New Build 35452 (BS): 03-20-2018-r35452

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Goto page Previous  1, 2, 3, 4  Next
Author Message
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Thu Mar 22, 2018 1:27    Post subject: Reply with quote
jerrytouille wrote:
Stupid question: what’s the benefit of unbound vs. default dns settings?

Best bet is just google it.
If I tell you what I think someone will just argue with me.
I like using it and when it is properly confg for dd-wrt (when the devs get it right) it will never ever give you any DNS problems.

The r35452 is also running unbound 1.7.0 which is the very latest available.
There is an unbound site https://www.unbound.net
It gets fairly techy for the av Joe iffin you aint familiar with it.

I figure the r7500v2 has it ????
Turn it on , let it run for few days Smile
Sponsor
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Thu Mar 22, 2018 2:23    Post subject: Reply with quote
id like to use unbound but this is why i dont http://svn.dd-wrt.com/ticket/5334

easy fix apparently but noone seems to care..

_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Thu Mar 22, 2018 2:52    Post subject: Reply with quote
tatsuya46 wrote:
id like to use unbound but this is why i dont http://svn.dd-wrt.com/ticket/5334

easy fix apparently but noone seems to care..

I've never ever had any problem with local host names....of course any device I might care to contact also holds a static lease.
I haven't used IPs to get to any of my devices in years....local or via ovpn.
devicename.domain just works.
I never understood why you had trouble.

My DNSMasq conf -


unbound conf - it pulls same data and uses it to do local
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Thu Mar 22, 2018 2:56    Post subject: Reply with quote
mrjcd wrote:
tatsuya46 wrote:
id like to use unbound but this is why i dont http://svn.dd-wrt.com/ticket/5334

easy fix apparently but noone seems to care..

I've never ever had any problem with local host names....of course any device I might care to contact also holds a static lease.
I haven't used IPs to get to any of my devices in years....local or via ovpn.
devicename.domain just works.
I never understood why you had trouble.

My DNSMasq conf -


unbound conf - it pulls same data and uses it to do local


does the unbound conf say what port its binded to anywhere?

_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Thu Mar 22, 2018 3:32    Post subject: Reply with quote
tatsuya46 wrote:
does the unbound conf say what port its binded to anywhere?

config don't say but it he catches anything UDP53 or TCP 53 also
:~# cat /tmp/unbound.conf
server:
verbosity: 1
interface: 0.0.0.0
interface: ::0
outgoing-range: 60
outgoing-num-tcp: 1
incoming-num-tcp: 1
msg-buffer-size: 8192
msg-cache-size: 100k
msg-cache-slabs: 1
num-queries-per-thread: 30
rrset-cache-size: 100k
rrset-cache-slabs: 1
infra-cache-slabs: 1
infra-cache-numhosts: 200
access-control: 0.0.0.0/0 allow
access-control: ::0/0 allow
username: ""
pidfile: "/var/run/unbound.pid"
root-hints: "/etc/unbound/named.cache"
target-fetch-policy: "2 1 0 0 0 0"
harden-short-bufsize: yes
harden-large-queries: yes
auto-trust-anchor-file: "/etc/unbound/root.key"
key-cache-size: 100k
key-cache-slabs: 1
neg-cache-size: 10k
local-data: "localhost A 127.0.0.1"
local-data: "Citadel-Station-Homeworld A 10.72.28.13"
local-data: "Citadel-Station-Homeworld.mrjcd.com A 10.72.28.13"
local-data: "bigdeb.mrjcd.com A 10.72.29.1"
local-data: "Apache.mrjcd.com A 10.72.29.2"
local-data: "Deb.mrjcd.com A 10.72.29.3"
local-data: "Note-8.mrjcd.com A 10.72.29.4"
local-data: "1505.mrjcd.com A 10.72.29.5"
local-data: "DogCow.mrjcd.com A 10.72.29.6"
local-data: "da-Box.mrjcd.com A 10.72.29.7"
local-data: "BARB-PC.mrjcd.com A 10.72.29.8"
local-data: "Barb.mrjcd.com A 10.72.29.9"
local-data: "TP-ASUS.mrjcd.com A 10.72.29.10"
local-data: "lildeb.mrjcd.com A 10.72.29.11"
local-data: "QTAIR7.mrjcd.com A 10.72.29.12"
local-data: "JCD-Droid-Turbo.mrjcd.com A 10.72.29.13"
local-data: "NONE2.mrjcd.com A 10.72.29.14"
local-data: "ZenPad.mrjcd.com A 10.72.29.45"
local-data: "VOLUS_Earth-Orbit47-HQ.mrjcd.com A 10.72.29.47"
local-data: "VOLUS_Outpost-AP48.mrjcd.com A 10.72.29.48"
local-data: "Volus_Homeworld.mrjcd.com A 10.72.29.50"
local-data: "Citadel-Switch.mrjcd.com A 10.72.29.51"
local-data: "EA8500.mrjcd.com A 10.72.29.52"
local-data: "Volus-Link53.mrjcd.com A 10.72.29.53"
local-data: "VOLUS_Earth-Orbit54-HQAP.mrjcd.com A 10.72.29.54"
local-data: "NONE3.mrjcd.com A 10.72.29.55"
local-data: "Will-Be-Was.mrjcd.com A 10.72.29.56"
local-data: "E2100L-WDS-South.mrjcd.com A 10.72.29.57"
local-data: "E2100L-WDS-North.mrjcd.com A 10.72.29.58"
local-data: "JonSteevPrinter.mrjcd.com A 10.72.29.59"
local-data: "Tisha-TV.mrjcd.com A 10.15.26.226"
local-data: "VIZIO-TV.mrjcd.com A 10.15.26.227"
local-data: "Tisha-Chromecast.mrjcd.com A 10.15.26.228"
local-data: "mrjcd-Chromecast.mrjcd.com A 10.15.26.229"
local-data: "Tisha_iPhone-6s.mrjcd.com A 10.15.26.230"
local-data: "JonXboxOne.mrjcd.com A 10.15.26.231"
local-data: "oShay.mrjcd.com A 10.15.26.232"
python:
remote-control:
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Thu Mar 22, 2018 3:43    Post subject: Reply with quote
you can read here http://svn.dd-wrt.com/browser/src/router/unbound/doc/unbound.conf.5.in?rev=35437
and here
http://svn.dd-wrt.com/browser/src/router/unbound/doc/unbound.8.in?rev=35437
where BS updated it couple days back it is left on default 53
jerrytouille
DD-WRT Guru


