Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to configure DNS over TLS in 2.4.4?

    Scheduled Pinned Locked Moved DHCP and DNS
    5 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wgstarksW
      wgstarks
      last edited by wgstarks

      I've read the Netgate blog post regarding enabling this feature in 2.4.3. At the end of the post it states that custom options will not be necessary in 2.4.4. Not exactly sure what is necessary though.

      I entered the Cloudflare and Quad9 servers in DNS Server settings.

      alt text

      I'm a little vague on what the check for DNS Resolver settings though.

      alt text

      alt text

      Box: SG-4200

      1 Reply Last reply Reply Quote 0
      • T
        TheNarc
        last edited by TheNarc

        If you want the firewall itself to only use the DNS servers that you specify in System > General, then you'll want to uncheck the "Allow DNS server list to be overridden by DHCP/PPP on WAN" option.

        For DNS over TLS, you need to put unbound into forwarding mode. Check the "Enable Forwarding Mode" and "Use SSL/TLS for outgoing DNS Queries to Forwarding Servers" options. 2.4.3 didn't have that latter check box, and instead you needed to add custom options for DNS over TLS, so that's what the post you mention was referring to.

        P wgstarksW 2 Replies Last reply Reply Quote 2
        • P
          P3R @TheNarc
          last edited by P3R

          @thenarc said in How to configure DNS over TLS in 2.4.4?:

          For DNS over TLS, you need to put unbound into forwarding mode.

          In the blog post it's specifically mentioned that forwarding mode "must be disabled".

          1 Reply Last reply Reply Quote 0
          • T
            TheNarc
            last edited by

            That's only because in the blog post, which applies to 2.4.3, you put it into forwarding mode using custom options.

            1 Reply Last reply Reply Quote 1
            • wgstarksW
              wgstarks @TheNarc
              last edited by

              @thenarc
              Thanks for the info.

              Box: SG-4200

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.