At the end of the day you can't fit a big pipe into a small pipe. Everything was tuned mathematically. I think that is explanation enough, now do your own research I'm outta here.
Ping 60 and ping‑restart 180 are a good fit for this Unbound‑over‑VPN setup because they match your DNS timing and Unbound’s tolerance for upstream “hiccups” while keeping the tunnel stable.
infra-cache-min-rtt: 60
Unbound treats anything below about 60 ms as “fast”, but this also means it...
unwanted-reply-threshold: <number>
If set, a total number of unwanted replies is kept track of in every thread. When it reaches the threshold, a defensive action is taken and a warning is printed to the log. The defensive action is to clear the rrset and message caches, hopefully flushing away...
Lot of you guys use ac routers, should at least upgrade to BE version or at the least an AX version.
just in case this setup is for dual core router 256 ram no vpn tuned to this config. best used with dynamic ip isp
#########################################
# integration IPV6
#
do-ip6: no...
Maximum RTT Value
The highest round-trip time (rtt) in this list is 1400 milliseconds.
Details
This peak occurs for 5.39.112.241 ovh.net. ttl 107 ping 0 var 350 rtt 1400 rto 1400 - note the 0 successful pings and ednsknown 0, indicating an unreliable/unprobed server.
Overall Historical Max...
For ddos mitigations I use this website
https://radar.cloudflare.com/security/application-layer
pick your city and see what is the culprit, I mean I block the whole ASN if its known for this type of attack. It is a very harsh way of blocking but it works. just look into ASN and see if you...