Could someone test to see if it works with Cleanbrowsing Adult?
https://cleanbrowsing.org/guides/dnsovertls
https://cleanbrowsing.org/guides/dnsovertls
Yes, it works adding the IP and name directly in the list. Also worked with DNSSEC enabled. Could not browse to playboy.com or youporn.com (not that I ever heard of those sites before).Could someone test to see if it works with Cleanbrowsing Adult?
https://cleanbrowsing.org/guides/dnsovertls
I discovered this morning that a stubby.yml in /jffs/configs will not work on reboot. stubby.yml.add does not work either.EDIT: BTW, providing a replacement stubby.yml will fail at boot because it needs to be told NOT to enforce TLS at boot time. If you just copy a stubby.yml config with TLS enabled, then your ntp will fail to synchronize the clock, as TLS cannot work until the clock is set. I will probably remove support for replacing stubby.yml for this reason, leaving postconf and .add only.
Want to share the contents? I could test. We’ve learned how finicky yml can be.stubby.yml.add does not work either.
Contents:Want to share the contents? I could test. We’ve learned how finicky yml can be.
I had this issue before but I got it working now.I discovered this morning that a stubby.yml in /jffs/configs will not work on reboot. stubby.yml.add does not work either.
I would really like the ability to modify stubby so I can run DNSSEC from stubby and modify other settings such as round_robin. I do feel that running DNSSEC from dnsmasq with static root keys can lead to issues when the resolver providers decide to change the keys. I do not share your security concern over dynamically retrieved keys.
Btw you need to name it stubby.add not stubby.yml.add. Then make it executable likewise with stubby.ymlI discovered this morning that a stubby.yml in /jffs/configs will not work on reboot. stubby.yml.add does not work either.
I would really like the ability to modify stubby so I can run DNSSEC from stubby and modify other settings such as round_robin. I do feel that running DNSSEC from dnsmasq with static root keys can lead to issues when the resolver providers decide to change the keys. I do not share your security concern over dynamically retrieved keys.
Make it just stubby.add and it works.Contents:
dnssec_return_status: GETDNS_EXTENSION_TRUE
tls_min_version: GETDNS_TLS1_3
Am considering a script that copies a "good" stubby.yml to /jffs/configs after the router is up, restarts stubby then deletes the file from /jffs/configs.
Yes! Works.Make it just stubby.add and it works.
For your consideration: Forced NTP redirection has been a huge benefit for me. Some devices (like TiVo) have no configuration for NTP server, yet benefit greatly from accurate time. TiVo NTP servers are always off a few seconds, messing up all my recordings. Since installing ntpMerlin, my recordings have been dead-on.I'll have to think some more about it. I'm not totally opposed to it, just... reluctant at this time.
I noticed it was stubby.add instead of stubby.yml.add because stubby.postconf and not stubby.yml.postconfMake it just stubby.add and it works.
IMHO, it should include the yml for consistency, like dnsmasq.conf.add and to be consistent with John’s fork.
When you decide to make changes using these features you should do service restart_dnsmasq. Wait a good 15 minutes to see it be stable-- then move on to test if it is stable via reboot.Yes! Works.
Also added round_robin_upstreams: 0 which added a second entry to stubby.yml but it seems to work ...
service restart_stubbyWhen you decide to make changes using these features you should do service restart_dnsmasq. Wait a good 15 minutes to see it be stable-- then move on to test if it is stable via reboot.
I use dnsmasq incase you include a dnsmasq.conf.add as wellservice restart_stubby
Sent from my SM-T380 using Tapatalk
I was also unable to access the GUI after flashing alpha4. AC3100
When I look in the logs, the time sync and WAN up log entries don't take place until the very end of the boot. The log entries are literally right before the end of the reboot process. The probable reason for my OVPN Server or Client not starting is not having a WAN connection and or NTP update. I DO NOT have any special scripts running. Only the stuff in my signature, there are no other custom mods. I have deliberately kept things simple too get to the bottom of the issue. You didn't say how things went when you tried the OVPN Server starting at reboot. I am unable to find any problems in the logs. The only entry I found was:Works for me. I just setup a router with a PIA OpenVPN client set to connect at boot, and DNS over TLS enabled. On a reboot everything was started normally.
VPN clients don't get started until after the WAN comes up.
Check what customization you have in place. Also check your boot log for any error message during boot.
May 4 23:05:11 WAN_Connection: Ethernet link down.
May 4 23:10:19 Skynet: [*] NTP Failed To Start After 5 Minutes - Please Fix Immediately!
can someone using .11 confirm this is fixed on ac3100
3.0.0.4.384.5951
Bug Fix
- Fixed Network Map related issues.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!