What's new

DNS/TLS IPv6.

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Analog-1

Regular Contributor
Is this still valid in 2024 ? Is there any security issues with this method and how does it work.


IMPORTANT: for DNS Privacy to work in IPv6, you must set IPv6 DNS Server in IPv6 page (not equivalent to add IPv6 DoT servers on the WAN -> Internet Connection page) to your router's LAN IPv6 Link-Local Address. You can find your router's LAN IPv6 Link-Local Address in System Log -> IPv6 tab. Link-local address starts with fe80.
 
I was running this setup with Quad9 until recently and it worked well. I disabled IPv6 because my ISP uses a slow 6RD tunnel.
 
Is this still valid in 2024 ? Is there any security issues with this method and how does it work.


IMPORTANT: for DNS Privacy to work in IPv6, you must set IPv6 DNS Server in IPv6 page (not equivalent to add IPv6 DoT servers on the WAN -> Internet Connection page) to your router's LAN IPv6 Link-Local Address. You can find your router's LAN IPv6 Link-Local Address in System Log -> IPv6 tab. Link-local address starts with fe80.
Well, you still need to set the IPV4 and IPV6 DNS resolvers in their respective locations then set up DoT. I recommend alternating IPV4 DoT resolvers with corresponding IPV6 DoT resolvers. So you will end up with four entries in DoT and your queries will, alternate between all four in turn.
 
Is this still valid in 2024 ? Is there any security issues with this method and how does it work.


IMPORTANT: for DNS Privacy to work in IPv6, you must set IPv6 DNS Server in IPv6 page (not equivalent to add IPv6 DoT servers on the WAN -> Internet Connection page) to your router's LAN IPv6 Link-Local Address. You can find your router's LAN IPv6 Link-Local Address in System Log -> IPv6 tab. Link-local address starts with fe80.
I had not come across this, so I tried it and IPv6 seem to work the same as when using external (OpenDNS) IPv6 DNS servers. Given that all client (rather than router) DNS lookups go though Unbound (scripts used are in my signature) I don't see if or why this might my improve(worsen) my setup, or how I could test it.
 
I was testing this last night. I removed the DNS settings from both the WAN and IPv6 page. Then setup to force DoT in strict mode. It still works and is actually much more fast and stable then it was before.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top