Hello everyone,
I'm trying to get my head around the configuration for DNS DoH and DoT. My network is a pfsense router with 2 piholes. Both piholes have pfsense has upstream server and all my client use piholes.
I want to use CIRA as upstream DNS server. So in PFsense, I entered all the information and configuration the DNS to be always local, ignore remote:
Then, in my DNS Resolver, I have Respond to SSL/TLS Query enabled
Use SSL/TLS for outbound query enabled and DNSSEC enabled.
In PFsense doc, they says to disable DNSSEC and enable Forwarding Mode for DoH (or DoT I forgot). This is where I get lost.
The information under Forwarding mode says that if it is enabled, it will forward the query to upstream DNS. OK, but what happen if it's not checked? If it's not check, it doesn't forward? So unknown DNS entry aren't forwarded to upstream DNS, is that what it mean?
I have many CName and alias configured so those need to keep working. But I don't get the forwarding feature. What does it do when on and off? Why is it required for either DoH or DoT?
Thank you!
Source: r/PFSENSE · by /u/nodiaque