0

Ubiquiti Cloud Gateway: install via SSH and CLI or simply enter DNS-over-HTTPS URL into UniFi OS?

I see the provided CLI script and I am capable of SSHing, but I'm wondering what the exact benefits of using the CLI over simply entering the URL into the UniFi UI are?

Are there things that can be configured by the CLI that I can't configure on my profile at https://my.nextdns.io/?

Is the CLI simply a way to do it from earlier times before UniFi offered a way to do in their UI? Or are there still advantages to using the CLI?

CLI Instructions I'm referring to: https://github.com/nextdns/nextdns/wiki

Aside, after reading https://help.nextdns.io/t/x2hmvas/what-is-dns-over-tls-dot-dns-over-quic-doq-and-dns-over-https-doh-doh3, I'm convinced to use DNS-over-HTTPS. If anyone is wondering why I specific in the title.

3 replies

null
    • Deltasse
    • 18 hrs ago
    • Reported - view

    NextDNS CLI: it was the way to doing it before UniFi implemented a way to do it. That approach comes with some benefits and many drawbacks.

    pros:

    individual devices naming despite being behind your router,

    cons:

    non-persistant, need to be reinstated after every single update.

    advance protection system non working with the CLI. (Content filter, packet origin localization, setting propagation across multiple ap, …)

    ———————————

     UniFi UI: now Unifi support that features, it’s possible solve those issues.

    pros: 

    all advance protection working together without know issues so far.

    Configuration persistence through every update.

    cons:

    no device individual naming. All traffic coming through your Unifi router will be marked as coming from that router. You can still install a NextDNS on individual devices (phone, pc, tablet) but their traffic will only appear coming from them only when they are outside your Unifi network 

    • My_Name_Is
    • 17 hrs ago
    • Reported - view

    I hope we get a method that is a simple as the UI but also still labels individual devices in the NextDNS web app - that would be the best of both worlds!

    I wonder if there could be a variant on the CLI that labels devices and otherwise acts as a passthrough?

      • Deltasse
      • 14 hrs ago
      • Reported - view

       

      I would say you don’t need the CLI label names. 
       

      the Unifi dpi graphics does it too. 
       

      if you use the CLI, the CLI allows identified packets without any intervention. Which the dpi fonction see as unknown or ssl encrypted packet 

      while in UI, all packets are firstly checked by the dpi and recorded into the UniFi analysis dashboard before being send to the encrypted dns. 
       

      Depending upon your preference and installation preferences. You may wish having the labels. But are they really necessary when you have another way to track the packets? 

Content aside

  • 14 hrs agoLast active
  • 3Replies
  • 31Views
  • 2 Following