Skip to content
DnsLister Forum

Where domain hunters compare notes

Domain resolution with Self signed certificate works on LAN but not on IOS and Android

Hello all !

I've to ask for help, I've lost too much sleep time trying to find an answer here … Could maybe someone see a hint or anything to help me? 🤔

Here's the issue I've been stuck on for the past 2–3 days, without any success.

I installed NGINX Proxy Manager behind Technitium (which is my DHCP and DNS server) because I wanted to use Vaultwarden, which requires a secure HTTPS connection.

Since I only want SSL to work on my local network, I created a DuckDNS domain. I now have a primary zone in Technitium that points to NGINX, and all my proxy hosts are configured correctly.

From every device connected to my LAN or Wi-Fi (desktops and laptops), I can access Vaultwarden using its domain name without any issues.

About 2–3 days ago, I tried connecting the Bitwarden mobile app to my Vaultwarden instance so I could replace Google Password Manager on my phone… but I've never been able to connect.

After a lot of troubleshooting (and asking Claude for help, which turned out to be incredibly unhelpful), this is where I am now:

  • It seems that Android and iOS are forcing the use of my ISP's DNS servers, regardless of what is configured in the network settings.
  • When I run an nslookup for my domain from my phone, it times out because the phone appears to be resolving the domain name over the Internet, finds my public IP address, and then tries to connect to port 443 (which is closed, and I do not want to open it).
  • If I run dig or nslookup while explicitly specifying my local DNS server, everything works perfectly.
  • No DNS queries appear in Technitium's logs unless I explicitly specify my local DNS server.
  • My IPv4 configuration is correct, and Android shows the correct DNS server (verified using Termux and Network Analyzer).

However, here's the interesting part. Using DNS Changer, I managed to force the phone to use IPv4 only, and then everything worked perfectly!

It turns out that on both Android and iOS, IPv6 takes precedence over the correctly configured IPv4 settings.

So my question is:

How can I force local devices to use IPv4 instead of IPv6 on my local network?

Unfortunately, my ISP's router doesn't allow me to disable IPv6, and it constantly advertises the ISP's DNS servers to all mobile devices.

I'm considering buying an open-source router and placing it behind my ISP's router, but would that actually solve the issue by preventing clients from using the ISP's DNS servers?

Bonus question:

The VPN I use to connect back home while I'm away also cannot resolve my local domain names. I assume I simply need to change the VPN configuration so it pushes the correct DNS server to clients? Right now it's configured to use 1.1.1.1. I haven't investigated that part any further yet. 🙂

submitted by /u/iron_glove to r/selfhosted
[link] [comments]

Source: r/selfhosted · by /u/iron_glove

Leave a Reply

Your email address will not be published. Required fields are marked *