NextDNS issues with DoT on ASUS Merlin
 
    Hello all,
Been having some issues for a while now when using the DoT functions natively supported in ASUS Merlin. Pages time out and often will sit with an "error not resolved" message for roughly 4-5 seconds before the page will refresh and load content.
 (This happens with or without DNS Filter active; Model AX-88U)
 
I have done a complete reset of the router, and used the NextDNS CLI (which doesn't have errors, but resolves slower) but for whatever reason the NextDNS DoT implementation doesn't seem to like the ASUS Merlin firmware anymore, or there's a CDN issue with DoT for the Atlanta region.
I have since disabled any options within the Performance tab of the website, and still am having issues. To the point that many of the diagnostic services for NextDNS itself will not work or report well. Options on the router are minimal outside of factory defaults, with IPv6 and DoT setup being the only noteable changes.
My ISP is AT&T U-verse/Fiber.
 
I preferred the DoT implementation as hostnames from the CLI can flood the logs with various (blank) names, and the DoT doesn't have to be regularly updated.
57 replies
- 
  Ditto. I cannot keep NextDNS engaged as the DNS DoT provider longer than about 12 hours since hitting Merlin 386.2 with a manual DoT setup. I have been using "stubby -l" to watch it step down the listing from NextDNS to QUAD9 and Cloudflare in about a 12 hour window. Sometime in there, DNSMASQ will "go bonkers" and I have to reboot the router usually to fully recover. Sometimes just restarting DNSMASQ will recover but most times when I check the stubby window it's had some failures and is well into using the other DNS providers. I've been fighting with this for weeks now on a brand new AX86U, total greenfielded from ground up. Please keep in touch. Stay safe, stay alive. 
- 
  I feel like I'm chasing the same issue since updating to Merlin 386.2_0 and 386.2_2 
 
 Any progress with this? I've disabled DoS under firewall at the moment and the issue hasn't returned, it's only been 17 hours since I disabled it though.
- 
  for asus-merlin its best to use the amtm utility and install dnscrpt and configure to use nextdns DoH works much better than the nextdns-cli and also supports asus dnsfilter which nextdns-cli does not. 
- 
  BS said: 
 I preferred the DoT implementation as hostnames from the CLI can flood the logs with various (blank) names, and the DoT doesn't have to be regularly updated.Why don't use disable query-logs to avoid the flood? CLI is pretty stable, you don't need to update it. For your dot issue, please submit a https://nextdns.io/diag 
- 
  My problem with NEXTDNS CLI on Merlin is different. Everything starts ok, as the CLI retrieves the nearest (and with lowest ping) server. In fact, there are two servers here in Portugal which I have exactly the same ping on both, and it keeps switching from one to another. Nothing wrong. The problem is, after a couple of hours the CLI changes the server to anycast, which is getting me a server with the triple of the ping (on Spain), and it keeps there forever. In order to come back to the steering server, I have to manually restart nextdns CLI. Any thoughts? 
- 
  Good morning/afternoon everyone. 
 
 Sorry to bump this topic, but I think I may have figured out what's causing the issue (fingers crossed) regarding the ASUSMerlin DoT implementation, and NextDNS...
 
 I noticed after using the DoT method, that pages were failing to resolve with "ERR_NAME_NOT_RESOLVED" as the Chromium error message.
 
 What I've discovered (SO FAR) is there's an issue with handshake/authentication with NextDNS services for some reason when this option is set to STRICT.I don't know if this is due to using a device name for the DoT resolution, "AX-88U-XXXXXX.dns.nextdns.io" or something else. 
 
 I'm unsure if this is an authentication factor on NextDNS's behalf, or some handshake requirement of ASUSMerlin... but I can confirm (with optimistic hesitation) that setting to OPPORTUNISTIC has resolved my DoT issues so far.
 
 I will bump/update if the problem continues after this adjustment.
Content aside
- Status Fixed
- 
    1
    
      Votes
    
- 3 yrs agoLast active
- 57Replies
- 3703Views
- 
    11
    Following
    

 
         
         
        