We want to block all clients on the LAN and all VLANs from directly accessing any external DNS servers. We really don't want anyone outside snooping on our DNS lookup history.
First: The question is how to set up the ER7206 for act as a forwarder?
I've already (I think) set up an Access Control to block all traffic from LAN -> WAN on port 53. It works, because it killed all DNS lookups on the LAN when I enabled it without setting up the rest of whatever is needed.
I started on Network > LAN > LAN DNS and selected "Forward" and then got lost on the required fields "Domain Name", "Alias Domain Name" and "DNS Server".
Should "Domain Name" be our registered domain? Or… what? (the * as an entry is invalid)
Should there be an "Alias Domain Name"? If so, what?
I "assume" the "DNS Server" would be where it's being forwarded to (Ex: quad9.net, 9.9.9.9 & 149.112.112.112 ).
Second: Should I setup DNS Proxy on the ER7206? In the Services > DNS Proxy > DOH, the predefined profile "quad9_2" is currently the only one enabled. I believe this "should" send all of the router's DNS quires to Quad9 using "DNS Over HTTPS". I "assumed" that this would also encrypt the forwarded DNS traffic (if I can get it to work) from the LAN DNS servers using the router as a forwarder.
Or, am I misunderstanding what this "DNS Proxy" is really used for?
Third: We don't want to try some other alternative to the ER7206, unless we know the ER7206 can't do what we think we need.
We have 3 MS 2019 Servers set up as redundant DNS servers for the internal LAN and they have their "forwarders" property set to the IP address of the ER7206's LAN interface (it resolves to the FQDN of the router). Right now, we needed to add a 2nd "forwarders" property (9.9.9.9) to keep DNS running. Without the 2nd "forwarders" property, all client DNS falls flat.
Note: We have not tried to enable / set up DNS Encryption on the 3 MS Servers "for reasons".
We run a split DNS with a registered DNS domain. The LAN DNS servers resolve all the clients internally and then resolve out to an services we host that are outside. The "outside" DNS is Dynu.com and there are only 3 outside services that resolve on that DNS server.
Source: r/TPLink_Omada · by /u/ticedoff8