Encrypt your DNS with TLS aka DoT

Comments

7 comments

  • Avatar
    Chris Hewitt

    Kind of defeats the purpose to use googles DNS and let them collect all the sites you’re going to. That’s why I do nothing but use unbound now.

    I also suggest using dnsleaktest.com to see who can observe your DNS queries. The best results, like the example below, are when only you ( your IP address) knows about your DNS queries.

    0
    Comment actions Permalink
  • Avatar
    JD Brookins

    Very interesting. Kinda of getting the best of both worlds here being that quad9 uses unbound. How will this affect firewalla's other features?

    0
    Comment actions Permalink
  • Avatar
    Chris Hewitt

    Three years not a single negative effect. I also monitor my Gold Plus with bpytop.

    0
    Comment actions Permalink
  • Avatar
    JD Brookins

    That's good to know. Thanks!

    0
    Comment actions Permalink
  • Avatar
    JD Brookins

    Now that I'm at my box. I can't seem to write the file. I get a "E212: Can’t open file for writing" error. I put sudo before the command. Am I missing something?

    0
    Comment actions Permalink
  • Avatar
    AZ

    JD Brookins you do need sudo there.  Make sure you are in the right directory.  Without sudo vi will throw those errors.

    Also just FYI theDude you can use 3 or even more DNS resolvers in the conf file.  Unbound will do some combination of randomly picking one plus some load balancing/favoring faster responding resolvers.  So having at least 2 will get rid of any chance that the one DNS you are relying on is totally down.  (which, admittedly, is a very very tiny chance)

    0
    Comment actions Permalink
  • Avatar
    theDude

    Glad you guys are finding this useful... Initially I was coming from a pfsense setup, and I wanted to replicate my DNS config to the firewalla.  I was also hoping that firewalla would eventually just make DNS over TLS a toggle switch option within the app.
    There are definitely numerous use case scenarios, hopefully this guide either provided exactly what you needed, or at least gave you a very good start. 

    0
    Comment actions Permalink

Please sign in to leave a comment.