home.social

#dnsmasq — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dnsmasq, aggregated by home.social.

fetched live
  1. Ubuntu 26.04 как маршрутизатор для GNS3: настраиваем NAT, DHCP и DNS в Hyper-V

    Как дать узлам внутри GNS3 доступ в интернет, не используя встроенный NAT Hyper-V? В этой статье превратим Ubuntu 26.04 в маршрутизатор лабораторного стенда. Настроим NAT, DHCP и DNS только средствами Linux. В результате Alpine получит сетевые параметры по DHCP, выйдет в интернет и мы установим на него клиент OpenSSH. Заодно разберем неочевидную проблему с маршрутом по умолчанию в Windows, из-за которой трафик физического хоста может попасть в петлю. Настраиваем стенд

    habr.com/ru/articles/1058702/

    #dnsmasq #dhcp #ubuntu #gns3 #gns3_vm #alpine #openssh #hyperv #nftables #powershell

  2. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  3. Can anyone out there who knows #IPv6, #dnsmasq and #OPNsense help me?

    I’m trying to figure out why DHCP clients on my LAN are respecting Option 6 to force IPv4 DNS servers, but not Option 23 for DNS over IPv6

    Much more detail here:
    forum.opnsense.org/index.php?t

  4. @rabautz ich habe erst mit #dnsmasq angefangen, wurde aber nicht warm damit. Bei weiterer Recherche kam ich auf #KeaDHCP und ich weis nicht wo ich es gelesen habe aber es wurde als neuer #DHCP Server gefeiert. Und mit Kea bin ich sehr gut klar gekommen und dabei geblieben.

    #OPNsense

  5. Hat sich schon wer zwischen #Dnsmasq (DHCP) und #KeaDHCP entschieden? Wenn ja für welches und warum?
    Kann mich gerade nicht entscheiden zu was ich auf meiner #Opnsense migrieren sollte.

  6. DoH на роутере OpenWRT, Mikrotik и Asus: пошаговая инструкция от того, кто сам хостит резолвер

    Если коротко, DNS это последний открытый протокол в вашей сети, по которому провайдер (и любой джентльмен в кафе на open WiFi) видит, куда вы ходите. HTTPS закрыли, SNI потихоньку прячут через ECH, а DNS как был в плейне на 53-м порту, так в большинстве домашних сетей и остался. DoH (DNS over HTTPS) это лечит, но не на устройстве, а на роутере, чтобы один раз настроил и забыл про все смартфоны, тостеры и умные лампочки. Я три месяца пилю свой DNS-резолвер с фильтрацией и за это время насмотрелся на чужие конфиги достаточно, чтобы написать инструкцию без воды. Разберу OpenWRT, Mikrotik (RouterOS 7+) и Asus с Merlin, плюс подводные камни, в которые я лично наступил.

    habr.com/ru/articles/1035612/

    #DoH #OpenWRT #Mikrotik #RouterOS #AsuswrtMerlin #dnsmasq #httpsdnsproxy #DNSoverHTTPS #роутер #privacy

  7. @openwrt It feels reassuring to see an OpenWRT release a short time after the #dnsmasq security fix with release notes explicitly mentioning said fix.

    #pfSense has been running incredibly stable for years on my home router but its update frequency feels questionable to me. I'm going to migrate to OpenWRT. After using it on some actual WiFi gear I am amazed how much OpenWRT has matured! 🤗

  8. If you use #dnsmasq on @fedora or @centos Stream - be aware that there are recently disclosed CVEs - kb.cert.org/vuls/id/471747

    @SUSE at least rates one of them a 9.2 on the CVSS 4.0 scale

    suse.com/security/cve/CVE-2026

    Fedora updates for stable releases are about to hit testing: bodhi.fedoraproject.org/update

    and if you have the #CentOSHyperscale repo enabled you can `sudo dnf install centos-release-hyperscale-testing && sudo dnf update 'dnsmasq*'`

    Please give feedback for the Fedora builds and for the Hyperscale ones if you give them a spin!

