[SOLVED] DNS issues Netgear WNDR3800 r61848

Post new topic   Reply to topic    DD-WRT Forum Index -> Qualcomm Atheros based Hardware
Goto page 1, 2  Next
Author Message
ssergey
DD-WRT User


Joined: 17 Jan 2014
Posts: 53

PostPosted: Tue Jun 24, 2025 14:14    Post subject: [SOLVED] DNS issues Netgear WNDR3800 r61848 Reply with quote
Alozaros wrote:
...
Big Thanks to Brain Slayerfor fixing devcrypto problem...and path to certificates for SmartDNS!!!

VPN client mode is fully operational again... Happy days Cool


Just hope SmartDNS stays up (doesn’t become unavailable) during extended use!!!
Sponsor
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 7063
Location: UK, London, just across the river..

PostPosted: Tue Jun 24, 2025 15:34    Post subject: Reply with quote
ssergey wrote:
Alozaros wrote:
...
Big Thanks to Brain Slayerfor fixing devcrypto problem...and path to certificates for SmartDNS!!!

VPN client mode is fully operational again... Happy days Cool


Just hope SmartDNS stays up (doesn’t become unavailable) during extended use!!!


define---> doesn’t become unavailable during extended use

In my case it is fully operational...im using DoT servers i have x3 of them all with adblock&malicious filter, but mostly is using the fastest..so, only one..as i dont want to use round robin...option...

Sadly my experience with SmartDNS... sometimes has a bitter taste...and recently there ware some updates and fixes from the upstream and some small fixes downstream...on the current build..its working so far...so good...
-recently quic support was introduced to SmartDNS...but when i tied it, it started to behave odd..as well i always run SmartDNS along with DNSmasq (the correct way).. Cool

_________________
Atheros
TP-Link WR1043NDv2 -DD-WRT 62606 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 -DD-WRT 63257 GTW/SmDNS/DoT,AD-Blk,Forced DNS,AP&Net Isolation,x2VLAN,Vanilla
Netgear R7800 --DD-WRT 62606 Gateway/DNSCryptv2,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla,VPN cli
Netgear R9000 --DD-WRT 62606 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Dynalink DL-WRX36-DDWRT 62606
Broadcom
Netgear R7000 --DD-WRT 63257 GTW/DNScrypt-proxy2/AD-Block,IPset Firewall,Forced DNS,x4VLAN,VPN cli
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
ssergey
DD-WRT User


Joined: 17 Jan 2014
Posts: 53

PostPosted: Wed Jun 25, 2025 11:30    Post subject: Reply with quote
Alozaros wrote:

define---> doesn’t become unavailable during extended use

In my case it is fully operational...im using DoT servers i have x3 of them all with adblock&malicious filter, but mostly is using the fastest..so, only one..as i dont want to use round robin...option...

Sadly my experience with SmartDNS... sometimes has a bitter taste...and recently there ware some updates and fixes from the upstream and some small fixes downstream...on the current build..its working so far...so good...
-recently quic support was introduced to SmartDNS...but when i tied it, it started to behave odd..as well i always run SmartDNS along with DNSmasq (the correct way).. Cool


Well, DNSmasq is down again. It lasted for a day.
Code:

❯ dig @195.0.1.254 -p 6053 www.google.com +short
;; communications error to 195.0.1.254#6053: timed out
;; communications error to 195.0.1.254#6053: timed out
;; communications error to 195.0.1.254#6053: timed out

root@gate:~# uptime
 14:20:21 up 1 day, 55 min,  load average: 0.03, 0.04, 0.04

only restarting the DNSmasq service helps
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 7063
Location: UK, London, just across the river..

PostPosted: Wed Jun 25, 2025 14:36    Post subject: Reply with quote
@ssergey Well...on all of my routers, i don't have any problems with DNSmasq...Very often problems occur when there is misconfiguration...as we don't know your current config, it will be pure guessing..and random shots...so provide more details...and make sure there is no rogue client in your network..

If that was a common issue, more people would complain...isn't it Cool

In fact there ware similar complains in the past all related to very heavy use of DNSmasq misconfigurated or rogue client that floods with requests...you can try to increase the concurrent requests...if so..

