Okay, DoT is now turned off permanently. This way DNS name lookups always works, and the site I mention above somewhere works 100% of the time. Problem solved - and anyone that like to guess why DoT does not work can do so - but it will be without my help.
PS! Anyone trying to convince me the...
I have to say no on that - at the point when you select what kind of "BankID" you like to select for starting the login process has not started at all. And, again, it works after switching DoT Off and then ON again - if "BankID" would be that problem you suggests, then it would not work. And yet...
YOU seem to miss the problem: as I mentioned the issue here is that when one turns OFF DoT and then back ON, it works - every single time. And if I use for example my mobile phone, disconnects it from WiFi supplied by my AX88, the web page comes up every single time - that is over my mobile...
DoT Problem - still :) after upgrade to 384.15 on my AX88...
So I have one web site that never works for DoT access. Well it works for "some" time, then it starts failing again.
Can someone somehow validate if this is something special just for me, or something DoT that may or may not work...
Google DoT works....
And now that I changed back to Cloudflare this works again. I am back at the privious config that did not work, and now it works.....
Have to reopen this....
Changed to Cloudflare, and thought that would solve this. It did not.
If I use 1.1.1.1 / 1.0.0.1 as static DNS, and not using DoT, it works.
Turning on DoT, Cloudflare, I still are refused to get login003.stockholm.se resolved.
Since 1.1.1.1 and cloudflare-dns.com...
Well which broser is used, if it is for example Firefox and it uses it own DoT (DNS over TLS) and if not configured correct this would mean, if I understand this correct, that Diverson on the router would be bypassed?
And what was wrong? DNS-over-TLS was on, and that made connections from client to not work, but it did work from Asus router.
Still do not get why that kind of did not work, why is the router using different DNS method/connection instead of the DoT setup?
That is a very good question, and the result is:
Windows:
C:\>nslookup login003.stockholm.se
Server: router.asus.com
Address: 10.168.1.1
*** router.asus.com can't find login003.stockholm.se: Server failed
Linux/Ubuntu 18.04LTS:
> nslookup login003.stockholm.se
Server: 127.0.0.53...
So I can ping
login003.stockholm.se
on my AX88 router - works perfect. GUI and commandline, both works just great.
However my clients, windows/linux/android, can not.
I use Diverson and Skynet - both are disabled !
It does not matter, on the router I can, on the clients I can not...
So why I...
You would need something that can identify signatures of IP traffic (snort?) to be able to block stuff like freegate (and all other proxy based web solutions). Freegate (dynaweb) let's a user who browses to there web page to surf internet thru proxys, so in a way you are running a TOR network...
Ohh Apple - no no not a device I like ;)
I tried "arp -a" - and got the same list as in the web gui for the router (AX88).
So I send an email to the manufacture, well it just swaped owner so in the end I got in contact with the new owner, a Mr Mansour Mamaghani, a very nice and friendly owner...