<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DNS over TLS</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148010/dns-over-tls</link><description>Apologies I know it&amp;#39;s been mentioned before, but I&amp;#39;m in the process of moving from pfsense + to XG Home. Got a variety of loose ends to sort out and DNS over TLS is one of them. Is this forthcoming within the v21 release cycle? 
 I&amp;#39;m sorting Wireguard</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: DNS over TLS</title><link>https://community.sophos.com/thread/548755?ContentTypeID=1</link><pubDate>Mon, 18 Nov 2024 08:11:55 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c3605cb4-9e78-4be1-bfa9-90ac22a6f0b2</guid><dc:creator>Vivek Jagad</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/mikeys"&gt;MikeyS&lt;/a&gt;&amp;nbsp;,&lt;br /&gt;&lt;br /&gt;Additionally, you can refer:&lt;br /&gt;&lt;br /&gt;&amp;gt;&amp;nbsp;&lt;a href="https://support.sophos.com/support/s/article/KBA-000006995?language=en_US"&gt;DNS over HTTPS (DoH) for web security&lt;/a&gt;&lt;br /&gt;&amp;gt;&amp;nbsp;&lt;a href="/sophos-xg-firewall/f/discussions/141573/dns-over-tls-https-with-tls-inspection"&gt;DNS over TLS / HTTPS with TLS Inspection - Discussions - Sophos Firewall - Sophos Community&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DNS over TLS</title><link>https://community.sophos.com/thread/548736?ContentTypeID=1</link><pubDate>Sun, 17 Nov 2024 18:45:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:56481894-b0fe-4231-882c-fccb287494eb</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Sophos is following up with DoT in Sophos DNS Protection as well.&amp;nbsp;&lt;br /&gt;Something we are keen to implemented.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/sophos-dns/"&gt;Sophos DNS Protection&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/sophos-dns-protection/f/discussions/146287/does-the-dns-protection-support-dns-over-tls-and-dns-over-https"&gt;Does the DNS Protection support DNS over TLS and DNS over HTTPS?&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;DNS Protection is only available for business customer - not for Home, as the home license is excluded from the licensing system.&amp;nbsp;&lt;br /&gt;This may change in the future.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;To be honest - Most home users have other techniques running anyway: So business customers using techniques like Sophos DNS, while home customers running PiHole or other systems, made it not to the priority number 1 on the firewall roadmap - but on the DNS protection roadmap.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DNS over TLS</title><link>https://community.sophos.com/thread/548725?ContentTypeID=1</link><pubDate>Sun, 17 Nov 2024 02:43:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1788a012-b78d-4780-896d-8467288278f5</guid><dc:creator>alan weir</dc:creator><description>&lt;p&gt;I asked about this a while ago also. I don&amp;#39;t think DNS over TLS or even DNS over HTTPS is on the roadmap. It seems it&amp;#39;s due to Sophos having their own&amp;nbsp;DNS service which requires a subscription. It is a shame,&amp;nbsp;because it wouldn&amp;#39;t be that difficult to do,&amp;nbsp;because DoT, DoH, STUN, and&amp;nbsp;Quic DNS are becoming the standard to replace insecure DNS that is susceptible to DNS highjacking and ISP snooping.&lt;/p&gt;
&lt;p&gt;I got around this by using Pi-Hole as my DNS server and set up secure DNS&amp;nbsp;using Unbound with DNScrypt. Maybe you can consider a network-wide DNS server and filter like a Raspberry PI running Unbound or AdGuard Home and establish a DNS over TLS connection from that to wherever DNS resolver you want.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: DNS over TLS</title><link>https://community.sophos.com/thread/548721?ContentTypeID=1</link><pubDate>Fri, 15 Nov 2024 20:27:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:84c1498d-7e8c-4c11-afd2-302a89575cbe</guid><dc:creator>RickWeiss</dc:creator><description>&lt;p&gt;Sophos has demonstrated no interest in DNS over TLS or HTTPS.&amp;nbsp; I honestly don&amp;#39;t understand why when other firewall vendors have offered that for a long time.&amp;nbsp; I personally got around that with a Linux server running Bind 9.&amp;nbsp; Don&amp;#39;t wait for Sophos.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>