Adguard Home on a VPS working, but no DoH for my home network

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Adguard Home on a VPS working, but no DoH for my home network

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Adguard Home on a VPS working, but no DoH for my home network
Adguard Home on a VPS working, but no DoH for my home network
2022-07-12 21:13:24
Tags: #doh
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.0.1

I have set up Aduard Home on a Gcloud server and have it set up with a 3rd party ssl cert. I enabled DoH/DoT and I can see my phone is using DoT when I check the queries. My home network however is using plain DNS. Normally that would be fine, but the ADH is external so I would like the connection to be secure.

 

I am using an ER605 v2 on 2.0.1 and I have the WAN DNS set to my VPS.

 

I want the entire network to dot/doh so I assume I need to do this on the router. When I check the Omada controller I don't see any options for something like this. When I google my router I see threads confirming router does not support DoH/DoT currently...but then people mention that it does use "Unbound" which can do it.  Problem is that they don't go into any detai about setting it upl. When I google my router or Omada and Unbound...I don't really get any results. Also when I google ADH and Unbound, they're all using either pihole or some other internal server which doesn't fit my use-case.

 

To be honest, I haven't looked into the process for setting up/using Unbound.  I don't want to go to deep in a rabbit hole and find out that it would not help me anyway.  Any suggestions on what to do?

  0      
  0      
#1
Options
2 Reply
Re:Adguard Home on a VPS working, but no DoH for my home network
2022-07-13 01:20:05

  @TotesFab If the router/gateway doesn't support DoH, you need to setup a DNS server/resolver in your network to forward the requests and then point the clients to it in the ER605.

 

Unbound is a popular DNS resolver.  You can run it on any most any machine in your LAN as long as it is on all the time.  There are also alternatives to unbound that can be used if you prefer to use something else.

 

I don't have any knowledge of what the ER605 is using internally but even if it is unbound I don't think it is likely you could modify the config on directly in any supported way.

  0  
  0  
#2
Options
Re:Adguard Home on a VPS working, but no DoH for my home network
2022-07-13 11:40:13

  @TotesFab 

 

So there isnt going to be any DoH/DoT between the ER and the VPS server.

 

You would need to google unbound setup on ARM chip.    The ER605 runs busybox linux. The issue I would be worried about is CPU/Mem usage on the ER605.  Not saying it will be be an issue, but I would keep an eye on it. 

 

I also don't know if the config's would stick after a re-provision?  

 

Like already posted, maybe a better idea to setup a DNS server internally.  Then it will all leave properly.  

 

 

I can not teach anyone anything - I can only make them think - Socrates
  0  
  0  
#3
Options