|
OpenBSD Security Functionally paranoid! |
|
Thread Tools | Display Modes |
|
|||
DNSCRYPT-Proxy causes slowdown on one service only
Testing my new firewall running pf on OpenBSD I have noticed something quite odd.
All of my machines get a constant 60Mbps downstream. Except for he xbox. I had originally thought hat maybe one of my pf rules was causing the issue. I have since narrowed it down to the dnxcrypt proxy. If I keep this rule in place: Code:
### Block Rogue DNS requests from LAN clients on port 53 then log and Redirect to use DNSCrypt and Unbound block return out quick log on egress proto { tcp udp } from any to any port 53 pass in on em1 inet proto { tcp udp } from any to ! 192.168.10.1 port 53 rdr-to 192.168.10.1 I have looked everywhere on google trying to see if I can find a reference to this and no go. i have tried specifying multiple dnscrypt servers on the list, turning dnssec off and no change. How would one go about resolving this as it seems to be the dnscrypt that is causing the issues. Could I just change the rules as follows (change in bold): Code:
### Block Rogue DNS requests from LAN clients on port 53 then log and Redirect to use DNSCrypt and Unbound block return out quick log on egress proto { tcp udp } from ! $xbox to any port 53 pass in on em1 inet proto { tcp udp } from any to ! 192.168.10.1 port 53 rdr-to 192.168.10.1 Open to any ideas to fix the speed issue with dnscrypt. Thanks |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
DNSCrypt and local Unbound resolver | Oko | OpenBSD Security | 1 | 28th December 2014 12:54 AM |
dnscrypt-proxy build errors? | gkbsd | OpenBSD Packages and Ports | 7 | 3rd May 2014 01:12 PM |
Security DNSCrypt: a tool to encrypt all DNS traffic | J65nko | News | 0 | 8th December 2011 08:13 PM |
Good VPN service? | guitarscn | Off-Topic | 2 | 15th December 2009 08:55 AM |
service prioritization | badguy | OpenBSD General | 1 | 29th July 2009 05:36 PM |