_________________
Atheros
TP-Link WR1043NDv2 -DD-WRT 62606 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 -DD-WRT 63257 GTW/SmDNS/DoT,AD-Blk,Forced DNS,AP&Net Isolation,x2VLAN,Vanilla
Netgear R7800 --DD-WRT 62606 Gateway/DNSCryptv2,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla,VPN cli
Netgear R9000 --DD-WRT 62606 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Dynalink DL-WRX36-DDWRT 62606
Broadcom
Netgear R7000 --DD-WRT 63257 GTW/DNScrypt-proxy2/AD-Block,IPset Firewall,Forced DNS,x4VLAN,VPN cli
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16696
Location: Texas, USA

PostPosted: Wed Jun 25, 2025 15:38    Post subject: Reply with quote
Try not specifying a port in dig. You are shortcutting dnsmasq.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
ssergey
DD-WRT User


Joined: 17 Jan 2014
Posts: 53

PostPosted: Wed Jun 25, 2025 16:32    Post subject: Reply with quote
Alozaros wrote:
@ssergey Well...on all of my routers, i don't have any problems with DNSmasq...Very often problems occur when there is misconfiguration...as we don't know your current config, it will be pure guessing..and random shots...so provide more details...and make sure there is no rogue client in your network..

If that was a common issue, more people would complain...isn't it Cool

In fact there ware similar complains in the past all related to very heavy use of DNSmasq misconfigurated or rogue client that floods with requests...you can try to increase the concurrent requests...if so..


It also seems strange to me that only I see the problem. On the other hand, the config has not been changed for many months
Code:
cat /tmp/smartdns.conf
server-name gate
bind [::]:6053
dualstack-ip-selection yes
prefetch-domain yes
serve-expired yes
log-size 32K
log-num 1
log-level warn
log-file /tmp/smartdns.log
ca-file /etc/ssl/certs/ca-certificates.crt
ca-path /etc/ssl/certs/
dualstack-ip-allow-force-AAAA yes
dualstack-ip-selection-threshold 500
server-https https://dns.quad9.net:443/dns-query -host-name dns.quad9.net -tls-host-verify dns.quad9.net -host-ip 2620:fe::fe
server-https https://dns.quad9.net:443/dns-query -host-name dns.quad9.net -tls-host-verify dns.quad9.net -host-ip 9.9.9.9


I'll try without the option now prefetch-domain

Netgear WNDR3800
DD-WRT v3.0-r61848 std (c) 2025 NewMedia-NET GmbH
Release: 06/24/25
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 7063
Location: UK, London, just across the river..

PostPosted: Wed Jun 25, 2025 16:58    Post subject: Reply with quote
may be for https try simple line like

server-https https://9.9.9.9/dns-query

or for tls

server-tls 9.9.9.9:853 -host-name dns.quad9.net -tls-host-verify dns.quad9.net

in my case prefetch domain is disabled

_________________
Atheros
TP-Link WR1043NDv2 -DD-WRT 62606 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 -DD-WRT 63257 GTW/SmDNS/DoT,AD-Blk,Forced DNS,AP&Net Isolation,x2VLAN,Vanilla
Netgear R7800 --DD-WRT 62606 Gateway/DNSCryptv2,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla,VPN cli
Netgear R9000 --DD-WRT 62606 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Dynalink DL-WRX36-DDWRT 62606
Broadcom
Netgear R7000 --DD-WRT 63257 GTW/DNScrypt-proxy2/AD-Block,IPset Firewall,Forced DNS,x4VLAN,VPN cli
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913


Last edited by Alozaros on Wed Jun 25, 2025 17:08; edited 1 time in total
ssergey
DD-WRT User


Joined: 17 Jan 2014
Posts: 53

PostPosted: Wed Jun 25, 2025 17:02    Post subject: Reply with quote
kernel-panic69 wrote:
Try not specifying a port in dig. You are shortcutting dnsmasq.


That's right, I skip dnsmasq. That's how it's supposed to be.
Dnsmasq is only for the internal zone. The idea is to keep open traffic out of the internet
MLandi
DD-WRT Guru


Joined: 04 Dec 2007
Posts: 1252
Location: Murrysville, PA

PostPosted: Wed Jun 25, 2025 17:09    Post subject: Reply with quote
Alozaros wrote:
may be for https try simple line like

server-https https://9.9.9.9/dns-query

or for tls

server-tls 9.9.9.9:853 -host-name dns.quad9.net -tls-host-verify dns.quad9.net

in my case prefetch domain is disabled


Curious, why disable prefetch, and why cache 0?

_________________
Linksys MX8500
DD-WRT v3.0-r62966 std (12/06/25)
Linux 6.6.118-rt29 #4715 SMP Sat Dec 6 10:22:51 +07 2025 aarch64

Gateway, AP, DNSMasq, SmartDNS, NSS-ECM-SFE, QCA NSS, no STP
VAP on wlan1 for internet devices
IPv4 & IPv6 (Prefix Delegation)
Static Leases & DHCP
Cloudflare DoH & DoT, No QoS, No Forced DoT, 802.11k
2.4GHz: AP, AX Only, ACK Timing 300, WPA2 & WPA3 w/AES & GCMP
5GHz: AP, AX Only, ACK Timing 300, WPA2 & WPA3 w/AES & GCMP
Netgear AX1800 WiFi Mesh Extender
Xfinity 1.2Gbps/40Mbps
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 7063
Location: UK, London, just across the river..

