What's new

SOLVED: Help: Diversion, DNSCrypt-Proxy; client exclusion

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

gspannu

Senior Member
Need some assistance with my setup..

RT-AX88U running Diversion & DNSCrypt-Proxy

Requirements:
- All of my clients to go through DNSCrypt & Diversion Ad-Blocking
- 2 of my clients to totally bypass Diversion, but still use DNSCrypt.

On searching the forums and Diversion website; there is a suggested solution listed on Diversion FAQ here
.... It says that I set the DNS to 8.8.8.8, ... but I want the excluded clients to still use DNSCrypt-Proxy

How to exclude a client from ad-blocking
In your router Web-UI, go to DNS-Filtering
- set 'Enable DNS-based Filtering' to ON
- set 'Global Filter Mode' to 'NO filtering'
- fill in 'Custom (user-defined) DNS 1' with, for example, Google's DNS 8.8.8.8
- select your client(s) in the Client List and set 'Filter Mode' 'Custom 1'
- click Apply

Now the client(s) in the Client list get the DNS from google and not from your router.

Q: What settings do I put in the DNS Filter section (or elsewhere)?

Seeking advise...
 
I think in general terms you need DNSCrypt-Proxy to also listen on a secondary LAN address (e.g. 192.168.50.2:53) and put that 50.2 address in DNSFilter as a custom entry. I don't use DNSCrypt to tell you how, but if you go to that thread and ask @SomeWhereOverTheRainBow or @Zastoff for help, I'm sure they could better than I.
 
I think in general terms you need DNSCrypt-Proxy to also listen on a secondary LAN address (e.g. 192.168.50.2:53) and put that 50.2 address in DNSFilter as a custom entry. I don't use DNSCrypt to tell you how, but if you go to that thread and ask @SomeWhereOverTheRainBow or @Zastoff for help, I'm sure they could better than I.

Thank you, I will check the DNSCrypt-proxy.toml file and see what is the IP address listed there and see if this works. My guess is that the IP address listed there will be 127.0.0.0:53 - so don't understand how this will work.

In addition, I have also posted in the thread you suggested and asked the 2 giants for help.
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top