1

DNS-over-TLS Asus Router Setup (Please Help)

I cannot get my head around the setup of dns-over-tls on my router AX56U and would just like some confirmation with the setup please. So when I navigate to the WAN section should I be selecting 'other' option and leaving DNS Server1 and DNS Server2 blank or should I be entering the assigned NextDNS IP addresses from my configuration page in those fields? 

Lastly, when entering details in the DNS-over-TLS Server List, should I be using the NextDNS IP Addresses from the Linked IP section of my configuration page or from the pfSense section under router configuration? As both sets of IP addresses are different so not really sure which ones to use, does it matter? 

Just to clarify I'm not using IPv4 with linked IP. But I'm currently using the Linked IP DNS server addresses in my router in both sections using DNS-over-TLS and I'm getting 100% Encrypted DNS traffic, just not sure of it's blocking everything from my configuration.

If someone could please clear this up I would greatly appreciate it. Thanks in advance..

36 replies

null
    • Luther.1
    • 2 days ago
    • Reported - view

    Another words since I enabled IPv6 in my Asus router and setup as you instructed my internet download speed has slowed down by 50%

      • tnpapa.1
      • yesterday
      • Reported - view

       The built in speed test on the router is very buggy.  Best bet is to download the Speedtest by ookla app onto a computer that is connected by ethernet to the router and test that way. Don't test over wifi. 

      • Luther.1
      • yesterday
      • Reported - view

        I usually don't have an issue with the built in speedtest and on ipv4 I practically get the same result every time but since I enabled ipv6 today I'm almost getting a 50% drop. I have been testing all day, not sure what's going on to be honest. Is it possible that the router is restricting speed somehow? I will do a speed test directly from the gateway in the morning and see what result I get...

      • tnpapa.1
      • yesterday
      • Reported - view
      • tnpapa.1
      • yesterday
      • Reported - view

       Router is limited by the CPU, It cant run tests properly due to resource limitations.  Always test from your computer. If your fiber modem has a built in test that will be your most accurate as it only test its connection to the ISP network and does not take your equipment into consideration.

      This is the test from my fiber modem. As you can see I get more speed on the modem than my router can show because my ethernet connections are limited to 1gb which is really only 940mbs at best.

      • Luther.1
      • yesterday
      • Reported - view

      my router only uses around 3-6% CPU that I can see, sometimes it has a little spike but nothing of concern. I have been using the internal speedtest for quite sometime now daily monitoring my speed at the router and it doesn't miss a beat at around 930mbps it's only since I enabled IPv6 now I'm getting under 500mbps and it's staying that way. I don't think it's the resources within the router. I manually kicked the nbn connection yesterday with my ISP on their end as well as reset the ports with the NBN company. I also reset the NTD device (Gateway) but nothing has changed. Regarding speed test from the gateway all I do is connect my macbook directly to the gateway via lan cable and navigate to speedtest.net website to test the connection which I will attempt to do in the next hour I guess this will isolate whether it's the router or gateway. Have I possibly missed any other settings within the router that could be causing the issue after enabling IPv6?

      Thanks again

      • tnpapa.1
      • yesterday
      • Reported - view

       As I said it is a known thing that the internal speed test on Asus is buggy. It is never to be relied on. Please use speed test app on your computer.

      There are several threads on Reddit and SNB forums that mention the IPv6 test is unreliable.

      • Luther.1
      • yesterday
      • Reported - view

      turns out you're 100% spot on. I did my own testing connected directly to gateway (NTD) via LAN I was getting full speed. I then connected directly to router via LAN same result, I then thought I'd try the internal speedtest whilst connected via LAN and what do you know, the result was a 50% decrease. As a final test I placed my Macbook right next to the router but this time I tested via WiFi and low and behold the result was close to full speed, definitely over and above the results I was getting from the internal speedtest inside the Asus router. All was tested via ipv6.speed.test.net

      Appreciate your help once again. You'd think Asus would sort this out, it would save a lot of headache. So the buggy side of the internal speed test only affects ipv6 or ipv4 also?

      Many thanks..

      • tnpapa.1
      • yesterday
      • Reported - view

       From what I have read it affects IPv6 more, but its not consistent and varies from router to router because Asus uses two different Ethernet chipsets in their routers, even in the same model, Broadcom and Realtek. Broadcom chipsets have less flakey behaviour.  Just a matter of what batch of chips they used on the day they built each router.

      • Luther.1
      • 23 hrs ago
      • Reported - view

       im pretty sure my router has the broadcom chipset and personally I haven't had any issues that I've noticed with ipv4 but I can confirm now that there's definitely an issue with ipv6. 

      Cheers

      • tnpapa.1
      • 22 hrs ago
      • Reported - view

       You don't really have an issue with IPv6, just the Speedtest built into the router. Which means nothing. Your IPv6 is working as you could see from the test ran on your computer.

      Only way to know which Ethernet chipset you have is to open an SSH session  to the router and run the command  ethtool -i eth0

      You will see this result if it is a Broadcom Ethernet chip:

      driver: Broadcom Ethernet Interface
      version: 7.0

       

      • Luther.1
      • 11 hrs ago
      • Reported - view

      thanks for that, I don't think I'll bother, all seems to be running well now. Appreciate the support 👍

Content aside

  • 1 Likes
  • 11 hrs agoLast active
  • 36Replies
  • 173Views
  • 2 Following