-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Installation on EdgeOS
The following instructions were tested on an ERLite-3 running EdgeOS 1.10.x.
Install dnsutils. Consult the EdgeOS documentation if you encounter problems with the installation.
sudo apt-get install -y dnsutils
sudo ntpdate -b 216.239.35.0Remove the dnssec option from /etc/dnsmasq.conf.
It's safe to set system DNS for the router, even if it will be ignored by dnsmasq. This can prevent problems while the router boots and dnscrypt-proxy is not yet available. Call:
show dns forwarding nameservers
If there are no nameservers provided by the system, or there is only one nameserver from your ISP, configure one:
configure
set system name-server 1.1.1.1
commit
save
Log in to your router with SSH. Download the MIPS64 binary from the releases page (update the version number):
curl -L -o dnscrypt-proxy.tar.gz https://github.com/DNSCrypt/dnscrypt-proxy/releases/download/2.1.17/dnscrypt-proxy-linux_mips64-2.1.17.tar.gzUnpack the content of this archive:
tar xzf dnscrypt-proxy.tar.gzThis will create the linux-mips64 folder.
Check whether the downloaded binary is compatible with your processor:
linux-mips64/dnscrypt-proxy -versionIf you see a version, it's all good. Otherwise, try a different binary. Maybe you have an ER-X, so try the MIPSLE binary.
Now is a good moment to create and edit the configuration file:
cp linux-mips64/example-dnscrypt-proxy.toml linux-mips64/dnscrypt-proxy.toml
vi linux-mips64/dnscrypt-proxy.tomlThe most important part is to edit listen_addresses. I propose the following change:
listen_addresses = ['127.0.0.1:5353']Optionally, improve performance by enabling this entry:
tls_cipher_suite = [52392, 49199]When done, move the whole folder to /config/ under a new name:
sudo mv linux-mips64 /config/dnscrypt-proxyCreate an executable script that will reinstall and start dnscrypt-proxy after a system upgrade:
echo '#!/bin/sh' | sudo tee /config/scripts/post-config.d/dnscrypt.sh
echo '/config/dnscrypt-proxy/dnscrypt-proxy -service install' | sudo tee -a /config/scripts/post-config.d/dnscrypt.sh
echo '/config/dnscrypt-proxy/dnscrypt-proxy -service start' | sudo tee -a /config/scripts/post-config.d/dnscrypt.sh
sudo chmod +x /config/scripts/post-config.d/dnscrypt.shNow you can try to start dnscrypt-proxy. Use the freshly created script:
sudo /config/scripts/post-config.d/dnscrypt.shIf no error is thrown, see which nameservers dnscrypt-proxy is using:
/config/dnscrypt-proxy/dnscrypt-proxy -listCheck whether the proxy is able to resolve names:
/config/dnscrypt-proxy/dnscrypt-proxy -resolve dnscrypt.info
dig @localhost -p 5353 google.comYou should get an answer. Refer to /var/log/messages for debugging.
If all went well, configure the router settings:
configure
Redirect DNS requests to dnscrypt-proxy:
set service dns forwarding options 'server=127.0.0.1#5353'
set service dns forwarding options proxy-dnssec
Prevent dnsmasq from using your ISP's DNS (eth0 is the WAN port):
set interfaces ethernet eth0 dhcp-options name-server no-update
Make sure dnsmasq is not using the system nameserver:
delete service dns forwarding system
Remove the dnsmasq cache because dnscrypt-proxy caches internally, and it's unnecessary to double-cache queries:
set service dns forwarding cache-size 0
Make sure dnsmasq is not using the content of /etc/resolv.conf:
set service dns forwarding options no-resolv
Commit changes and activate redirection to proxy:
commit
Check the connection. Initially, it can take a while until all your devices react correctly.
Test whether there are no queries sent in "plain text":
sudo tcpdump -i eth0 dst port 53 or src port 53 -n -x -X -vImportant: perform tests while using the internet from devices within your local network. For comparison, run this from another session on the router:
sudo nslookup dnscrypt.info
ping github.comThis will produce a large amount of plain-text output, as locally run requests travel through the system nameserver and are not encrypted.
If nothing works, check the logs in /var/log/messages. Revert the router DNS redirect with:
load; commit
When DNS works as expected, save configuration and make it permanent:
save
- Home
- Installation
- Configuration
- Checking that your DNS traffic is encrypted
- Automatic Updates
- Server sources
- Combining blocklists
- Public Blocklist and other configuration files
- Building from source
- Run your own DNSCrypt server in under 10 minutes
- DNS stamps specifications
- Windows tips
- dnscrypt-proxy in the media
- Planned Features