1
24.7 Production Series / Re: Configure Unbound to listen for TLS requests on port 853?
« on: November 12, 2024, 02:47:03 am »Quote
Are you saying that some devices on your lan are actually using DOT?, ie port 853 and not port 53I would like them to have the option to use DoT, since unbound supports it, but I can't say if any actually do. Like I said, in my previous setup it was just a checkbox and a cert select dropdown to enable it, so I did.
As for DoH, I don't really care to support it for local clients. Part of the point of that protocol is to hide DNS traffic and skirt around things like the NAT redirect rules and DNSBLs I have setup. I obviously can't just block traffic with a destination of port 443 and neither can anyone else, so the best I can do to prevent things like IoT devices from trying to use DoH is to block the IPs of known DoH servers.