Joined: 11 Dec 2015
Posts: 1304

PostPosted: Thu Mar 22, 2018 4:48    Post subject: Reply with quote
mrjcd wrote:
jerrytouille wrote:
Stupid question: what’s the benefit of unbound vs. default dns settings?

Best bet is just google it.
If I tell you what I think someone will just argue with me.
I like using it and when it is properly confg for dd-wrt (when the devs get it right) it will never ever give you any DNS problems.

The r35452 is also running unbound 1.7.0 which is the very latest available.
There is an unbound site https://www.unbound.net
It gets fairly techy for the av Joe iffin you aint familiar with it.

I figure the r7500v2 has it ????
Turn it on , let it run for few days Smile


Are you using it with Cache DNSSec data and custom cache-size?
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Thu Mar 22, 2018 4:58    Post subject: Reply with quote
jerrytouille wrote:
mrjcd wrote:
jerrytouille wrote:
Stupid question: what’s the benefit of unbound vs. default dns settings?

Best bet is just google it.
If I tell you what I think someone will just argue with me.
I like using it and when it is properly confg for dd-wrt (when the devs get it right) it will never ever give you any DNS problems.

The r35452 is also running unbound 1.7.0 which is the very latest available.
There is an unbound site https://www.unbound.net
It gets fairly techy for the av Joe iffin you aint familiar with it.

I figure the r7500v2 has it ????
Turn it on , let it run for few days Smile


Are you using it with Cache DNSSec data and custom cache-size?

yeah custom dnsmasq size still there but it ain't nessasary...but ain't hurting anything either. cache DNSSEC in the dnsmasq section isn't needed running unbound but it won't hurt either.
If you want to run unbound just turn it on and leave everything else just like it is.
Only thing that would HAVE to be turned off would be DNSCrypt.
labo
DD-WRT Guru


Joined: 30 Jan 2015
Posts: 676
Location: Texas, USA

PostPosted: Thu Mar 22, 2018 9:00    Post subject: Reply with quote
This says you could use unbound with dnsCrypt:

https://etherarp.net/build-an-adblocking-dns-server/index.html

Encrypted DNS with DNSCrypt
DNSCrypt is an arguably more complicated way to encrypt DNS requests. It uses its own custom protocol (based on TLS) that hasn't been standardized with an RFC. It is not directly supported in Unbound, and instead requires a client side application known as dnscrypt-proxy

The server side implementation of dnscrypt is known as dnscrypt-wrapper.
We will talk about this in another post.

Using dnscrypt-proxy
It is available in most package repositories

A list of resolvers is found in /usr/share/dnscrypt-proxy/dnscrypt-resolvers.csv. This is where the resolver-name option gets its entries from. Be warned, the file may be out-of-date, get the latest from here

Creating a systemd unit
Create /etc/systemd/system/dnscrypt-proxy.service with the following

[Unit]
Description=DNSCrypt Proxy
After=syslog.target network.target

[Service]
Type=forking
ExecStart=/usr/sbin/dnscrypt-proxy --user=nobody --resolver-name=dnscrypt.ca-1 --local-address=127.53.53.53 --daemonize

[Install]
WantedBy=multi-user.target
Then start it with
sudo systemctl daemon-reload && sudo systemctl start dnscrypt-proxy

Check it works by running
dig @127.53.53.53 example.com +short

Then add the following to /etc/unbound/unbound.conf (replacing any of the earlier forward rules)

forward-zone:
name: "."
forward-addr:127.53.53.53

_________________
ASUS GT-BE98 PRO Main: Fiber 5gbps up/down
ASUS AXE16000: AI Mesh node
2 X ASUS RT-AX89X: AI Mesh nodes
QNAP QSW-1208-8C 12-Port 10GbE Switch
XS712T ProSafe 12-Port 10GbE Switch
3 X R9000 DD-WRT Mesh
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6290
Location: Texas

PostPosted: Thu Mar 22, 2018 10:46    Post subject: Reply with quote
No you cannot run dd-wrt dnscrypt-proxy same time as unbound.
Of course unbound can do it all plus much more but that defeats the purpose of why I use it on a router.
If you want DNSCrypt use dd-wrt DNSCryt-proxy plus BS & Kong builds both have added DNSSEC easily added with it.

The openNIC DNS servers I was using all did DNSSEC ... many do these days, it's finally getting popular.
Google DNS servers has used it forever.... but still that aint the point.

I use unbound in dd-wrt cause if where you want to go ain't cached it resovles from 13 root DNS servers which are
always DNSSEC and they just don't ever breakdown ...point blank, that's it, that's all I want, and yea it works great.
moon_pie
DD-WRT Novice


Joined: 11 Aug 2017
Posts: 29
Location: edmonton, alberta, canadia!!

PostPosted: Thu Mar 22, 2018 17:24    Post subject: Reply with quote
Router Model: D-Link DIR-E3
Firmware Version: DD-WRT v3.0-r35452 std 03/20/18
Kernel Version: Linux 3.10.108-dd #51864 Tue Mar 20 05:19:36 CET 2018 mips

Status: Working - as a wired DHCP forwarder to secondary AP off our primary router (as a different SSID solely for 2-5 24/7 video streaming in 1-25Mbps bursts devices)
Reset: YES - but not via the gui AND it didn't work via telnet this time (not that the upgrade gui has worked for me for a number of versions, now). I logged in, erased, rebooted, etc - ended up grabbing a pencil and mashing the reset button to wipe settings.
Errors: None as of yet - and I'm seeing better speedtest.net throughput via wifi on 2.4Ghz than previous builds; going out on a limb and guessing LZO compression has something to do with that? Should probably check the system load and temperature, hmm..


(On this device, at least) - this actually feels like a solid build compared to the past couple, although my system use is extremely low and I have logging turned off. For all I know it's chucking errors left and right, but as it's just a secondary AP for a secondary set of devices I don't pay it much mind; nor can I separate any issues in streaming videos between the android devices and the router (I tend to assume it's android though as the app I'm using is pretty rubbish).

_________________
Primary Router for Residential 150Mbps/150Mbps Fiber:
*Asus RT-N66U: running DD-WRT v3.0-r37961 std (12/12/18)*
SpiderVice
DD-WRT Novice


Joined: 24 Aug 2015
Posts: 32

PostPosted: Thu Mar 22, 2018 18:53    Post subject: Reply with quote
Adding to my previous report, I confirmed LZO is not working on my 841ND v9 in Telnet, as the wireless status shows "LZO: no" even when it's enabled in the GUI.
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Thu Mar 22, 2018 20:35    Post subject: Reply with quote
cause LZO detection is wrong anyway, & it also needs client device support, like everything in wifi
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

SpiderVice
DD-WRT Novice


Joined: 24 Aug 2015
Posts: 32

PostPosted: Thu Mar 22, 2018 21:45    Post subject: Reply with quote
Other than other routers running latest dd-wrt, not sure what else supports this so I guess it's one of those features to stay off for years.
Psyxroid
DD-WRT User


Joined: 24 Jan 2016
Posts: 130
Location: Midwest, US

PostPosted: Fri Mar 23, 2018 3:01    Post subject: Reply with quote
Router: Buffalo WZR-600DHP
Firmware: 35452 std (03/20/18 )
Kernel: 3.10.108
Status: OK
Reset: No
Errors: None
Webui upgrade from 35244
Uptime: 2 days, 4:30

Another solid build

_________________
Buffalo WZR‑600DHP (WZR-HP-AG300H)
Goto page Previous  1, 2, 3, 4  Next Display posts from previous:    Page 3 of 4
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum