How to add NextDNS to my hex

Just wanted to say that everything "appears" to be working very well. No problems so far that I can see, So thank you all for your help. Very much appreciated.

Just mark one of the responses as solution, then the topic is solved.

So if I wanted to go back to where I was before I assume that I just "restore" the text file that I created, correct? Can you please tell me how exactly I would do that? I should have asked back then but I didn't think about it.

It is not so easy (for complete exports), in your case of a (very) partial export it is a litlle easier.

Basicallly the configuration of a Mikrotik revolves around two commands/statements:

  1. add
  2. set

The "add" command - but it may depend on context, usually adds :wink: something, no matter if already existing.
This can create duplicates.

The "set" command is "better" as it simply changes some settings.

BUT there is an added issue, by default (i.e. without "verbose" flag) an export command only exports whatever is different form "default" so there may be cases where some setting is NOT present in the export (because it is "default") and so it cannot overwrite a setting that has been changed from "default".

So the "right" way is to first delete the whole section and then re-import (actually this means only to open a terminal and paste the previous export).

Usually it is much easier to delete the section from the WInbox GUI and then paste the commands from the previous export in a new terminal window, though it is of course possible to make the deletion through CLI, it is more complicated and prone to errors.

OK so I'm guessing that perhaps better would be to just go line by line in what I did and just remove or change it back then right? Because it doesn't look like it changed that much. So this is what it did ...

/tool fetch url=https://curl.se/ca/cacert.pem
/certificate import file-name=cacert.pem

it would seem that I can go to where the certificates are and just delete them. There were zero certificates there before I did this so this should be no problem.

-

/ip dns set servers=""

This looks like I just go into the DNS servers and set it back to using my peer servers.

-
/ip dns static add name=dns.nextdns.io address=45.90.28.0 type=A
/ip dns static add name=dns.nextdns.io address=45.90.30.0 type=A
/ip dns static add name=dns.nextdns.io address=2a07:a8c0:: type=AAAA
/ip dns static add name=dns.nextdns.io address=2a07:a8c1:: type=AAAA

The above I'm not sure how to undo.

-

/ip dns set use-doh-server=“https://dns.nextdns.io/XXXXXX/main” verify-doh-cert=yes

This looks like I go into IP-> DNS and just remove the DoH server. Not sure if I have to change anything else on that page.

Am I close?

Prior to doing anything my export looked like this:

/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan

After doing everything it looked like this:

/ip dns
set allow-remote-requests=yes use-doh-server=https://dns.nextdns.io/XXXXXX/main verify-doh-cert=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
add address=45.90.28.0 name=dns.nextdns.io
add address=45.90.30.0 name=dns.nextdns.io
add address=2a07:a8c0:: name=dns.nextdns.io type=AAAA
add address=2a07:a8c1:: name=dns.nextdns.io type=AAAA

After undoing the things I said above it looks like this:

/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
add address=45.90.28.0 name=dns.nextdns.io
add address=45.90.30.0 name=dns.nextdns.io
add address=2a07:a8c0:: name=dns.nextdns.io type=AAAA
add address=2a07:a8c1:: name=dns.nextdns.io type=AAAA

So it looks like all I have to do it get rid of those added addresses and I'll be back to where I was. Am I correct?

Yep. Reloading entire configurations is way too cumbersome for this. You simply:

  1. Set some plain dns servers. Either manually in the dns->servers menu, or by enabling the "use peer dns" setting on your dhcp or pppoe client.
  2. Remove the "use DoH server" part.
  3. (Optional.) You may delete the static dns entries for nextdns. You can also just leave them there.

That is what I did. I found where the extra servers were and removed them. Also I got rid of the certificates. Thank you.

If you're using RouterOS v7, I'd also recommend upgrading to the latest stable version before configuring NextDNS, as DoH certificate handling is much better than in v6. Other than that, the official NextDNS setup should work fine if your clients use the MikroTik as their DNS server.

Yes, I am experiencing an ongoing error that I posted about in another topic, and in doing my research on it most people say that ros7 helps. I was at ros6 but I am in the middle of upgrading now to see if that's true. Thank you.

This particular topic was just so that I could nail down both the proper way to enable it and get rid of it so that I could effectively test it out.

I just read in another topic here the following...

This is great and I'm going to try to remove the tons of certificates now and see if ti still works.