OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • DNSCrypt Proxy Only Localhost
« previous next »
  • Print
Pages: [1]

Author Topic: DNSCrypt Proxy Only Localhost  (Read 3871 times)

Nekromantik

  • Jr. Member
  • **
  • Posts: 91
  • Karma: 2
    • View Profile
DNSCrypt Proxy Only Localhost
« on: August 26, 2018, 12:37:16 am »
Hi all
I have DNSCrypt proxy 2 set up and running on 127.0.0.1 port 5353.
On opnsense I can use drill to query DNS on that port and it works.
However when I got Unbound forwarder set to :
Code: [Select]
forward-zone:
    name: "."
    forward-addr: 127.0.0.1@5353

all my LAN devices cant query DNS anymore.
When I add 8.8.8.8 to the forwarder it works again.

Any suggestions?
Logged

jjanzz

  • Newbie
  • *
  • Posts: 20
  • Karma: 3
    • View Profile
Re: DNSCrypt Proxy Only Localhost
« Reply #1 on: August 26, 2018, 10:34:13 am »
So, dnscrypt-proxy is, in fact listening on 127.0.0.1, port 5353? Did you configure an upstream server in dnscrypt-proxy? It does need to relay the queries somewhere. If you already set that, can you SSH into the machine and see whether dnscrypt-proxy is actually listening?

What is the output of:

Code: [Select]
sockstat -4 -l | grep 5353
and:

Code: [Select]
telnet 127.0.0.1 5353
Logged

Nekromantik

  • Jr. Member
  • **
  • Posts: 91
  • Karma: 2
    • View Profile
Re: DNSCrypt Proxy Only Localhost
« Reply #2 on: August 26, 2018, 01:23:56 pm »
I found the issue.
I was missing:
Code: [Select]
do-not-query-localhost: noin unbound custom config.
Now my LAN devices can resolve when forwarding to port 5353 in unbound.
thanks
Logged

jjanzz

  • Newbie
  • *
  • Posts: 20
  • Karma: 3
    • View Profile
Re: DNSCrypt Proxy Only Localhost
« Reply #3 on: August 26, 2018, 01:31:31 pm »
Quote from: Nekromantik on August 26, 2018, 01:23:56 pm
I found the issue.

Good job! And thank you kindly for sharing the solution - others might benefit from that if they ran into the same issue!
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • DNSCrypt Proxy Only Localhost
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2