0

NextDNS with mwan3 in OpenWrt/FriendlyWrt 24.10

Hello folks,

I don't know if it's bug or something but once I setup NextDNS with my FriendlyWrt 24.10 together with mwan3 for multi-WANs of VNPT and FPT in Vietnam, one IPv4 of FPT (or perhaps VNPT?) was missing out.

Normally when I setup OpenWrt with `mwan3`, `odhcpd` and `unbound` for DNS-over-TLS with Cloudflare (1.1.1.2) blocking malware, I have fully received 4 Public IP address as:

VNPT IPv4

FPT IPv4

VNPT IPv6

FPT IPv6

`dnsmasq` cannot serve me well since I got `odhcpd` and `unbound` for taking care of DHCP and DNS already. 

But when I configured NextDNS with mwan3 only, I was missing one public IPv4. I used anycast IP addresses of NextDNS for configuring general settings for these two WANs respectively for IPv4 & 6 interfaces:

45.90.28.0
45.90.30.0
2a07:a8c0::
2a07:a8c1::

 

 

 

 

5 replies

null
    • Corgei
    • 7 days ago
    • Reported - view

    By the way, I could not find anywhere to edit my topic...

      • BigDargon
      • 7 days ago
      • Reported - view

       Forum configuration only takes 45 minutes to edit content.

    • BigDargon
    • 7 days ago
    • Reported - view

    Hi,

    If you use NextDNS to filter domain names with multiple WANs, use NextDNS Cli or https-dns-proxy. When querying DNS over multiple WANs, with IPv4 you have to link-ip but only accept 1 IP, if querying from the remaining WANs it will not be possible.

    I recommend you to use encrypted DNS, multiple WAN addresses using 1 config ID is fine. You can refer to the https-dns-proxy configuration guide here (or use nextdns-cli) https://voz.vn/t/tat-tan-tat-ve-dich-vu-nextdns.522718/post-23369797

      • Corgei
      • 4 days ago
      • Reported - view

       Well... I changed my setup, for clients inside my network, I'll use NextDNS app, for the router itself, I still configure it with dnsmasq (no-resolv for DNS, DNS forwarding to 127.0.0.1#5353), unbound (port 5353, for DNS-over-TLS with 1.1.1.2), mwan3 (for combining 2 WANs) and adblock (forcing port 53, 853 and 5353) in OpenWrt/FriendlyWrt 24.10.

      • BigDargon
      • 2 days ago
      • Reported - view

       Nice.. Currently, I also deploy NextDNS to each device in the company's network, avoiding dependence on the router. The router DNS will serve visitors, devices that do not support encrypted DNS.

Content aside

  • 2 days agoLast active
  • 5Replies
  • 53Views
  • 2 Following