I run BIND on OPNsense as the slave server for an internal DNS zone.
I notice that, if the master for that zone goes down, the slave will stop answering request for that zone (responding with SRVFAIL) after the first failed update attempt.
The design reason behind that is probably to avoid giving out stale data from the slave if the master cannot be reached. (After all, the master may still be fine and it is just the network connection from the slave that has failed.) However, this is bad news for resilience if the master server is down and cannot be brought up in time.
Is there a setting to tell BIND to always serve the last known information for a slave zone, regardless of how long the master server has been unreachable, even at the risk of returning stale data?
If so, is that somehow accessible from the OPNsense web GUI (i.e. no unsupported poking under the hood)?