    gitlab.com/CentOS/Hyperscale/r

    As of the time of posting there is no advisory from #RedHat yet

    #Fedora
    #CentOS
    #CentOS_Stream

  9. 🚨 OMG, #dnsmasq is exploding! 🚨 In a shocking twist of fate, CERT drops six #CVEs on lazy vendors who didn't realize their software was a ticking time bomb. Apparently, "longstanding bugs" means "we've ignored this for years, but now it's an emergency" 😂.
    lists.thekelleys.org.uk/piperm #cybersecurity #softwarebugs #vendorresponsibility #emergencyfix #HackerNews #ngated

  10. Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq

    Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.

    habr.com/ru/articles/1033562/

    #iptables #bonding #dns #linux #dnsmasq

  11. @lattera

    Do you really want to use software distributed via unauthenticated channels (looks like it isn't anymore)? I suggested the authors years ago and he flat out said he did didn't want to and didn't see any value in using https.

    I don't trust people who have that attitude about security to write software that I run.

    #dnsmasq

  12. and then my DNS failed again 😭
    But this time it was my upstream non-HA unbound on opnsense that just terminated.
    unbound is serving my local dhcp entries and some magic.. those are not replicated to the backup system :(

    monit to the rescue! it will (re)start unbound no in case of failure.

    #dns #dnsmasq #monit #opnsense #ha #unbound

  13. Also ein Flat LAN mit Fritz!Box, Pihole und rund 75 Netzwerkgeräten in ein ausgewachsenes Business LAN mit OPNsense, Omada, mehreren Access Points und alles schön getrennt in VLANS umzubauen, ist echt ne Lebensaufgabe, bis alles reibungslos funktioniert....... 😛

    #opnsense #omada #tplink #dnsmasq #unbounddns #selfhosted #network #netzwerk #fritzbox #homeassistant

  14. Chromecast said "Not connected to the internet", rendering it unusuable.

    I drop all external DNS (and DNS-over-TLS) requests on my network.

    Google (along with Chinese IoT spyware, Samsung, and others) now try to use their hardcoded DNS servers.

    My network now fools them all, they think they get a response from their DNS, but it's really my PiHole that answers! NAT + Masquerading FTW!

    See the diagram for a simplified overview

    AMA

    #ama #chromecast #chromecastultra #dns #nat #masquerading #dnsmasq #pihole #networking #adblock #fuckads #samsung #spyware #malware #dns

  15. I had read good reviews about the #GL-iNet #routers so I purchased one of their products around 18 months ago. One of my main motivations was supporting, at some level, #OpenWrt and including tools like #AdGuardHome and #Wireguard.

    But to be honest, it all has been a bit disappointing.

    AdGuardHome never worked very well. Apart from being slow, the service would frequently freeze (e.g. whenever I updated the custom filter) and I had to manually restart it.

    In addition, the system stack was quite messy and difficult to make sense of. For example, the #DNS service #Dnsmasq could be managed directly or via Openwrt, sometimes creating unintended problems.

    Anyway, the router decided to implode after a firmware upgrade, which is quite underwhelming. I tried a few things like reflashing Uboot, factory reset, etc. before deciding to just toss it away and get another one, from a different brand.

  16. Switched from DHCP to on .

    The transition wasn't very smooth as the update process disabled without enabling so essentially you had to assign static ips to restore your setup after the update, yikes.

    Anyway, now finally running a DHCP server that can do both ipv4 and ipv6 in a single process.

  17. When upgrading I would have really liked to know in advance that it would remove my DHCP static ips and remove the current DHCP server without automatically enabling the new server.

    I've found this wasn't very clear in advance.

    Both having to first create static routes to reconfigure as well as having to rebuild my ranges and static IPs from memory was a pity.

    Having a single DHCP server do both the IPV4 and IPV6 in one overview is really nice though!

  18. @pid_eins this clearly conflicts with previous declaration systemd-resolved is stub only, not a server. I expect networkd would not recommend non-systemd implementations? I can see this as replacement. But Dnsmasq never was a DNS stub client. Does this introduce systemd-dhcpd? Is there a plan to reimplement also radvd?