What's new

DNS not working locally for ASUSWRT (RT-AC88U)

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Darf Nader

Occasional Visitor
DNS not working locally for ASUSWRT (RT-AC88U)

I have been run ASUSWRT on a number of wifi routers using ASUSWRT for many years and have never had any problems getting local DNS to work by simply defining the hosts in the DHCP assignments GUI which uses the MAC ID to identify hosts and give them an IP. I am not sure what changed- maybe an config change I made or something that came with a firmware update, but accept for when I on the CLI for the router DNS does not work for any client on the LAN. It seems to get the correct DNS resolution info over DHCP with only the ASUSWRT router as the DNS server and correct search domain, but try to resolve the name (FQDN or otherwise) it fails. Only bonjour seems to work, but only when I specify .local after the host for hosts that explicitly advertise a bonjour address. If I connect to my router with nslookup the DNS server is functional as I can lookup any other domains. It just appears that my local domain doesn't contain any of the hosts that I have put in my list of DHCP assignments where before this was always automatic. I have not changed any of the routers DNS settings:

Enable the DHCP Server: Yes
Hide DHCP/RA queries: No
RT-AC88U's Domain Name: home
IP Pool Starting Address: 192.168.250.200 (all assigned IPs by MAC-ID are below this IP)
IP Pool Ending Address: 192.168,.250.240
Lease Time: 86400
Default Gateway: 192.168.250.1

DNS server 1 & 2 are empty
Advertise router's IP in addition to user-specified DNS: Yes
Forward local domain queries to upstream DNS: No
Enable DNSSEC support: No
Enable DNS Rebind protection: Yes (though with "No" behavior is the same

This is how I have been configured for ages though I had been using an external domain for a while and this caused problems when there was a conflict for host that is available both internally and externally, so I went with the local domain instead.

I have detailed information but it contains something that cloudflare thinks is malicious and won't let me post it, but needless to say my dnsmasq files look pretty straightforward.
 
I discovered what the cause is. I had turned on DNSFilter to see if that would help with security as I have newbs in the house now, but apparently this breaks local DNS. :(
 
I have dns filtering set so that all DNS requests originating on the LAN are routed to the RT-AC88U and have no trouble with local name resolution. I don't think that's strictly the issue. Instead of "home" for the RT-AC88U Domain Name, try "home.lan."
 
Good catch. In my case the DNS filter forces every query to go through my RT-AC88U, so local name resolution is not affected. I hadn't considered the case of forcing all queries to external DNS resolvers.
 
Makes sense. How else would DNS filtering work unless it had a local exception somehow which could used in a way to circumvent the security somehow unless you specifically specify it to do so. I will see if I can replicate the configuration so DNS security checking happens after local resolution. All of this is great info. Thanks guys.


Sent from my iPhone using Tapatalk Pro
 
You could probably just set the DNS servers you wish to use in the GUI and then use DNS filtering to force all DNS queries to the RT-AC88U. Then everyone would be resolving using the servers of your choice and local names wouldn't be affected.
 
I just updated my router RT-AC88U from the official Asus firmware to the Merlin firmware and i dont see the "DNSFilter option/settings" under the "AiProtecttion" section?

What did I do wrong?
 
I just updated my router RT-AC88U from the official Asus firmware to the Merlin firmware and i dont see the "DNSFilter option/settings" under the "AiProtecttion" section?

What did I do wrong?

It was moved under LAN a few releases ago.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top