Unifi UXG-MAX, not all DNS requests using profile
My problem is that in my profile dashboard, the status keeps alternating every few seconds from "All Good" to "This device is using NextDNS with no profile." Subsequently I'm getting hit and misses on my content mangement settings.
My Setup is using a DoH connection from a UXG-MAX gateway. This is configured with a custom DNS stamp based on the Linux - DNSCrypt stamp provided in the setup guide. The only difference is I specify my customer ID in the path /<Cust ID/<Dev Name>. This does seem to work as at times the status is all good, but every second or so the status flips. Looking at the Log all DNS requests are encrypted, so at least that is working 100%.
On the Gateway, I have blocked all outbound DNS from the LAN, so the gateway is the only path to NextDNS. I also don't have any secondary DNS services configured.
Requests to test.nextdns.io mirror this behaviour with some returning (sensitive data removed)
"status": "ok",
"protocol": "DOH",
"client": "xxx.xxx.xxx.xxx",
"srcIP": "xxx.xxx.xxx.xxx",
"destIP": "45.90.30.0",
"anycast": true,
"server": "vultr-ams-1",
"clientName": "dnscrypt"
and some returning
"status": "ok",
"protocol": "DOH",
"profile": "------------",
"client": "xxx.xxx.xxx.xxx",
"srcIP": "xxx.xxx.xxx.xxx",
"destIP": "45.142.244.191",
"anycast": false,
"server": "zepto-lon-1",
"clientName": "dnscrypt",
"deviceName": "UXGMax",
"deviceID": "----"
This looks to me like an error with load balancing which I assume NextDNS has setup. One resolver path gets correct response, while another path does not. Appreciate if anyone has further ideas on what I can do to test / trouble shoot and resolve this.
Many Thanks....Rob
Reply
Content aside
- 13 hrs agoLast active
- 7Views
-
1
Following
