Ubiquiti UniFi - DNS Shield (DNS Privacy & Security, dnsmasq, dnscrypt-proxy )

  Рет қаралды 3,826

777 or 404

777 or 404

Ай бұрын

Пікірлер: 22
@dp1971pd
@dp1971pd Күн бұрын
Very informative, but still device's hard-coded DNS take priority and ignore DNS shield.
@jamb312
@jamb312 Ай бұрын
Love every video. Learning so much keeps me coming back every time.
@NoCPU
@NoCPU 23 күн бұрын
The quality of the information in this video is incredible. The amount of detail and low level testing you do to teach how this works is unreal.
@yankee-in-london
@yankee-in-london 10 күн бұрын
great video! nice work.
@Lee-wh3ht
@Lee-wh3ht Ай бұрын
Juicy
@corsontucker
@corsontucker Ай бұрын
your video descriptions with different virtual/physical hosts being shown are amazing and graphics are very clean. what program(s) do you use to virtualize and tile your windows like this? really enjoy the minimalist look. keep up the great content.
@hz777
@hz777 Ай бұрын
For vm, I use ESXi; for tile management, I use window tidy.
@TangDynasty1983
@TangDynasty1983 Ай бұрын
Thanks for another great video! Can you share how you used Wireshark to capture the traffic on the router? Did you use a client device and set WS to capture the WAN port of the UXG pro?
@hz777
@hz777 Ай бұрын
The router in the video is for my lab environment, which is behind the main router of my home, so I can easily run Wireshark on wan port. An alternative way is to run tcpdump in ssh to the router, to capture wan port traffic.
@suprakar
@suprakar 2 күн бұрын
Thank you for the very informative video. Now the one question I have is can we use our own DNS over HTTPS server? Can I manually override this in the cli?
@hz777
@hz777 2 күн бұрын
Nope, because the UI's list comes from the url in the DNScrypt-proxy config file. Even if you manually change the file, you won't be able to touch the list of servers hosted on public web. Having said that, I don't see why you want to use DNS Shield if you host your own DNS resolver already.
@toddshreve
@toddshreve 16 күн бұрын
Thanks for the video! I would seem there are 3 DNS related features we may want to implement 1) Blocking ads (pihole) 2) Full DNS server (not just a relay/proxy - Unbound) 3) DNS encryption (Unbound and DNS Shield). If you want all 3, it would appear Pihole + Unbound is still the ticket?
@hz777
@hz777 16 күн бұрын
I think so as well.
@hz777
@hz777 16 күн бұрын
The DNScrypt-proxy features are not completely exposed in unifi's DNS Shield yet, so there are something to improve there for sure. And if Ubiquiti can add DNS log function, it will be perfect.
@toddshreve
@toddshreve 16 күн бұрын
@@hz777 At the moment I have my pihole DNS upstream server set as the LAN port of my Gateway Max to try out DNS Shield. I just purchased this unit. I haven't had a UniFi security device since the USG. Figured I'd see if they made any progress in the space. Indeed, they have.
@andreamessina6439
@andreamessina6439 17 күн бұрын
So, what's the point in having the option to select a DNS in WAN if when DNS Shield is enabled, it will take over the WAN DNS anyway? Shouldn't make more sense that options for DNS in WAN became graded out and give an information message to warn the user that DNS Shield settings are inhibiting DNS WAN setting? This would have make it more user-friendly to understand the way it really works. BTW many thanks for your video as I doubt I would have never find out how the settings take over each other without your video. I subscribed already :)
@hz777
@hz777 17 күн бұрын
I am completely with you on this! But we all know how Ubiquiti responds to this type of "minor" things in the web interface, so I never bothered to suggest anything to them.
@andreamessina6439
@andreamessina6439 17 күн бұрын
@@hz777 actually I was just playing around with it again and I just find out that if you set up the WAN DNS and later go to DNS Shield and change it to auto or manual it gives you a warning message: “the DNS server configured on the WAN will no longer be used” 😂
@hz777
@hz777 17 күн бұрын
@andreamessina6439 interesting... So the warning is only implemented in one way instead of completely.
@JonnieF14
@JonnieF14 22 күн бұрын
Would you still say Pi-Hole is best practice? Or just use DNS shield?
@hz777
@hz777 22 күн бұрын
I have never said pi-hole was the best practice:) However, even with DNS Shield, UniFi routers still miss some features in pi-hole, but for me DNS Shield is good enough.
@JonnieF14
@JonnieF14 22 күн бұрын
@@hz777 Haha , yeah I know you didn't say best! I just followed some of your previous videos and setup my pi-hole and wasn't sure if that was still the way to go! :D Both seem great obviously, especially if you don't want to go through the process of setting up one or two pi-holes. Great vid as always.
UniFi Network Setup & Configuration Guide | 2023
38:31
Unified IT
Рет қаралды 214 М.
UniFi Wireguard VPN (And Firewall Rules)
14:11
Tech Me Out
Рет қаралды 20 М.
1 or 2?🐄
00:12
Kan Andrey
Рет қаралды 35 МЛН
Wait for the last one! 👀
00:28
Josh Horton
Рет қаралды 129 МЛН
Вечный ДВИГАТЕЛЬ!⚙️ #shorts
00:27
Гараж 54
Рет қаралды 13 МЛН
Secure your DNS Queries with Encrypted DNS
13:15
Mental Outlaw
Рет қаралды 81 М.
Ubiquiti UniFi - Local Domain Name  (.internal. / .home.arpa.)
27:01
Host Your Own Encrypted DNS Server
24:21
Mental Outlaw
Рет қаралды 117 М.
I bought the World's RAREST Tech!
39:54
Mrwhosetheboss
Рет қаралды 1,5 МЛН
Ubiquiti UniFi VLAN - Isolate Network vs.  Guest Network
32:02
Lock down DNS on your network
11:55
Willie Howe
Рет қаралды 16 М.
Top 13 Unifi Network Setup Tips - Planning and Optimization
40:02
Ethernet Blueprint
Рет қаралды 39 М.
1 or 2?🐄
00:12
Kan Andrey
Рет қаралды 35 МЛН