined entries and conditional forwarding rules. These allow specific zones to be directed to designated DNS servers, such as internal networks or remote domains accessible via a virtual private network. The new resolver cache persists across restarts, reducing lookup times after reboot and alleviating pressure on higher-level DNS servers. Knot Resolver utilizes multiple worker processes to share cache and status information, enabling IPFire to utilize multiple CPU cores without requiring isolated caches per process. Administrators must adjust existing configurations to accommodate these changes. Previously configured fully qualified domain names (FQDNs) as forward zones are no longer accepted; instead, IP addresses must be used. This requires revisiting and modifying current DNS forwarding settings to ensure compatibility with the updated system. On the wireless front, IPFire's built-in access point now supports the 6-GHz frequency band, providing better performance for Wi-Fi 6E and Wi-Fi 7 devices. This spectrum offers less interference from older devices and allows for wider channels of up to 80 or 160 MHz, improving throughput and reliability. Unlike parts of the 5-GHz band, the 6-GHz spectrum does not require dynamic frequency selection (DFS) for radar detection, eliminating the need for access points to scan for free channels or switch frequencies upon detecting radar signals. This change helps prevent connection drops caused by unnecessary channel switches. For users deploying IPFire on Amazon Web Services (AWS), the update includes support for IMDSv2, the newer version of the instance metadata service. This token-based service provides greater security compared to the previous version, ensuring more robust authentication and data protection for cloud-hosted instances.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 8017 days ago
IPFire: Knot Resolver replaced by Unbound

IPFire, a security-focused Linux distribution commonly used as a firewall andVPN gateway, has released a major update (Core Update 203) that replaces its previous DNS resolver, Unbound, with Knot Resolver. This change aims to enhance functionality by enabling encrypted DNS traffic via DNS over TLS, implementing DNS-based filtering rules, and introducing a persistent cache. The new resolver also supports modern Wi-Fi standards such as Wi-Fi 6E and Wi-Fi 7 through the integrated WLAN access point. Knot Resolver offers a more modular architecture, allowing for custom scripting and integration features like DHCP lease binding and DNS filter lists. Additionally, the update introduces a network-wide DNS firewall to block malicious domains and enables SafeSearch enforcement across supported search engines and YouTube. However, administrators using existing DNS forwarding configurations will need to adjust their settings since fully qualified domain names (FQDNs) configured as forward zones are no longer supported.

Bias read (Center): The article discusses technical updates to a software project focused on networking and security infrastructure. It provides factual information about changes in DNS resolution technology, new features, and compatibility considerations. There is no political framing, bias, or ideological emphasis in

Why factuality (85): The article accurately reports the main points from the primary source document, including the switch from Unbound to Knot Resolver, the features like DNS over TLS and the 6 GHz WiFi support. It mentions the technical benefits and new functionalities introduced in the update. However, it omits some

Why objectivity (80): The tone is neutral and informative, presenting the facts without apparent bias. However, it slightly emphasizes the significance of the DNS change and the new features, which could be seen as a minor promotional angle.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories