What's new

Prevent client auto DoH

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Xboxsx4life

Occasional Visitor
Hello. I'm running AX86U Pro with latest Merlin release. I've reviewed this thread...


...but I'm still not clear on the difference between "Auto" and "Yes" for the "Prevent client auto DoH" setting when using a DNS filter with DoT.

I currently have DoT enabled in strict mode with Cloudflare's resolvers. And I have Prevent client auto DoH set to "Auto". Should this be changed to "Yes"?

Capture.PNG
 
Many Asuswrt settings will display a context help popup if you click on the label:

1707424329575.png
 
Just note that DoH depends on a white/black list of hosts...
The way my Prevent auto DoH works is through the APIs used by Windows and Firefox.

In Firefox's case, it won't auto-promote to DoH if the use-application-dns.net hostname resolves to NXDOMAIN or no valid record.

In Windows' case, it works by preventing DDR (Discovery of Designed Resolver) from working:
 
Thanks for everyone’s responses. Much appreciated. Final follow up question…

How valuable would it be to enable rebind protection? I understand what it does but not sure how much additional security it would add given that it can break certain services from what I’ve read. I’m using DoT in strict mode with ‘DNSSEC’ and ‘validate unsigned replies’ both enabled. Just not sure if it’s worth enabling rebind protection too.

Thanks again.
 
Last edited:

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top