DNS over TLS support

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Advanced Networking
Author Message
murtaza12
DD-WRT User


Joined: 19 Nov 2015
Posts: 122
Location: Pakistan

PostPosted: Thu Jan 10, 2019 11:13    Post subject: DNS over TLS support Reply with quote
So Google announced DNS over TLS support for their public DNS recently.

https://security.googleblog.com/2019/01/google-public-dns-now-supports-dns-over.html

I had used DoT previously on my Netgear router with a modified stock firmware with Stubby built-in. (Voxel firmware).

However, I have Kong's DD-WRT builds on my Netgear R7800 now, and would like to use DNS over TLS with Google DNS.

I've read online about Stubby, Unbound and DNSMasq. Some say Unbound is required, some say it isn't. I also read that Stubby dies immediately after being launched.

How would I go about getting DNS over TLS enabled on my router, and is there any chance of native support being added to DD-WRT in the future?

Thanks

_________________
Active devices:
Netgear R7800 - Stock v1.0.2.63
Linksys EA8500 - OpenWRT 18.06.4
ASUS RP-AC68U - 3.0.0.4.382.40019
Sponsor
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 2808
Location: UK, London, just across the river..

PostPosted: Thu Jan 10, 2019 14:28    Post subject: Reply with quote
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=314677
_________________
Atheros
TP-Link WR740Nv1 ------DD-WRT 33772 BS WAP/Switch (wired)
TP-Link WR1043NDv2 -----DD-WRT 41057 BS (AP,PPPoE,NAT,AD Blocking,AP Isolation,Firewall,Local DNS,Forced DNS,DoT)
TP-Link WR1043NDv2 -----DD-WRT 40890 BS (AP,NAT,AD Blocking,Firewall,Wi-Fi OFF,Local DNS,Forced DNS,DoT)
TP-Link WR1043NDv2 -----Gargoyle OS 1.11.0 (AP,NAT,QoS,Quotas)
Qualcomm/IPQ8065
Netgear R7800 ---------DD-WRT 40270M 4.9 Kong (AP,NAT,AD-Blocking,AP&Net Isolation,Firewall,Local DNS,Forced DNS,DNSCrypt v2 x2)
Broadcom
Netgear R7000 ---------DD-WRT 40270M Kong (AP,NAT,VLAN,AD-Blocking,Firewall,Local DNS,Forced DNS,DoT)
------------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 via Entware by mac913
murtaza12
DD-WRT User


Joined: 19 Nov 2015
Posts: 122
Location: Pakistan

PostPosted: Fri Jan 11, 2019 7:07    Post subject: Reply with quote
Alozaros wrote:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=314677


Thanks, I did come across that yesterday before posting the thread, but I got nowhere using the instructions of that thread.

Eventually I did get stubby and getdns installed, and sort of working, but I may have screwed up the configuration with DNSMasq since nothing worked after that.

Will try again on Sunday when everyone is sleeping in so nobody in the house is affected by it.

_________________
Active devices:
Netgear R7800 - Stock v1.0.2.63
Linksys EA8500 - OpenWRT 18.06.4
ASUS RP-AC68U - 3.0.0.4.382.40019
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 2808
Location: UK, London, just across the river..

PostPosted: Fri Jan 11, 2019 7:39    Post subject: Reply with quote
all 1.1.1.1 and 9.9.9.9 support both DoH and DoTls...
only 8.8.8.8 was late... if you want to use it on browser level for PC better use FFox as DoH is emended
on the browser level...i dearly hope it will be implemented on router level soon..but in general
not even one of the commercial browsers uses plain text
for DNS lookups anymore min is TLS handshake...

_________________
Atheros
TP-Link WR740Nv1 ------DD-WRT 33772 BS WAP/Switch (wired)
TP-Link WR1043NDv2 -----DD-WRT 41057 BS (AP,PPPoE,NAT,AD Blocking,AP Isolation,Firewall,Local DNS,Forced DNS,DoT)
TP-Link WR1043NDv2 -----DD-WRT 40890 BS (AP,NAT,AD Blocking,Firewall,Wi-Fi OFF,Local DNS,Forced DNS,DoT)
TP-Link WR1043NDv2 -----Gargoyle OS 1.11.0 (AP,NAT,QoS,Quotas)
Qualcomm/IPQ8065
Netgear R7800 ---------DD-WRT 40270M 4.9 Kong (AP,NAT,AD-Blocking,AP&Net Isolation,Firewall,Local DNS,Forced DNS,DNSCrypt v2 x2)
Broadcom
Netgear R7000 ---------DD-WRT 40270M Kong (AP,NAT,VLAN,AD-Blocking,Firewall,Local DNS,Forced DNS,DoT)
------------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 via Entware by mac913
drdedus
DD-WRT User


Joined: 31 Dec 2013
Posts: 94
Location: Greece

PostPosted: Wed Sep 11, 2019 9:00    Post subject: Reply with quote
is Dot or Doh supported without to do any other steps in the latest August or September 2019 builds?
just by entering the dns server address?
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 2808
Location: UK, London, just across the river..

PostPosted: Wed Sep 11, 2019 9:54    Post subject: Reply with quote
nope DNS over Tls is not supported by default...
you'd need to use either "Stubby (getdns), or Unbound"
than you need a USB port on your router and install Entware
DNScrypt is doing DoH and DNScrypt...also via Entware..
package manager...for more details about those check my sig
those 2 links there...

_________________
Atheros
TP-Link WR740Nv1 ------DD-WRT 33772 BS WAP/Switch (wired)
TP-Link WR1043NDv2 -----DD-WRT 41057 BS (AP,PPPoE,NAT,AD Blocking,AP Isolation,Firewall,Local DNS,Forced DNS,DoT)
TP-Link WR1043NDv2 -----DD-WRT 40890 BS (AP,NAT,AD Blocking,Firewall,Wi-Fi OFF,Local DNS,Forced DNS,DoT)
TP-Link WR1043NDv2 -----Gargoyle OS 1.11.0 (AP,NAT,QoS,Quotas)
Qualcomm/IPQ8065
Netgear R7800 ---------DD-WRT 40270M 4.9 Kong (AP,NAT,AD-Blocking,AP&Net Isolation,Firewall,Local DNS,Forced DNS,DNSCrypt v2 x2)
Broadcom
Netgear R7000 ---------DD-WRT 40270M Kong (AP,NAT,VLAN,AD-Blocking,Firewall,Local DNS,Forced DNS,DoT)
------------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 via Entware by mac913
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum