Page MenuHomePhabricator

Encrypted DNS
Open, WishlistPublicFEATURE REQUEST

Description

Encrypted DNS makes user tracking more difficult for service providers.

Different approaches exist

  • DNS over TLS
  • DNS over HTTPS

It would be nice to set this up in VyOS and let clients use VyOS as their DNS forwarder (announce automatically via DHCP) instead of manually configuring every client manually.

Cloudflare has a free implementation if you need some servers to test.

Most tutorials I found use "unbound" as DNS cache/forwarder.

Details

Difficulty level
Unknown (require assessment)
Version
-
Why the issue appeared?
Will be filled on close
syncer triaged this task as Wishlist priority.Oct 19 2018, 5:54 PM

There is no way to signal DOH (DNS over HTTP/S) via dhcp.
DOH and DOT is supported in latest dnsdist packages see https://dnsdist.org/ and https://mailman.powerdns.com/pipermail/dnsdist/2018-August/000466.html.

It should also be a good idea to include dnsdist into vyos for dns cacheing and loadbalancing.

syncer added a subscriber: syncer.Oct 20 2018, 6:57 AM

pdns recursor is used for forwarder and we not going to include an additional layer

pdns recursor is from the same people who writes dnsdist.
There are three products wirh diffrent scopes:

pdns-server = Authoritive DNS Server
pdns-recursor = Recursive DNS Server
dnsdist = Loadbalancer, Filter, Cache

The normal setup would be

INTERNET/USER --> DNSDIST (anycast) -- > some pdns-recursor|pdns-server

This is why they implement things like DOH and DOT at first in dnsdist and later on to the other products.

Most ISP's use anycast DNS systems this means you have only one or two IPv4/IPv6 addresses for their users. Cause most resolver libs are not good in handling multiple servers
and errors on one of them. Also you don't want have more pdns-recursors as needed cause you only get good dns performance with massive cacheing. See:

https://www.researchgate.net/figure/Comparison-of-PDNS-performance-with-and-without-caching-for-querying-existing-records_fig6_224719164

There is no mechanism to distribute caches between recursor instances. So don't create to many recursor instances better a few big and distribute dnsdist in front of them as anycast.
So from my point of view it would be for many setups helpfull to have dnsdist and recursor in vyos so that the user can choose what he need.

@rherold my point bit different
we will take care about DNS little bit later

pasik added a subscriber: pasik.Mar 12 2019, 6:09 PM
Alfa80 added a subscriber: Alfa80.Mar 22 2019, 7:29 PM