SMARTDNS Guide

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Goto page Previous  1, 2, 3 ... 7, 8, 9 ... 18, 19, 20  Next
Author Message
strange
DD-WRT User


Joined: 18 Jun 2006
Posts: 229

PostPosted: Sun Jun 12, 2022 22:40    Post subject: Reply with quote
I guess that I am ignorant, is there a reason that I should not trust my VPN's DNS? Couldn't I just remove it's line from the SmartDNS options?
server-tls x.x.x.x:853 -host-name: xxxxxx

_________________
Netgear XR500 - Gateway
R6700 v3 - Station Bridge
Sponsor
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6445
Location: UK, London, just across the river..

PostPosted: Mon Jun 13, 2022 7:44    Post subject: Reply with quote
I prefer to use another DNS different than this one parsed from the VPN provider due to a few reasons...more likely i don't want to provide them with history where i go and what i visit..although they will know it anyway...

server-tls x.x.x.x:853 -host-name: xxxxxx
no idea what is this line but this is the standard format to use DNS over TLS via SmartDNS...if this is the VPN DNS parsed to SmartDNS automatically(i doubt)...the better way to not use VPN DNS is via those lines i offered...

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
strange
DD-WRT User


Joined: 18 Jun 2006
Posts: 229

PostPosted: Mon Jun 13, 2022 15:27    Post subject: Reply with quote
Alozaros wrote:
I prefer to use another DNS different than this one parsed from the VPN provider due to a few reasons...more likely i don't want to provide them with history where i go and what i visit..although they will know it anyway...

server-tls x.x.x.x:853 -host-name: xxxxxx
no idea what is this line but this is the standard format to use DNS over TLS via SmartDNS...if this is the VPN DNS parsed to SmartDNS automatically(i doubt)...the better way to not use VPN DNS is via those lines i offered...


Thank you

_________________
Netgear XR500 - Gateway
R6700 v3 - Station Bridge
tcpud
DD-WRT Novice


Joined: 23 Jun 2022
Posts: 12

PostPosted: Thu Jun 23, 2022 13:47    Post subject: Reply with quote
I have read this page and the wiki for the app.
I undertood the format for tls to be used in the text box.

May I clarify the format for the DoH DNS servers for the additional settings:

I tried:

server-https https://family.cloudflare-dns.com/dns-query :443

and
server-https 1.1.1.1: 443 -host-name :family.cloudflare-dns.com/dns-query

but neither of them work?
tcpud
DD-WRT Novice


Joined: 23 Jun 2022
Posts: 12

PostPosted: Thu Jun 23, 2022 17:27    Post subject: Reply with quote
to add i am using todays bulit on R7800.

I read this again : https://pymumu.github.io/smartdns/ReadMe_en.html and tried the below unsuccessfully:




Anyone knows in that format for DoH DNS to enter in addtional samrt DNS settings[/img]
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6445
Location: UK, London, just across the river..

PostPosted: Thu Jun 23, 2022 18:55    Post subject: Reply with quote
-do you have a dns without those rules...

-did you click at force DoT box...form basic set up page...untick that...

-do you have in advanced DNSmasq a server= [loopback interface] [smart dns port used]

-have you read the set up guide in the thread...

also today build will sound today build even after 10 years
not bad to mention the build number as today build is 49326
Laughing Laughing

did you try DNS over TLS instead..
server-tls 1.0.0.1:853 -host-name: security.cloudflare-dns.com
server-tls 1.0.0.2:853 -host-name: security.cloudflare-dns.com
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 149.112.112.112:853 -host-name: dns.quad9.net

or just
server-tls 9.9.9.9:853


as i haven't tested the new updated SmartDNS nor i tested via DOH yet...

https://svn.dd-wrt.com/browser/src/router/smartdns/etc/smartdns/smartdns.conf

server-https https://dns.quad9.net/dns-query
server-https https://cloudflare-dns.com/dns-query

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
tcpud
DD-WRT Novice


Joined: 23 Jun 2022
Posts: 12

PostPosted: Thu Jun 23, 2022 19:33    Post subject: Reply with quote
Thank you for responding Smile

I have DNS with TLS
The TLS resolution has been flawless with these
server-tls 1.0.0.1:853 -host-name: security.cloudflare-dns.com
server-tls 1.0.0.2:853 -host-name: security.cloudflare-dns.com
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 149.112.112.112:853 -host-name: dns.quad9.net

I have server=127.0.0.1:53 in DNSmasq options

No resolution, When trying any of the above DoH addrress.
Do they need to be entered in some other format?
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1952

PostPosted: Thu Jun 23, 2022 19:57    Post subject: Reply with quote
Reading here:
wabe wrote:
Smartdns listen to 127.0.0.1:6053 and added to dnsmasq.conf when smartdns is enabled

and here:
TCB13 wrote:
server=127.0.0.1#6053

leads me to believe your configuration is the problem.

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
tcpud
DD-WRT Novice


Joined: 23 Jun 2022
Posts: 12

PostPosted: Thu Jun 23, 2022 20:41    Post subject: Reply with quote
this is how it is after server=127.0.0.1#6053
But why is then tls resol by smartdns is fine and only Doh is not reachable?
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1952

PostPosted: Thu Jun 23, 2022 21:06    Post subject: Reply with quote
My best educated guess:

https://svn.dd-wrt.com/changeset/49289

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
tcpud
DD-WRT Novice


Joined: 23 Jun 2022
Posts: 12

PostPosted: Thu Jun 23, 2022 21:28    Post subject: Reply with quote
If I understood correctly,we can only use TLS and DoH is unworkable in smart DNS. Thanks
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12909
Location: Netherlands

PostPosted: Fri Jun 24, 2022 12:01    Post subject: Reply with quote
I just added to SmartDNS additional options:
server-https https://1.1.1.1/dns-query

and Cloudfare seems to resolve my DNS queries

and this is my only DNS server:
smartdns.conf:
Code:
bind :6053
prefetch-domain yes
serve-expired yes
log-size 64K
log-num 1
log-level error
log-file /tmp/smartdns.log
log-level  debug
server-https https://1.1.1.1/dns-query
audit-enable yes
audit-file /tmp/smartdns-audit.log


Not saying everything is hunky-dory as I cannot get the stupid thing to log anything yet.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12909
Location: Netherlands

PostPosted: Fri Jun 24, 2022 13:59    Post subject: Reply with quote
SmartDNS userguide attached

Note:
I am not an expert in these matters at all!
Just an ordinary but very smart DDWRT user Very Happy

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
tcpud
DD-WRT Novice


Joined: 23 Jun 2022
Posts: 12

PostPosted: Fri Jun 24, 2022 16:07    Post subject: Reply with quote
Smile Thank you so much. With the above format (relacing https address in words with numbers) as advised by @egc all DNS servers DoH queries are resolved.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12909
Location: Netherlands

PostPosted: Fri Jun 24, 2022 16:23    Post subject: Reply with quote
tcpud wrote:
Smile Thank you so much. With the above format (relacing https address in words with numbers) as advised by @egc all DNS servers DoH queries are resolved.


Great, to hear.

I actually like this, it lets you easy use DoH and/or DoT while still using DNSMasq

Now looking into how to get this stupid thing output any logs, or am I the only without logs?
(cat /tmp/smartdns.log should show you the log)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Goto page Previous  1, 2, 3 ... 7, 8, 9 ... 18, 19, 20  Next Display posts from previous:    Page 8 of 20
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum