Tech9
Part of the Furniture
Yes they will
Interesting. Why is this even allowed?
Yes they will
Why not?Interesting. Why is this even allowed?
There's inherently nothing wrong with that. There's no reason to assume that the router's WAN DNS servers are public servers or what the user's network topology is. Just because the average home user uses something like Google DNS doesn't mean everybody does.Interesting. Why is this even allowed?
I've seen Amazon use public DNS records that return private IP addresses for video services. VoIP services also do it sometimes. And of course services like Cloudflare and NextDNS do it when they're blocking certain domains (e.g. porn, malware, etc.). So given that this is perfectly legitimate practice it makes sense that dnsmasq has an option to choose whether of not to accept it.I understand, but we were talking about home router to public DNS like Quad9. This service is not intended for someone running a datacenter, I believe.
What's the benefit of enabling it on a home router in this case? Sound like it does more harm than good.
Sarcasm? Do you have a problem reading Wikipedia?Ah, okay... Wikipedia. Thank you.
My understanding was that the OP's issue was that he couldn't use Quad9 at all.No. What's your recommendation about this setting in this particular case - home router, Quad9? I believe it has to stay disabled given the fact it's not the only measure on a typical home network using typical home products. Not talking about business firewalls and servers.
It makes SSH management easier, yes. We had a naming scheme, so we used DNS for what it was intended to: rely on easy to remember names rather than memorizing 100+ IP addresses.This customer with >100VMs in a datacenter relies on an upstream DNS server because it was easier?
no risks, no rewards.What's the benefit of enabling it on a home router in this case? Sound like it does more harm than good.
It makes SSH management easier, yes. We had a naming scheme, so we used DNS for what it was intended to: rely on easy to remember names rather than memorizing 100+ IP addresses.
memorizing 100+ IP addresses.
Yes they will (or at least most of them do). That's the entire point of having the rebind protection option.
Not normally. Personally, I have it enabled. But if you use a DNS blocking service (like Cloudflare for Families) that returns bogus addresses for blocked domains you may see lots of false warnings in your router's system log.So is there any impact on web browsing from being enable?
Not normally. Personally, I have it enabled. But if you use a DNS blocking service (like Cloudflare for Families) that returns bogus addresses for blocked domains you may see lots of false warnings in your router's system log.
If the warnings become too much of an irritation you can either whitelist the specific domain being blocked or globally allow the bogus IP address.It makes sense what to say, because actually on some devices I have DNS from Cloudflare for Families defined by DNS Director (not for the main network) and several false warnings actually appear. So I deduce that's it.
If the warnings become too much of an irritation you can either whitelist the specific domain being blocked or globally allow the bogus address.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!