What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

RT-AX82U DNS OVER TLS

tiomiguel

Regular Contributor
Anybody know if this service works in RT-AX82U or similar routers. I have configured bur wireshark does no show TLS... but, is conveniente use thsi security layer or better use DNS plain. I use adguard family DNS long tiem ago...
 
Asus routers do not block outbound traffic. So your clients should be able to connect to public DoT servers on port 853 if they are configured to do so.

Asus routers running stock firmware do not support DoT for their own DNS. Merlin/GNUton firmware does provide DoT support on the router.
Not true. Most Asus routers do support DoT.
 
DOT configured but it seems is not working
Captura de pantalla 2025-08-26 014347.png

configured but not working

Captura de pantalla 2025-08-26 014714.png

Captura de pantalla 2025-08-26 014659.png
 
When using DoT disable DNSSEC You do not need both.
 

ASUS RT-AX82U – Secure DoT (DNS-over-TLS) Setup with AdGuard Family​


1. WAN DNS Settings​


  • DNS ServerLeave blank
    (If you put IPs here, the router may bypass DoT and use plain DNS over UDP/53.)

GPT say this...
 
DOT does not override regular DNS. If you manually query a standard public DNS server, then you will be doing just that. Only queries sent to the router (which should be the default DNS for your LAN clients) will use DOT when being sent upstream- and Wireshark would need to monitor the traffic between the router and the ISP, not between the clients and the router.
 
since we're on the subject, let me (nyc) know if i did anything
wrong here or there is room for improvement.
according to various tsl test sites, tsl seems to be working fine.
i leave everything ipv6 = disabled and blank.
 

Attachments

  • mydnsovertsl.jpg
    mydnsovertsl.jpg
    51.8 KB · Views: 25
if i did anything wrong here or there is room for improvement
If you trust Cloudflare and Quad9 to validate DNSSEC for you on their end, you can disable DNSSEC on the router.

You only get malware protection from Quad9 50% of the time since you alternate with an unfiltered Cloudflare service. Consider using 1.1.1.2 if you want malware protection all the time.
 
since we're on the subject, let me (nyc) know if i did anything
wrong here or there is room for improvement.
according to various tsl test sites, tsl seems to be working fine.
i leave everything ipv6 = disabled and blank.
Use Quad9 or Cloudflare Security but not both at the same time.

Cloudflare Security is 1.1.1.2 and 1.0.0.2. TLS Hostname: security.cloudflare-dns.com. This is a manual input to the Asus DoT settings.

I find that Cloudflare Security is more reliable than Quad9 in my area when using DoT.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top