1 files changed,
+7,
-0
+7,
-0
1@@ -44,4 +44,11 @@ in
2 "2a03:4000:0:1::e1e6"
3 "2a03:4000:8000::fce6"
4 ];
5+
6+ # netcup's firewall policy allows only listed inbound ports, so replies to
7+ # outbound UDP DNS (to a random high port) never arrive; only netcup's own
8+ # resolvers get through. TCP replies do. A recursive unbound (sovrn's
9+ # Stalwart resolver, nix/modules/stalwart.nix) therefore queries upstream
10+ # over TCP only. Inert where unbound isn't enabled.
11+ services.unbound.settings.server.tcp-upstream = true;
12 }