dns over https not getting redirected

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Wed Jun 22, 2022 20:41    Post subject: dns over https not getting redirected Reply with quote
on r49289 im testing icloud relay and to see how it works (it shouldnt) with my dns filter list. it seems icloud relay uses dns over https, and the 2 icloud relay domains mask.icloud.com and mask-h2.icloud.com are already blocked to 0.0.0.0 and ::. but my iphone can still bypass my entire blocklist if i enable icloud relay.

i already have forced dns redirection and forced dns redirection (DoT) enabled. how can i force DoH to do the same and be overridden by the local dns?

_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Sponsor
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Wed Jun 22, 2022 21:28    Post subject: Reply with quote
Afaik DNS over HTTPS bypasses some filters, e.g. host files and perhaps others.

Also what static DNS servers are you using? The must support DoH e.g. 1.0.0.1 and 9.9.9.9 do, others also, I rather peel my eye lids off rather than use google anything..

_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Wed Jun 22, 2022 22:11    Post subject: Reply with quote
cloudflare right now ipv4/6. the blocklist is handled by unbound and unbound checks local-zone before forwarding.. why im confused
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6436
Location: UK, London, just across the river..

PostPosted: Thu Jun 23, 2022 0:57    Post subject: Re: dns over https not getting redirected Reply with quote
tatsuya46 wrote:
i already have forced dns redirection and forced dns redirection (DoT) enabled. how can i force DoH to do the same and be overridden by the local dns?


It's a million dollar question !!! Laughing

I still don't get how Force DoT works...if it captures..INBOUND 853 requests...witch are encrypted...and forces them lets say trough a normal forced DNS port 53...than what? Rolling Eyes

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1931

PostPosted: Thu Jun 23, 2022 1:46    Post subject: Reply with quote
This commit only seems to apply to dnsmasq; but conditional compile options are present for smartdns and unbound in the affected file. Shouldn't dnsmasq forward requests to the proxy of choice (smartdns / unbound) or vice-versa? Visual lecture aids are welcome to explain the "problem".

https://svn.dd-wrt.com/changeset/49289

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12881
Location: Netherlands

PostPosted: Thu Jun 23, 2022 6:29    Post subject: Reply with quote
I am the author of https://svn.dd-wrt.com/changeset/49289 Smile

For Firefox Browser it is possible to signal NOT to use DoH with the help of a canary domain see:
https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet

But it can be manually overridden.

You cannot redirect DoH, your only option is to block all DoH addresses with IPSET.
The IPSET guide (a sticky in the Advanced Networking forum) has a paragraph about this.

But even then tech save users will use a proxy server they setup in the cloud or even use a VPN (you can use IPSET to block all known VPN servers), but again if they setup their own in the cloud (which is really easy and free, I am running a free Oracle Cloud server with OpenVPN and WireGuard) you are toast.

Bottom line only real thing that might work is using IPSET with a whitelist.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6436
Location: UK, London, just across the river..

PostPosted: Thu Jun 23, 2022 11:13    Post subject: Reply with quote
if im not wrong this option persist in dnscrypt-proxy v2
use-application-dns.net for force/check the use of firefox DOH..and overrides it..
if im not wrong there was a thread somewhere around DDWRT where a chap was looking for this option where you can add this in DNSmasq exactly like egc patch address=/use-application-dns.net in order to prevent the use of DOH and than you get the slap in the face with tor browsers like opera GX and others..

This reminds me, once i was called to my friend private school to consult the Internet filtering options... kids are so crafty and clever this days.. Razz Twisted Evil Twisted Evil

and yep IPset seems to be the best solution so far...even if its a bit of an effort...to deploy and set up...

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Thu Jun 30, 2022 11:16    Post subject: Reply with quote
TBH unless you need your specific icloud relay for something it maybe easier to just not use it.

icloud sounds like something Apple, just thinking about it I get a rash.

_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum