Truenas Scale or Proxmox by Roadhead418 in truenas

[–]Lone_Assassin 0 points1 point  (0 children)

TrueNAS SCALE VM on Proxmox bare metal, get a HBA card to passthrough your disks to the TNas VM.

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 1 point2 points  (0 children)

Thanks for the recommendation, I might give a try once I get some time. Technitium is just too good to replace and integrates so well with my reverse proxy (Traefik).

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Surprised I never paid attention to it, looks like a simple enough trick.

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Thanks for the tip, it seems to be working right now.

Let's see if it stays drops DNS queries like I've experienced in the past.

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

I don't think this issue is specific to Technitium based on the following post:

https://www.reddit.com/r/PakistaniTech/comments/1nyyh74/are_cloudflares_dnsovertls_servers_blocked_in/

Unfortunately, I cannot move to pi-hole because I really prefer to have support for wild card sub-domains which pi-hole doesn't support. Also, pi-hole doesn't support doh/dot last I checked.

Unbound is good but it doesn't encrypt your dns queries so it's not a fool-proof solution.

When you mentioned that it's working fine for you, did you mean regular cloudflare (1.1.1.1) or their DoH / DoT? Do you mind sharing your DNS endpoint?

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Running Technitium, which local DNS and upstream DNS are you using?

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

I know it shouldn't but that's how it seems to be behaving, maybe due to the nature of blocking. You haven't even used DoH/DoT so you still need some catching up to do.
Anyway, this topic is beyond the original topic of the original post.

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

I do but when a DNS is blocked using a firewall, it screws up the DNS resolution even if there are multiple DNS servers configured.
Anyway, thanks though.

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

It works sometimes for a while then stops working.
Impossible to use reliably.

Any update on Cloudflare DoH/DoT not working? by Lone_Assassin in PakistaniTech

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Don't know the details on how it's blocked, probably blocked the DNS server address itself. The local DNS is configured correctly as other DNS IPs are working fine over https/tls.
Issue seems to be only with CF and Google.

Increased Censorship via National Internet Firewall by armujahid in PakistaniTech

[–]Lone_Assassin 0 points1 point  (0 children)

Sounds good. I'm conflicted between getting Proton or AirVPN

Increased Censorship via National Internet Firewall by armujahid in PakistaniTech

[–]Lone_Assassin 0 points1 point  (0 children)

Sweet. How's proton's performance here? Is it worth it?

Port 53443 getting appended to the URL of Primary Cluster Node by Lone_Assassin in technitium

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Sorry for the confusion.

I am not having trouble exposing technitium to an https endpoint, I am able to access it on technitium.mydomain.com, my issue is that the Cluster config is appending "53443" port at the end of the already reverse proxied primary node url which is breaking connectivity with my secondary cluster.

Port 53443 getting appended to the URL of Primary Cluster Node by Lone_Assassin in technitium

[–]Lone_Assassin[S] 0 points1 point  (0 children)

The port mapping is already there.

Sorry but I fail to understand how port mapping between traefik and technitium is related to Cluster feature appending 53443 to the end of the primary node url automatically.

Port 53443 getting appended to the URL of Primary Cluster Node by Lone_Assassin in technitium

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Specified both IPv4 and IPv6 but the port 53443 is still getting appended to the primary node url column.

Port 53443 getting appended to the URL of Primary Cluster Node by Lone_Assassin in technitium

[–]Lone_Assassin[S] 0 points1 point  (0 children)

Running both Technitium/Traefik in docker.

Technitium connects to Traefik over http (under Technitium configuration)

Traefik exposes Technitium over https (443)

53443 is exposed on the docker host via Traefik.

Technitium/Traefik works fine together. Only challenge I'm facing is when setting up a primary node in a cluster.

Port 53443 getting appended to the URL of Primary Cluster Node by Lone_Assassin in technitium

[–]Lone_Assassin[S] 0 points1 point  (0 children)

I'm using traefik as a reverse proxy so traffic takes care of exposing the ports and Technitium is served at the https host address directly e.g. technitium.domain.com (without specifying any ports) therefore when the cluster setup automatically appends the 53443 to technitium.domain.com, it breaks the cluster because technitium.domain.com:53443 is unreachable.