Ubiquiti UniFi Gateway - Block Client's Custom DNS Settings (DoH/DoT)

  Рет қаралды 2,580

777 or 404

777 or 404

Күн бұрын

Пікірлер: 12
@buenology
@buenology 28 күн бұрын
I am glad to have found your videos. Excellent work! I subscribed!!
@reelmccoyfx
@reelmccoyfx 4 ай бұрын
Thanks for the video. I love the thoroughness and testing of changes made. Looking forward to future videos. And stupid me accidentally got click happy on my previous comment and deleted it. Sorry about that.
@hz777
@hz777 4 ай бұрын
np😊
@frenchysg8089
@frenchysg8089 3 ай бұрын
Great video. Could you help me understand one part? I've a Pihole and Unbound on a separate server like your Pihole+unbound example, and this is my DNS resolver. But When I'm blocking "All other DNS" my server no longer resolve DNS, It seems to have something to do with Unbound and that rule. Using Debian 12 on that server. I did add my server IP in the DNS group, but it doesn't help.
@hz777
@hz777 3 ай бұрын
How did you block "all other DNS"? Do you use Unifi gateway?
@bavobostoen
@bavobostoen 4 ай бұрын
Thanks, very clear, I wonder if doh blocking can ever be implemented without full SSL decryption at gateway?
@hz777
@hz777 4 ай бұрын
If the server also has other functions you need so you only want to block the doh function, you are right that's impossible. In this video I assume it's fine to block the server completely.
@TangDynasty1983
@TangDynasty1983 4 ай бұрын
Could you please share how to set up WS to capture the WAN port of the UXG-Pro? Thank you.
@hz777
@hz777 4 ай бұрын
It's very easy. My uxg-pro runs behind another router, and the wan port is connected to a UniFi switch in my home network. I simply set a port on the same switch to monitor the port that connects to uxg-pro's wan port, then run Wireshark against the monitoring port
@TangDynasty1983
@TangDynasty1983 4 ай бұрын
@@hz777 makes sense. what if I have the Unifi as my WAN router, is there way to have WS capture the WAN traffic?
@hz777
@hz777 4 ай бұрын
@@TangDynasty1983 the easiest way is to use tcpdump in the router to capture wan traffic to a file, then later using Wireshark to display the captured file.
@LabMonkey-k2j
@LabMonkey-k2j 4 ай бұрын
so just use Secure DNS as a client or a vpn with DNS leak protection. Bye bye gateway dns
Tailscale Is Awesome - Deployment, Testing, ACLs, and Exit Nodes
29:23
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 74 МЛН
Как Я Брата ОБМАНУЛ (смешное видео, прикол, юмор, поржать)
00:59
Натурал Альбертович
Рет қаралды 4,4 МЛН
[TryHackMe] Rootme: Resolución Paso a Paso
39:57
Ciber Intrépidos
Рет қаралды 208
Pi-hole + Unbound + DNS Over TLS  (Ubiquiti/UniFi/DoT/DoH)
23:36
A Pi-Hole DNS server for my homelab - No Music
24:39
Hardwood Homelab
Рет қаралды 2,8 М.
Ubiquiti UniFi SD-WAN - Site Magic & OSPF
28:30
777 or 404
Рет қаралды 2 М.
Ubiquiti Just Killed 4 Products with the Cloud Gateway MAX!
9:38
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 74 МЛН