Firewalla DNS Services

Follow

Comments

5 comments

  • Avatar
    Pat Dwyer

    Nice guide. Where do I make these setting elections?

    0
    Comment actions Permalink
  • Avatar
    Peter Guyton

    Great guide. On the "3. A quick comparison of DNS services" I have a suggestion. 

    For for "Unbound" I believe it makes sense to add the same footnote "1" next to the word "No" in column "Reduce Tracking (ISP)" as you did in the "Data Encryption" column.  I believe 'DNS over VPN' will reduce ISP tracking.

    Or better yet, It might make sense to add another row called "Unbound w/DNS over VPN" then change the second and forth columns to 'yes'. 

    0
    Comment actions Permalink
  • Avatar
    Joseph Lim

    Hi, I have added a Custom DNS Rules to resolve my internal service app.  I have my laptop DNS pointing to my Firewalla Gold SE ip address.  After adding the DNS rules, i still couldn't resolve the name.  Is there anything i'm missing ?

    0
    Comment actions Permalink
  • Avatar
    Ethan Romero

    I have run into an issue where I am working towards obtaining my Offensive Security Certified Professional certification where in the course work you'll utilize an AWS DNS instance and have found that utilizing a Kali Virtual Machine in VMWare Pro and adding the AWS DNS nameserver to my /etc/resolv.conf and restarting the appropriate service won't connect to the appropriate DNS host in any of the situations listed in Firewalla's DNS strategies.  If i add the DNS host via a Custom DNS Rule, it still does not work.  I have to place the Virtual Machine in Firewalla's "Emergency Access" for the DNS to respond correctly. 

    Is there a way to chase down the specific problem to add a firewall allow rule or appropriate custom DNS rule to get this to work without going to Emergency Access?

    0
    Comment actions Permalink
  • Avatar
    Geo

    Support Support Team

    Need deeper clarification on the Unbound + DNS over VPN. Please

    Basically I want Unbound  + DNS over VPN for ALL my devices INCLUDING ones that I have setup on a FULL 3rd party VPN Client. 

    The bulk of the confusion is what should the VPN Client FORCE DNS over VPN be set to ON or OFF when used with Unbound  + DNS over VPN?

    How do I do this? I have Proton VPN and able to have multiple active setups/connections.

    So obviously I have Services > Unbound ON.
    And of course DNS over VPN > Proton (my VPN Client Proton-1.conf).

    Q 1 - Now inside my VPN Client (the one selected/used above - Proton-1.conf).
    Do I turn ON/OFF FORCE DNS over VPN when used with the DNS over VPN > Proton setting above?

    Q 2 - Same basic question... what changes (if any do) I need to make in my Proton-2.conf which is for my few FULL VPN (Browser and DNS w/ Unbound). I want these to use Unbound + DNS over VPN (the VPN connection/conf does not matter to me). I assume best to create separate ones depending on your answer if they need different settings.

    I've read everything and you have done a great job with documentation as always!
    But I am not 100% on this fringe case and its hard to test due to Unbound mixing things up. And even more confusing since I need to do this for all my Firewalla clients both on and off a VPN client for browsing.

    I hope this make sense.
    Thank you!


     

     

    * Technically I have it setup as Unbound + DNS over TLS. 
    https://help.firewalla.com/hc/en-us/community/posts/15281951152531-Encrypt-your-DNS-with-TLS-aka-DoT
    https://github.com/upmcplanetracker/firewalla-unbound-DoT-config

    0
    Comment actions Permalink

Please sign in to leave a comment.