Add DNS over HTTPS (DoH) support

If you use a validating, recursive, caching DNS resolver you don’t need any ISP or any other resolver that is providing a DNS service.

You are then asking the authorative servers themselves and so cutting out all the collectors/providers in between. Those big firms will only know of that resolve when they are the authorative server for that domain. You request goes plain over the internet but then you csn alway put that traffic in a VPN tunnel.

https://en.m.wikipedia.org/wiki/Name_server

I am using it now for several years and it as fast or faster then using the DNS of my ISP. Unbound is very flexible and full of features you can only dream of and give you full control of what you need. It has DoT serving to clients and if you want to use a DoT server to resolve, it works great.

No DoH supported, I don’t expect that ever happening. Knot resolver is also such a kind of server that has similar or more features.

If you want be indepented then run you own DNS recursive server. Running great on just a RaspberryPI board.

Is this really better than going through your ISP for EU users?

Like said many times before, it depends on your country and your ISP.
Some people have strong censorship, some are afraid of their governments.

So in the end, information will flow somewhere, this feature allows you to control who you trust more.

I think Firefox just defaulted everybody to Cloudflare.

I personally trust cloudflare more than my ISP, but you are free to turn it off.
Screenshot 2020-02-27 at 16.14.10.png

So there’s no EU equivalent?

https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Public+Resolvers

It would be nice when MikroTik finally implemented support for static records that return NXDOMAIN in RouterOS so Firefox can do their canary lookup and the admin can select the desired behavior…

I see nothing from the EU jurisdiction that is similarly well-known.

What I read was not accurate, Mozilla is only rolling out the Cloudflare default in the US for now.

I see a Finland server here https://blahdns.com/

But the ISP can just perform a reverse lookup.

Lots more EU servers here https://github.com/curl/curl/wiki/DNS-over-HTTPS

I didn’t go through every post, but I noticed that at some point normis asked for a use case.

Example 1:
There are companies that have on-prem systems, that are used both from the Internet and from the corp LAN.
Let’s say company has an email server, located on domain “email.company.net”. The server lives inside the company network. People have laptops, mobile phones, etc. All of that connects to hostname “email.company.net”. When accessing that hostname from inside corp LAN, you have to resolve “email.company.net” hostname to some internal IP address. So it can point local users to a local IP. You don’t access a local server via a public IP, from inside a NAT routed network (maybe with some magic you could, but it’s far less dirty to just give out the local IP to the client). So, in your local DNS you add a record (static entry in Mikrotik) for the hostname. The client receives a local IP address of the server, available inside the LAN and problem is solved. Clients only need to use that DNS server (and DHCP gives then the proper one) and that’s it. Everything works from the Internet and also when you’re inside the corp network where the servers actually live.
This approach solves availability of resources from both corp LAN and Internet, where this is needed.

Example two:
Another example are systems that are not at all available from the Internet directly, but only from through a VPN. Many companies employ this. So, the client (or the entire client network) first has to connect to VPN, then access resources. If this VPN is resolved with Mikrotik (many RB devices, even the cheap ones, have nice hardware offloading for IPSEC, so it’s a very good solution for site-to-site VPN) it’s all good. We just use static entries in DNS in ROS and point clients to use DNS from ROS. And everything works. No need for additional DNS server.

And this all works well for IMAP, SMTP etc, because normally everything on the machine uses DNS server as set up on the system. So email clients and custom applications all work. But what about browsers. All is well until a browser decides not to honor system DNS settings. Then, anything in the corp LAN that you try to access through a browser, doesn’t work anymore. Same is you’re accessing through a VPN. Stuff like CRM, webmail - well, most apps today are web apps anyway, used through a browser.

And now it starting to happen, browsers are trying to reinvent how Internet works. Because… DNS, in it’s standard and widely used implementation, is no longer deemed safe enough. Ok, fine. Someone has to lift the standards. Browsers are trying to do it, other apps will probably follow after that. But if Mikrotik doesn’t follow this change, and MT is used to provide DNS queries, then setups like the ones described in above examples will stop working.

Yeah, we can use a separate DNS server that would solve this, of course, and maybe we should. But why not have it in ROS, as an option at least. Network-wise we have (almost) everything you can imagine in ROS - even stuff you wouldn’t expect to have. But none of the more recent DNS stuff. Why ? Why would Mikrotik not provide a solution that solves this issue, like any other network related issue it already solves, in the same box ?

I understand that many proposals exists to solve DNS problem and it’s not yet clear which one is going to be used in future. It’s hard to know what to implement. One way is to implement just the ones that browsers are going for → because those are the ones we’re going to need to have in our network for above setups to continue working. And that’s probably the ones that everyone is going to switch to in the end.

I believe these setups (like the ones mentioned above) are not at all uncommon. Well, maybe people don’t use ROS for DNS in such cases, but you get the point. So, again, yes, we can solve this by installing a compatible DNS inside our network, but… ROS was always able to handle this stuff for us, without the need for additional equipment. Why would we need to change that. Is it too heavy load for a Mikrotik device (TLS handshakes and all that) ? But recent RB-s are not at all slow, I guess this won’t be a problem. Or would it be ? Normis, could you provide any insight regarding this ?

Regards,
David

How about my homepod, robotcleaner, Intelligent curtain and other smart device, and home server like unraid or freenas?
My refrigerator can connect the internet itself to tell me the balance foods.
We are obviously at a time of Internet of Everything, doh or dot is the most useful to everyone.

There is information when the DoH function will go from beta to release?

When version 6.47 is released to stable channel. There’s no date for that, though.

Tell me how to configure DoH cloudflare, when specifying the address 1.1.1.1 an error occurs: “DoH server connection error, resolving error”
and:
1.PNG

In 6.47 announced DoH support, but it does not working.
I tried servers 1.1.1.1, 8.8.8.8, 9.9.9.9 - no success. How to use it?

to use it check the manual form cloudflare at https://developers.cloudflare.com/1.1.1.1/dns-over-https/

TLDR from the cloudflare page ; in the DoH server field you have to put

https://cloudflare-dns.com/dns-query