Using the latest Merlin beta firmware on an AC68 and trying to install DNScyrpt. Used the instructions here:
https://github.com/RMerl/asuswrt-merlin/wiki/Secure-DNS-queries-using-DNSCrypt
Went through each step. Everything seemed fine. I stopped the proxy (said stopped) tried the ping against bing.com, nothing. Started the proxy (said running), tried the ping again, nothing. Here are the logs showing this event:
dnscrypt-proxy[1036]: Stopping proxy
dnscrypt-proxy[1036]: UDP listener shut down
dnscrypt-proxy[1036]: TCP listener shut down
admin: Started from .
dnscrypt-proxy[2788]: Starting dnscrypt-proxy 1.9.5
Generating a new session key pair
dnscrypt-proxy[2788]: Done
dnscrypt-proxy[2788]: Server certificate with serial #1498586461 received
dnscrypt-proxy[2788]: This certificate is valid
dnscrypt-proxy[2788]: Chosen certificate #1498586461 is valid from [2017-06-27] to [2017-06-28]
dnscrypt-proxy[2788]: Server key fingerprint is 0BC9... big long number
Proxying from 127.0.0.1:65053 to 185.133.72.116:443
When I check my DNS it is using some servers in New Jersey (should be in EU). I still have WAN DNS boxes filled in with google dns; LAN DHCP DNS boxes are blank with 'forward router IP' set on and 'DNSsec enable' set off. I use Hurricane Electric for IPV6 and those servers seem to show up - there are three nameserver entries in the logs after reboot, the two IPV6 servers and a 127.0.0.0 entry.
Oddly I can't find the dnscrypt.proxy.options (not under /jffs/configs or /etc). I'm starting this thread because the old thread is a bit dated. Also, if I can get this thing working (my ISP hijacks), I'd also like to know how to add additional DNScrypt servers (where is that conf file?). Thanks in advance.
https://github.com/RMerl/asuswrt-merlin/wiki/Secure-DNS-queries-using-DNSCrypt
Went through each step. Everything seemed fine. I stopped the proxy (said stopped) tried the ping against bing.com, nothing. Started the proxy (said running), tried the ping again, nothing. Here are the logs showing this event:
dnscrypt-proxy[1036]: Stopping proxy
dnscrypt-proxy[1036]: UDP listener shut down
dnscrypt-proxy[1036]: TCP listener shut down
admin: Started from .
dnscrypt-proxy[2788]: Starting dnscrypt-proxy 1.9.5
Generating a new session key pair
dnscrypt-proxy[2788]: Done
dnscrypt-proxy[2788]: Server certificate with serial #1498586461 received
dnscrypt-proxy[2788]: This certificate is valid
dnscrypt-proxy[2788]: Chosen certificate #1498586461 is valid from [2017-06-27] to [2017-06-28]
dnscrypt-proxy[2788]: Server key fingerprint is 0BC9... big long number
Proxying from 127.0.0.1:65053 to 185.133.72.116:443
When I check my DNS it is using some servers in New Jersey (should be in EU). I still have WAN DNS boxes filled in with google dns; LAN DHCP DNS boxes are blank with 'forward router IP' set on and 'DNSsec enable' set off. I use Hurricane Electric for IPV6 and those servers seem to show up - there are three nameserver entries in the logs after reboot, the two IPV6 servers and a 127.0.0.0 entry.
Oddly I can't find the dnscrypt.proxy.options (not under /jffs/configs or /etc). I'm starting this thread because the old thread is a bit dated. Also, if I can get this thing working (my ISP hijacks), I'd also like to know how to add additional DNScrypt servers (where is that conf file?). Thanks in advance.