Ubiquiti UniFi - DNS Shield (DNS Privacy & Security, dnsmasq, dnscrypt-proxy)

  Рет қаралды 7,827

777 or 404

777 or 404

Күн бұрын

Пікірлер: 35
@NoCPU
@NoCPU 5 ай бұрын
The quality of the information in this video is incredible. The amount of detail and low level testing you do to teach how this works is unreal.
@jamb312
@jamb312 5 ай бұрын
Love every video. Learning so much keeps me coming back every time.
@Blaarg987
@Blaarg987 3 ай бұрын
Wow man, you have some great videos. I have been wondering what's going on in the backend with Unifi equipment for a long time and it has made advanced configurations quite challenging, but you have definitely helped!
@ThatHz-
@ThatHz- Ай бұрын
Excellent video
@--Buxtehude--
@--Buxtehude-- Ай бұрын
Wow this guy knows what he is doing!! Thank you learned so much!!
@dp1971pd
@dp1971pd 4 ай бұрын
Very informative, but still device's hard-coded DNS take priority and ignore DNS shield.
@dannydigtl
@dannydigtl 2 ай бұрын
Excellent info. Btw, in the current version of Network app, if you have a custom Internet/WAN DNS set and go to enable DNS Shield it'll warn you that it will override.
@klimisa
@klimisa 14 күн бұрын
That was really informative, ty!
@only_kvvia
@only_kvvia 3 ай бұрын
love your videos, I always wanted to test these setups but I don't have money to build a lab, and I can't disrupt production environment...
@ArtemioSilva
@ArtemioSilva 12 күн бұрын
Awesome video, do I need to change settings to my access point in order to benefit from this configuration?
@hz777
@hz777 12 күн бұрын
The setting is in the gateway and will impact your whole network, instead of just an access point. When it comes to whether to implement a feature or not, my answer is always the same: it depends. I believe all functions are there for a reason.
@suprakar
@suprakar 4 ай бұрын
Thank you for the very informative video. Now the one question I have is can we use our own DNS over HTTPS server? Can I manually override this in the cli?
@hz777
@hz777 4 ай бұрын
Nope, because the UI's list comes from the url in the DNScrypt-proxy config file. Even if you manually change the file, you won't be able to touch the list of servers hosted on public web. Having said that, I don't see why you want to use DNS Shield if you host your own DNS resolver already.
@laurentmc82
@laurentmc82 Ай бұрын
Thank you!
@TangDynasty1983
@TangDynasty1983 5 ай бұрын
Thanks for another great video! Can you share how you used Wireshark to capture the traffic on the router? Did you use a client device and set WS to capture the WAN port of the UXG pro?
@hz777
@hz777 5 ай бұрын
The router in the video is for my lab environment, which is behind the main router of my home, so I can easily run Wireshark on wan port. An alternative way is to run tcpdump in ssh to the router, to capture wan port traffic.
@corsontucker
@corsontucker 5 ай бұрын
your video descriptions with different virtual/physical hosts being shown are amazing and graphics are very clean. what program(s) do you use to virtualize and tile your windows like this? really enjoy the minimalist look. keep up the great content.
@hz777
@hz777 5 ай бұрын
For vm, I use ESXi; for tile management, I use window tidy.
@andreamessina6439
@andreamessina6439 5 ай бұрын
So, what's the point in having the option to select a DNS in WAN if when DNS Shield is enabled, it will take over the WAN DNS anyway? Shouldn't make more sense that options for DNS in WAN became graded out and give an information message to warn the user that DNS Shield settings are inhibiting DNS WAN setting? This would have make it more user-friendly to understand the way it really works. BTW many thanks for your video as I doubt I would have never find out how the settings take over each other without your video. I subscribed already :)
@hz777
@hz777 5 ай бұрын
I am completely with you on this! But we all know how Ubiquiti responds to this type of "minor" things in the web interface, so I never bothered to suggest anything to them.
@andreamessina6439
@andreamessina6439 5 ай бұрын
@@hz777 actually I was just playing around with it again and I just find out that if you set up the WAN DNS and later go to DNS Shield and change it to auto or manual it gives you a warning message: “the DNS server configured on the WAN will no longer be used” 😂
@hz777
@hz777 5 ай бұрын
@andreamessina6439 interesting... So the warning is only implemented in one way instead of completely.
@toddshreve
@toddshreve 5 ай бұрын
Thanks for the video! I would seem there are 3 DNS related features we may want to implement 1) Blocking ads (pihole) 2) Full DNS server (not just a relay/proxy - Unbound) 3) DNS encryption (Unbound and DNS Shield). If you want all 3, it would appear Pihole + Unbound is still the ticket?
@hz777
@hz777 5 ай бұрын
I think so as well.
@hz777
@hz777 5 ай бұрын
The DNScrypt-proxy features are not completely exposed in unifi's DNS Shield yet, so there are something to improve there for sure. And if Ubiquiti can add DNS log function, it will be perfect.
@toddshreve
@toddshreve 5 ай бұрын
@@hz777 At the moment I have my pihole DNS upstream server set as the LAN port of my Gateway Max to try out DNS Shield. I just purchased this unit. I haven't had a UniFi security device since the USG. Figured I'd see if they made any progress in the space. Indeed, they have.
@yankee-in-london
@yankee-in-london 5 ай бұрын
great video! nice work.
@LeePrzy
@LeePrzy 5 ай бұрын
Juicy
@huskyman20435
@huskyman20435 10 күн бұрын
Hello I hope you can help me out. I have implemented all this in exactly the same way, but when I inspect with wireshark I notice that during the TLSv1.3 handshake the SNI is completely leaked. Any idea why that can be?
@hz777
@hz777 9 күн бұрын
Are you referring to the SNI in the "server_name" section of the "Client Hello" packet? Because a server can host multiple websites, the SNI is needed to make sure the server can choose correct certificate to provide the service. As long as the SNI does not include the domain name you want to resolve, I don't see an issue.
@JonnieF14
@JonnieF14 5 ай бұрын
Would you still say Pi-Hole is best practice? Or just use DNS shield?
@hz777
@hz777 5 ай бұрын
I have never said pi-hole was the best practice:) However, even with DNS Shield, UniFi routers still miss some features in pi-hole, but for me DNS Shield is good enough.
@JonnieF14
@JonnieF14 5 ай бұрын
@@hz777 Haha , yeah I know you didn't say best! I just followed some of your previous videos and setup my pi-hole and wasn't sure if that was still the way to go! :D Both seem great obviously, especially if you don't want to go through the process of setting up one or two pi-holes. Great vid as always.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 159 МЛН
The PROS and CONs of UniFi in 2024
21:59
NASCompares
Рет қаралды 85 М.
A Pi-Hole DNS server for my homelab - No Music
24:39
Hardwood Homelab
Рет қаралды 2,7 М.
Secure your DNS Queries with Encrypted DNS
13:15
Mental Outlaw
Рет қаралды 86 М.
Why I no longer use a VPN (most of the time) and nor should you
11:25
Sun Knudsen
Рет қаралды 1,3 МЛН
Configure VLANs on Unifi Switches
20:13
Ethernet Blueprint
Рет қаралды 33 М.
Ubiquiti UniFi Teleport VPN - Deep Dive
25:09
777 or 404
Рет қаралды 1,4 М.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 159 МЛН