Skip to content
DnsLister Forum

Where domain hunters compare notes

DNS DoH and DoT

Hello everyone,

I'm trying to get my head around the configuration for DNS DoH and DoT. My network is a pfsense router with 2 piholes. Both piholes have pfsense has upstream server and all my client use piholes.

I want to use CIRA as upstream DNS server. So in PFsense, I entered all the information and configuration the DNS to be always local, ignore remote:

https://preview.redd.it/fdro07d45fmh1.png?width=835&format=png&auto=webp&s=b4a2eacdef73af4ac8d17f38aa38035945ceb1ca

Then, in my DNS Resolver, I have Respond to SSL/TLS Query enabled

https://preview.redd.it/oe7jcgtc5fmh1.png?width=591&format=png&auto=webp&s=9ea9a45cb327d14bd55f01aaf62defe17e98b379

Use SSL/TLS for outbound query enabled and DNSSEC enabled.

https://preview.redd.it/s5rrjmwe5fmh1.png?width=623&format=png&auto=webp&s=afd0779bc0f8d4131557907a1bbc4c1628f28ae6

In PFsense doc, they says to disable DNSSEC and enable Forwarding Mode for DoH (or DoT I forgot). This is where I get lost.

The information under Forwarding mode says that if it is enabled, it will forward the query to upstream DNS. OK, but what happen if it's not checked? If it's not check, it doesn't forward? So unknown DNS entry aren't forwarded to upstream DNS, is that what it mean?

I have many CName and alias configured so those need to keep working. But I don't get the forwarding feature. What does it do when on and off? Why is it required for either DoH or DoT?

Thank you!

Source: r/PFSENSE · by /u/nodiaque

Leave a Reply

Your email address will not be published. Required fields are marked *