Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

DNS over TLS

Apologies I know it's been mentioned before, but I'm in the process of moving from pfsense + to XG Home.  Got a variety of loose ends to sort out and DNS over TLS is one of them.  Is this forthcoming within the v21 release cycle?

I'm sorting Wireguard out via a virtual machine hosted within my home DMZ.  Additional Let's Encrypt certs I'll either generate from a linux machine or ditch and get a cheap wildcard cert to cover most items or I'll stand up and internal CA, but will have to install the cert on end devices.



Added TAGs
[edited by: Erick Jan at 1:27 AM (GMT -8) on 18 Nov 2024]
Parents
  • I asked about this a while ago also. I don't think DNS over TLS or even DNS over HTTPS is on the roadmap. It seems it's due to Sophos having their own DNS service which requires a subscription. It is a shame, because it wouldn't be that difficult to do, because DoT, DoH, STUN, and Quic DNS are becoming the standard to replace insecure DNS that is susceptible to DNS highjacking and ISP snooping.

    I got around this by using Pi-Hole as my DNS server and set up secure DNS using Unbound with DNScrypt. Maybe you can consider a network-wide DNS server and filter like a Raspberry PI running Unbound or AdGuard Home and establish a DNS over TLS connection from that to wherever DNS resolver you want.

Reply
  • I asked about this a while ago also. I don't think DNS over TLS or even DNS over HTTPS is on the roadmap. It seems it's due to Sophos having their own DNS service which requires a subscription. It is a shame, because it wouldn't be that difficult to do, because DoT, DoH, STUN, and Quic DNS are becoming the standard to replace insecure DNS that is susceptible to DNS highjacking and ISP snooping.

    I got around this by using Pi-Hole as my DNS server and set up secure DNS using Unbound with DNScrypt. Maybe you can consider a network-wide DNS server and filter like a Raspberry PI running Unbound or AdGuard Home and establish a DNS over TLS connection from that to wherever DNS resolver you want.

Children
No Data