PostPosted: Wed Jun 25, 2025 17:11    Post subject: Reply with quote
ssergey wrote:
kernel-panic69 wrote:
Try not specifying a port in dig. You are shortcutting dnsmasq.


That's right, I skip dnsmasq. That's how it's supposed to be.
Dnsmasq is only for the internal zone


if you disable DNSmasq for DNS completely it will work to but its not advised, bear in mind DNSmasq is the backbone of DDWRT..and in certain cases its due...to be enabled...as for SmartDNS, VPN, WG and ect.

just disable the cache for DNSmasq as SmartDNS has its own cache if you need it..
in my case i use DNSmasq where i have my adblocker and SmartDNS just for encryption and it works well..as well i know other forum members that will advise the same Cool

here is a sample SmartDNS config



im usually using only tls prior to https...servers

disable prefetch - pefetch generates more DNS traffic..
DNSmasq cache is 0 to not interfere with SmartDNS cache Wink where you can control it too...

_________________
Atheros
TP-Link WR1043NDv2 -DD-WRT 62606 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 -DD-WRT 63257 GTW/SmDNS/DoT,AD-Blk,Forced DNS,AP&Net Isolation,x2VLAN,Vanilla
Netgear R7800 --DD-WRT 62606 Gateway/DNSCryptv2,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla,VPN cli
Netgear R9000 --DD-WRT 62606 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Dynalink DL-WRX36-DDWRT 62606
Broadcom
Netgear R7000 --DD-WRT 63257 GTW/DNScrypt-proxy2/AD-Block,IPset Firewall,Forced DNS,x4VLAN,VPN cli
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16696
Location: Texas, USA

PostPosted: Wed Jun 25, 2025 17:21    Post subject: Reply with quote
LAN clients hit dnsmasq first, which forwards queries to smartdns. That's how it works unless you disable dnsmasq for DNS. Anyhow, more to point, it works either way for me so we'd need your full configuration details.

EDIT: fumble fingers caps lock ... Rolling Eyes



Screenshot at 2025-06-25 12-17-17.png
 Description:
 Filesize:  63.23 KB
 Viewed:  5014 Time(s)

Screenshot at 2025-06-25 12-17-17.png



_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net


Last edited by kernel-panic69 on Wed Jun 25, 2025 17:57; edited 1 time in total
ssergey
DD-WRT User


Joined: 17 Jan 2014
Posts: 53

PostPosted: Wed Jun 25, 2025 17:36    Post subject: Reply with quote
I didn't say that I want to disable dnsmasq, it handles the internal zone.
This configuration worked for me without problems for many months.
Why should I disable dualstack if I use both protocols?
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16696
Location: Texas, USA

PostPosted: Wed Jun 25, 2025 18:05    Post subject: Reply with quote
I still don't see the full disclosure of "this configuration"... and as I've said, it works for me, but I'm not using IPv6 or dualstack. So, I'm leaning towards your IPv6 / dnsmasq configuration. Nobody is saying to disable dnsmasq or dualstack.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
ewo32
DD-WRT User


Joined: 11 Nov 2023
Posts: 203

PostPosted: Wed Jun 25, 2025 21:01    Post subject: Reply with quote
MLandi wrote:
why cache 0?

I do so because of limited RAM on MX4200 v1 : 24% free on a good day so every byte counts.
MLandi
DD-WRT Guru


Joined: 04 Dec 2007
Posts: 1252
Location: Murrysville, PA

PostPosted: Wed Jun 25, 2025 21:03    Post subject: Reply with quote
ewo32 wrote:
I do so because of limited RAM on MX4200 v1 : 24% free on a good day so every byte counts.


That I understand!

_________________
Linksys MX8500
DD-WRT v3.0-r62966 std (12/06/25)
Linux 6.6.118-rt29 #4715 SMP Sat Dec 6 10:22:51 +07 2025 aarch64

Gateway, AP, DNSMasq, SmartDNS, NSS-ECM-SFE, QCA NSS, no STP
VAP on wlan1 for internet devices
IPv4 & IPv6 (Prefix Delegation)
Static Leases & DHCP
Cloudflare DoH & DoT, No QoS, No Forced DoT, 802.11k
2.4GHz: AP, AX Only, ACK Timing 300, WPA2 & WPA3 w/AES & GCMP
5GHz: AP, AX Only, ACK Timing 300, WPA2 & WPA3 w/AES & GCMP
Netgear AX1800 WiFi Mesh Extender
Xfinity 1.2Gbps/40Mbps
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Qualcomm Atheros based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum