Community discussions

MikroTik App
 
voip
just joined
Topic Author
Posts: 3
Joined: Tue Jan 09, 2024 12:17 pm

DoH Mullvad/Yandex

Thu Feb 08, 2024 3:02 pm

Yes, I can see that DoH om Mikrotik does not work with Mullvad/Yandex
but does anybody know why?
https://help.mikrotik.com/docs/display/ ... oHservices


I have just tried (just in case something has changed (running v.7.13.4):
/tool fetch url="https://letsencrypt.org/certs/isrgrootx1.pem"
/certificate import file-name=isrgrootx1.pem
/ip dns set use-doh-server=https://all.dns.mullvad.net/dns-query verify-doh-cert=yes
/ip dns static add address=194.242.2.9 name=adblock.doh.mullvad.net
/ip dns static add address=2a07:e340::9 name=adblock.doh.mullvad.net
And in the log I can see:
DoH server connection error: remote disconnected while in HTTP exchange
DoH server connection error: remote disconnected while in HTTP exchange [ignoring repeated messages]

Is it that Mullvad/Yandex are not sticking the RFC or Mikrotik did not implemented DoH properly?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26387
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: DoH Mullvad/Yandex

Fri Feb 09, 2024 9:57 am

Yes, as you found in the documentation, those are currently not supported, as they force using HTTP2, which RouterOS currently does not support

Who is online

Users browsing this forum: GoogleOther [Bot], toldyzol and 16 guests