[Solved] WAN Setup

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Author Message
jbkt23
DD-WRT User


Joined: 31 Dec 2018
Posts: 58

PostPosted: Fri Aug 26, 2022 18:26    Post subject: [Solved] WAN Setup Reply with quote
Just a question regarding the setting: Ignore WAN DNS

I'm assuming that this literally means ignore the ISP provide DNS servers. Currently they are tagged on as the 4th and 5th choices since I've selected 3 other servers elsewhere in the setup.

Is there any advantage to selecting the Ignore WAN DNS?

There is another setting "Search in strict order" I've enabled which I assume means the DNS servers I've selected will be searched for in the order I entered them. Thus, only if the first three are unreachable will the 4th and 5th be consulted.

Just making sure I understand what I see.

_________________
ARCHER-C7v5 | v3.0-r55460 std | AP Gateway
WNDR4000|v24-52189_NEWD-2_K3.x_mega|Inactive Spare


Last edited by jbkt23 on Sun Aug 28, 2022 22:33; edited 1 time in total
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12884
Location: Netherlands

PostPosted: Fri Aug 26, 2022 18:40    Post subject: Reply with quote
Strict order does not work reliably.

So I do not use it and have Ignore WAN DNS checked and have 2 reliable Static DNS servers set.

On other setups I use smart dns with tls servers for added security

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
dpp3530
DD-WRT Guru


Joined: 12 Dec 2007
Posts: 780
Location: Pittsburgh, PA USA

PostPosted: Fri Aug 26, 2022 19:33    Post subject: Reply with quote
For years I had OpenDNS servers configured and paid for the subscription so I could use the family filters. Did this after my then 7-year-old daughter was researching birds for a school project and "found something weird" when searching for "blue footed boobies." Ignore WAN DNS was important in that setup because without it, there was a 40% chance (2/5) that it would use my ISP DNS and bypass the filters.
_________________
__________________________
Netgear R7800
DD-WRT v3.0 STD
Linksys WRT1900AC
DD-WRT v3.0 STD
strange
DD-WRT User


Joined: 18 Jun 2006
Posts: 229

PostPosted: Fri Aug 26, 2022 21:20    Post subject: Reply with quote
Just keep in mind that whoever your DNS provider is will know your browsing history. If you are comfortable with you ISP knowing this then, fine. If not, then turn the block on. Note, many people do not trust their ISPs and are concerned about them selling surfing data.
_________________
Netgear XR500 - Gateway
R6700 v3 - Station Bridge
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Fri Aug 26, 2022 21:30    Post subject: Reply with quote
ISPs also use their DNS to impose bandwidth limits, Like Virgin Media for instance.
_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
jbkt23
DD-WRT User


Joined: 31 Dec 2018
Posts: 58

PostPosted: Sat Aug 27, 2022 1:00    Post subject: Reply with quote
Quote:
ISPs also use their DNS to impose bandwidth limits


Since they control the pipe how would the fact that I use or not use their dns servers aid them further in bandwidth limits?

I'm not seeing this in my usage. My thoughts in using a dns server outside my ISP was more to do with the the thinking that the ISP's server would be handling more connections than a server that you have to make an effort to select thus being more responsive. But from the other prior responses I may not be getting exclusive use of my primary dns selection and not reaping the benefits.

_________________
ARCHER-C7v5 | v3.0-r55460 std | AP Gateway
WNDR4000|v24-52189_NEWD-2_K3.x_mega|Inactive Spare
ArjenR49
DD-WRT Guru


Joined: 05 Oct 2008
Posts: 666
Location: Helsinki, Finland / nr. Alkmaar, Netherlands

PostPosted: Sat Aug 27, 2022 8:58    Post subject: Reply with quote
strange wrote:
Just keep in mind that whoever your DNS provider is will know your browsing history. If you are comfortable with you ISP knowing this then, fine. If not, then turn the block on. Note, many people do not trust their ISPs and are concerned about them selling surfing data.


It is my understanding that if you use Unbound, only the final authoritative DNS server of the site you're looking for gets to know the full web address.

I've been using a Raspberry Pi on my LAN to provide Unbound (and PiHole), but I remember seeing mention of Unbound in connection with dd-wrt f/w, too, although I cannot find it in the GUI now.

In one location I use a Raspberry Pi 4 (and added Wireguard for VPN access) and in another location a Raspberry Pi Zero 1.3 with an USB hub with Ethernet adapter. The Pi Zero has a UPS 'HAT' (PiVoyager with small LiPo battery) because there are long times without human presence in that location and sometimes blackouts.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12884
Location: Netherlands

PostPosted: Sat Aug 27, 2022 9:20    Post subject: Reply with quote
Yes but that was not the question, the question was should you Enable Ignore WAN DNS.

The general idea is unless you really trust your ISP you should Enable it.

Of course you can secure your DNS even further, which is not a bad idea (Smart DNS with DoT/DoH, Unbound, Stubby, DNScrypt etc.) and then it does not matter what you have set for upstream DNS resolvers as that is usually overridden.

But that was not the question.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
jbkt23
DD-WRT User


Joined: 31 Dec 2018
Posts: 58

PostPosted: Sat Aug 27, 2022 11:23    Post subject: Reply with quote
Quote:
Strict order does not work reliably


Is this because it doesn't work or that the heuristics of the search picks the first dns server to reply?
Is the dns server locked in on router startup or is it searched for on every client query?

_________________
ARCHER-C7v5 | v3.0-r55460 std | AP Gateway
WNDR4000|v24-52189_NEWD-2_K3.x_mega|Inactive Spare
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12884
Location: Netherlands

PostPosted: Sat Aug 27, 2022 11:33    Post subject: Reply with quote
Some people think that it always use the first DNS server and only if that is not available then proceed to use the second but that is not the case.

As speed is important a DNS server is flagged unavailable rather quickly so if a server is moderately busy it can already be flagged unavailable, we have had in the recent past DNSMaq versions where it looked more like at random, current version does moderately well but still it will sometimes pick the second or third available server while the first is still working so if your ISP server is in the list (if you did not Enable "Ignore WAN DNS") it will get used occasionally also as it is very quick to answer.

So bottom line it is fairly useless, just pick 2 or 3 reliable trusted servers and let DNSMasq use them all, it then uses the quickest

Of course DNS is not very secure at all so if you want better security use secure DNS (SmartDNS with DoT/DoH, DNSCrypt, Unbound, Stubby etc)

For my main router I use SmartDNS with DoT (a sticky in the Advanced Networking forum)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
jbkt23
DD-WRT User


Joined: 31 Dec 2018
Posts: 58

PostPosted: Sun Aug 28, 2022 22:32    Post subject: [Solved] Reply with quote
My questions have been answered so I'll leave it at that.
_________________
ARCHER-C7v5 | v3.0-r55460 std | AP Gateway
WNDR4000|v24-52189_NEWD-2_K3.x_mega|Inactive Spare
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum