• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to Use DNS Over TLS Server Option

Scheduled Pinned Locked Moved DHCP and DNS
22 Posts 7 Posters 2.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jimp Rebel Alliance Developer Netgate
    last edited by Sep 25, 2020, 5:05 PM

    I added the option I mentioned above to 2.5.0, so now all you have to do is go to System > General and set DNS Resolution Behavior to Use local DNS (127.0.0.1), ignore remote DNS Servers.

    https://redmine.pfsense.org/issues/10931

    Also cleaned up a giant mess in DNS-related code throughout the code base.

    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

    Need help fast? Netgate Global Support!

    Do not Chat/PM for help!

    1 Reply Last reply Reply Quote 2
    • P
      ProfessorManhattan
      last edited by Sep 27, 2020, 2:47 AM

      For anybody else trying to get this to work, follow this guide:

      https://docs.netgate.com/pfsense/en/latest/recipes/dns-over-tls.html

      And then if you're using systemd-resolved (Ubuntu, Arch Linux etc.), then modify /etc/systemd/resolved.conf by changing:

      #DNSOverTLS=

      To:

      DNSOverTLS=opportunistic

      Using opportunistic is the only time when I saw port 853 getting requests on the firewall. After setting it up this way, I no longer saw any requests on port 53. I tried using Stubby but was unable to get it working. The Arch Linux wiki says you're supposed to also set DNS={{ router_ip }}#router.domain.name. However, I got it working without specifying this. It may be because I used ACME to get a certificate. The hostname/domain you're using with ACME should probably match the information provided in General Setup.

      @jimp said in How to Use DNS Over TLS Server Option:

      https://docs.netgate.com/pfsense/en/latest/recipes/dns-over-tls.html

      1 Reply Last reply Reply Quote 0
      22 out of 22
      • First post
        22/22
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received