Project

General

Profile

Actions

Todo #13456

closed

Feedback on pfSense® software Configuration Recipes — Configuring DNS over TLS

Added by Sean McBride about 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
DNS
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:

Description

Page: https://docs.netgate.com/pfsense/en/latest/recipes/dns-over-tls.html

Feedback:

For the "Enable DNS over TLS Server (optional)" section (at the end):

1) The use of "must" is too strong in this sentence "Only enable this feature if local clients must talk to the DNS Resolver using DNS over TLS queries." That may scare people away from enabling it, and really it should be encouraged to turn this on.

2) I would suggest also adding a sentence like: "DoT is supported by iOS 14, macOS 11 Big Sur, Android 9 (Pie), and systemd-resolved (not sure of version)."

3) The sentence "Now the DNS Resolver will listen for DNS over TLS queries from local clients on port 853." would be better if it said "*TCP* port 853" (as opposed to UDP, like plain old DNS).

but most importantly:

4) It should address https://redmine.pfsense.org/issues/13454 and https://redmine.pfsense.org/issues/13393 That is, it should say that one must not select "All" for the network interfaces.

Actions

Also available in: Atom PDF