Unifi UDMP-SE Custom DNS Shield - Multiple Profiles/Servers?
I have multiple profiles on my NextDNS service. I use the NextDNS CLI on my UDM Pro SE and my config file for that assigns the profile based on the network or MAC address of the device. I am able to add multiple custom DNS Shield servers to my UDM Pro SE, one for each of my profiles.
Okay .... now what? Is this even doing anything? I think it may be, as I was getting some undesirable logs in the NextDNS app when I didn't have the Stamps configured correctly. It looks like things are correct now in those logs. Is the custom DNS Shield compatible with the NextDNS CLI? Can you use both at the same time? Is it possible to assign the custom DNS Shield server to be used by network or MAC address, like you can in the NextDNS CLI? I was thinking that the NextDNS CLI may not be needed if that was possible. Seems like it may be a useful feature, but I am not sure of the proper implementation for my situation. Any guidance would be appreciated. Thank you.
13 replies
-
Most advanced features of the CLI like multi-profiles or LAN client identification in the log won’t be supported by DNS shield.
-
Unfortunately, you won't be able to identify clients without the CLI. However, after much consideration, I'm not going to install the CLI on my EFG. Just too high of a risk to cause something to break.
I really wish NextDNS would work with Ubiquiti to have an officially supported integration so firmware updates won't break it. Would generate more business for NextDNS, and it would allow users to have client identification, multiple profiles, etc.
I believe eventually Ubiquiti will partner with a DNS service. Question will be who gets their interest first. NextDNS, ControlD, DNSFilter, etc.
-
The DNS Stamp I am using in the custom DNS Shield is here:
sdns://AgEAAAAAAAAAGzQ1LjkwLjI4LjAvMjQsNDUuOTAuMzAuMC8yNKDMEGDTnIMptitvvH0NbfkwmGm5gefmOS1c2PpAj02A5iCaOjT3J965vKUQA9nOnDn48n3ZxSQpAcK6saROY1oCGRNkb2gzLmRucy5uZXh0ZG5zLmlvEi9hYmMxMjMvZGV2aWNlTmFtZQ
I replaced my real profile ID with 'abc123' in this stamp so you will need to update that. Go to https://dnscrypt.info/stamps/ and paste the stamp above in, then change the path to your profile ID and the resulting stamp will be for your profile ID.
In my very limited testing this seemed to work for my main profile ID, although it may have been that that I did not re-start the router after making some changes and some caching was still in play. It may be some time before I can more full test this on my home network. I am curious if anyone is able to use the custom DNS Shield server on their Unifi router with their NextDNS profile ID and have the LAN device names come through in the NextDNS logs without using the NextDNS CLI.
Content aside
- 2 mths agoLast active
- 13Replies
- 970Views
-
4
Following