Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Request: DNSCrypt package for pfsense 3.3.3

    DHCP and DNS
    4
    4
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Mithrondil
      last edited by

      A lot of ppl ( including myself ) has been waiting for a legit and proper DNSCrypt package for pfsense for a very long time now, are there any1 news on this happening anytime soon?

      1 Reply Last reply Reply Quote 0
      • S
        swmspam
        last edited by

        Agreed. I ran DNSCrypt on my previous firewall for a long time (through OpenDNS). I would definitely install a DNSCrypt package on my pfsense.

        1 Reply Last reply Reply Quote 0
        • N
          NOYB
          last edited by

          @swmspam:

          Agreed. I ran DNSCrypt on my previous firewall for a long time (through OpenDNS). I would definitely install a DNSCrypt package on my pfsense.

          Are there any other public DNS services that support DNSCrypt?

          For something like pfSense DNS Resolver (non forwarding) don't think it would be very useful until a lot of authoritative and root DNS servers support it.

          It would be nice if the DNS was encrypted though.  The DNSSEC thing is…

          • Overly complex
          • Too many links in the chain to fail
          • Bloatware (signed zones are huge)
          • Query response packets are huge.  Consuming orders of magnitude more bandwidth.  Making them much more attractive for DNS Amplified Reflective Exploit Attack (DNS AREA).

          I'm sure that is probably just scratching the surface.  Many of you probably know much worse things about DNSSEC.

          1 Reply Last reply Reply Quote 0
          • K
            kpa
            last edited by

            There's already another thread for DNSCrypt so maybe post there instead…

            Other than that don't expect the pfSense devs to have any interest in DNSCrypt, they have already stated that they don't think DNSCrypt as a necessary addon for pfSense. However a community contributed DNSCrypt package is not outside of possiblities but someone (you?) has to step up and do the leg work.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.