Are you running a browser where you turned on DoH? Nothing I did supports thatI've just switched over from Asuswrt-Merlin 380.70 to TLS-B6 fork of yours and this is the result:
Thanks a lot!
Are you running a browser where you turned on DoH? Nothing I did supports that
Thanks for confirming that.....just wanted to double checkI know your fork doesn't suppoer DoH (yet) I've set Firefox to use DoH for extra privacy/security.
Sharp eye When you are booting the router and the clock hasn't been set yet, you can't use TLS. So stubby first starts in normal TCP/UDP mode to allow you to resolve your NTP server, then is restarted in TLS "strict' mode when the clock is set.Hmm. I'm noticing one more thing in the log I'm curious about:
"stubby-proxy: configured no-TLS mode"
Thanks for the report! Fix writtenRT-AC66U_B1 When i set just WAN DNS servers without selecting DNSSEC it still asks to set a DoT server.
Sent from my P01M using Tapatalk
b7c5000dc webui: do not force stubby server selection if stubby not enabled
Easiest way.....the cloudfare test site works with any serverfinally installed on minethanks John.
edit: how to check if DoT is working
Thanks for the feedback and effort you put in....would still like to figure it outI invested some time in this. I started from scratch as if baking biscuits and cleared NVRAM. As I was setting up the router on 374.43_34B6j9527 from scratch I checked the log after each change, and with a clean NVRAM I do not get the log message about "syslog: password for 'admin' changed". So seems like no problemo. Thanks John for making kick butt software!
Thanks for the kind words. Things like this become like a 'quest' for me I have a hard time admitting defeat when I think I should be able to find an answer.I kept an eye on https://github.com/getdnsapi/stubby/issues/124 as you were working on it. I am so impressed with the time and effort you put into adding features and making this firmware work for all of us. Thanks a lot! I just updated to B6, and it works as expected.
Do not need the workaround as I am using the DoT with Quad9 and DNSSEC. Am questioning my use of only one server. Chose Quad9 for the supposed malware blocking but would entertain comments on this approach and recommendations from the crew...Thanks for the report! Fix written
Code:b7c5000dc webui: do not force stubby server selection if stubby not enabled
Workaroumd....
Enable DoT
Make sure at least one DoT server is selected
Disable DoT
Change any other settings, then click Apply
I’ve also been using that exact setup for the duration of the DoT betas. I tend to try to keep things simple and that setup has worked without issue so far.Do not need the workaround as I am using the DoT with Quad9 and DNSSEC. Am questioning my use of only one server. Chose Quad9 for the supposed malware blocking but would entertain comments on this approach and recommendations from the crew...
If you are using a server from one of the 'big' guys, in general you should be OK since they have redundant servers automatically.Do not need the workaround as I am using the DoT with Quad9 and DNSSEC. Am questioning my use of only one server. Chose Quad9 for the supposed malware blocking but would entertain comments on this approach and recommendations from the crew...
With this I am back to Asus from a WRT1900AC with Openwrt. Was not entirely pleased with Openwrt.
Sent from my P01M using Tapatalk
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!