Jack-Sparr0w
Senior Member
No problem using this in config file with vpn atm
use-caps-for-id: yes (don't use if you are using pi-hole)
harden-referral-path: yes
harden-algo-downgrade: yes
harden-large-queries: yes
harden-short-bufsize: yes
val-clean-additional: yes
harden-dnssec-stripped: yes
unwanted-reply-threshold: 5000000
jostle-timeout: 200 (North America) helps with dos attack
sock-queue-timeout: 3
discard-timeout: 1900 use 3000 if you bind VPN
qname-minimisation-strict: yes
infra-cache-numhosts: 20000 or 40000 ax 88u
harden-unknown-additional: yes
hide-trustanchor: yes - don't use vlan or VPN with this as some VPNs need this
hide-http-user-agent: yes - don't use vlan or DoT with this
use-caps-for-id: yes (don't use if you are using pi-hole)
harden-referral-path: yes
harden-algo-downgrade: yes
harden-large-queries: yes
harden-short-bufsize: yes
val-clean-additional: yes
harden-dnssec-stripped: yes
unwanted-reply-threshold: 5000000
jostle-timeout: 200 (North America) helps with dos attack
sock-queue-timeout: 3
discard-timeout: 1900 use 3000 if you bind VPN
qname-minimisation-strict: yes
infra-cache-numhosts: 20000 or 40000 ax 88u
harden-unknown-additional: yes
hide-trustanchor: yes - don't use vlan or VPN with this as some VPNs need this
hide-http-user-agent: yes - don't use vlan or DoT with this
Last edited: