Feature request: IPv6 DNS Proxy/Override + DoH/DoT hostname support
Hello TP-Link Omada team,
I would like to submit a feature request regarding DNS handling on Omada Gateways.
At the moment, DNS Proxy and DNS Override only work for IPv4. On IPv6 networks, clients still receive DNS servers from the ISP via RDNSS, which means IPv6 DNS traffic bypasses the gateway. On dual-stack networks this results in unavoidable DNS leaks, because modern clients such as macOS and iOS prefer IPv6.
This makes it impossible to consistently enforce DNS policy, DNSSEC validation, or resolver selection when IPv6 is enabled.
In addition, DoH and DoT configuration currently only accepts IP addresses.
Many modern DNS providers, including ISPs, require hostname-based endpoints with proper TLS validation.
These cannot be configured because hostname, SNI and URL path support are missing.
I would like to request the following improvements:
Support for IPv6 DNS Proxy / DNS Override, including advertising the gateway itself as IPv6 DNS via RDNSS,
and DoH/DoT support using hostnames (including SNI and HTTPS URL paths).
These changes would make DNS handling consistent across IPv4 and IPv6 and allow Omada to work properly with modern ISP-provided DoH/DoT resolvers, without forcing users to disable IPv6 or deploy external DNS servers.
Thank you for considering this request.
Nice to have:)
Additional IPv6 DNS controls such as per-LAN/VLAN RDNSS configuration, unified IPv4/IPv6 DNSSEC validation, and improved visibility into IPv6 DNS usage (logging or status).
