Swistheater
Very Senior Member
the only reason a person should be concerned that it wasn't working is if there was no connection, you can check this with stubby -l, which means your servers are not setup right.
OK thanks, that's what I thought... I'll fire up that ancient laptop of mine and play with wireshark (I prefer the interface lol).opkg install tcpdump
tcpdump -i eth0 port 53<------- this would show you any traffic that was being passed that was not connected via DoT "lets say for example you used DNSFILTER to use a different server for a specific device"
this would show the traffic of that one device.
tcpdump -i eth0 port 853<-------- This shows all traffic concerned with the DoT connected devices.
I understand... I get nervous when I pull out the ol'wireshark.... you never know what you will find.OK thanks, that's what I thought... I'll fire up that ancient laptop of mine and play with wireshark (I prefer the interface lol).
Right jsbeddow, but I think our reliance on the cf help page was hinging on not using 'strict' dnssec validation... which as rmerlin said before there's no point in using dnssec if it isn't strict. So now we swallow the red pill, and must know it is more complicated than we all thought, but for a good reason.
I notice that enabling this D0T feature slows down (creates a pause) between the time you request a page and the page displays. Does anyone else experience that?Looks good to me!
Sent from my iPhone using Tapatalk
I notice that enabling this D0T feature slows down (creates a pause) between the time you request a page and the page displays. Does anyone else experience that?
Anton
I notice that enabling this D0T feature slows down (creates a pause) between the time you request a page and the page displays. Does anyone else experience that?
Anton
Set that client to use "Router" instead on the DNSFilter rules.
Merlin is correct 100 percent. Router forces the dot to be used on that device. You can globally specify router for all devices and make rules to specifically require certain devices to use other servers if you do not want them on DoT server. ---this would be devices that may be required to be on isp servers or maybe they require certain filtering like open dns provides.
If you assign Quad9 in DNSFilter, even though it supports DoT, DNSFilter is still only passing old fashioned DNS over 53/udp.
I wonder if they are hearing the complaints in here. Think we should ping them about this?...more and more complains will arise.
No, actually I noticed my internet started acting snappier after I started using DoT+cloudflare a few weeks ago. I was using google dns with dnssec before that. I am in California though... YMMV with cloudflare depending on where you are on the globe. As rmerlin mentioned, you may be able to improve performance by picking servers that are located closer to you.I notice that enabling this D0T feature slows down (creates a pause) between the time you request a page and the page displays. Does anyone else experience that?
Anton
I wonder if they are hearing the complaints in here. Think we should ping them about this?
For a router in AP mode, what should I select for the LAN DNS servers to get DNSSEC+DoT on devices connected to the AP?
YMMV with cloudflare depending on where you are on the globe.
Yes on ap set lan dns to 192.168.1.1 (your main routers ip) or leave it as automatic
It won't help the connection, unless your ISP has bad packet routing there is not much else that can be done short of getting a faster connection or an ISP with better international routing or backhaul bandwidth during peak hours.@RMerlin dumb question, I do alot online gaming thru PS4/Xbox via WiFi (yes not the best setup). Wld messing with any of these settings i.e. DNS over TLS mess with lag while playing say CoD4? Just curious as I tend to keep my settings defaulted while running your FW. I am running FreshJr script which has completely minimized any lag while playing on WiFi. Also currently I don't use the stubby script. But I use diversion, skynet and pixelserv-tls.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!