home.social

#dnsmasq — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dnsmasq, aggregated by home.social.

fetched live
  1. Ubuntu 26.04 как маршрутизатор для GNS3: настраиваем NAT, DHCP и DNS в Hyper-V

    Как дать узлам внутри GNS3 доступ в интернет, не используя встроенный NAT Hyper-V? В этой статье превратим Ubuntu 26.04 в маршрутизатор лабораторного стенда. Настроим NAT, DHCP и DNS только средствами Linux. В результате Alpine получит сетевые параметры по DHCP, выйдет в интернет и мы установим на него клиент OpenSSH. Заодно разберем неочевидную проблему с маршрутом по умолчанию в Windows, из-за которой трафик физического хоста может попасть в петлю. Настраиваем стенд

    habr.com/ru/articles/1058702/

    #dnsmasq #dhcp #ubuntu #gns3 #gns3_vm #alpine #openssh #hyperv #nftables #powershell

  2. Ubuntu 26.04 как маршрутизатор для GNS3: настраиваем NAT, DHCP и DNS в Hyper-V

    Как дать узлам внутри GNS3 доступ в интернет, не используя встроенный NAT Hyper-V? В этой статье превратим Ubuntu 26.04 в маршрутизатор лабораторного стенда. Настроим NAT, DHCP и DNS только средствами Linux. В результате Alpine получит сетевые параметры по DHCP, выйдет в интернет и мы установим на него клиент OpenSSH. Заодно разберем неочевидную проблему с маршрутом по умолчанию в Windows, из-за которой трафик физического хоста может попасть в петлю. Настраиваем стенд

    habr.com/ru/articles/1058702/

    #dnsmasq #dhcp #ubuntu #gns3 #gns3_vm #alpine #openssh #hyperv #nftables #powershell

  3. Ubuntu 26.04 как маршрутизатор для GNS3: настраиваем NAT, DHCP и DNS в Hyper-V

    Как дать узлам внутри GNS3 доступ в интернет, не используя встроенный NAT Hyper-V? В этой статье превратим Ubuntu 26.04 в маршрутизатор лабораторного стенда. Настроим NAT, DHCP и DNS только средствами Linux. В результате Alpine получит сетевые параметры по DHCP, выйдет в интернет и мы установим на него клиент OpenSSH. Заодно разберем неочевидную проблему с маршрутом по умолчанию в Windows, из-за которой трафик физического хоста может попасть в петлю. Настраиваем стенд

    habr.com/ru/articles/1058702/

    #dnsmasq #dhcp #ubuntu #gns3 #gns3_vm #alpine #openssh #hyperv #nftables #powershell

  4. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  5. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  6. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  7. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  8. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  9. Can anyone out there who knows #IPv6, #dnsmasq and #OPNsense help me?

    I’m trying to figure out why DHCP clients on my LAN are respecting Option 6 to force IPv4 DNS servers, but not Option 23 for DNS over IPv6

    Much more detail here:
    forum.opnsense.org/index.php?t

  10. Can anyone out there who knows #IPv6, #dnsmasq and #OPNsense help me?

    I’m trying to figure out why DHCP clients on my LAN are respecting Option 6 to force IPv4 DNS servers, but not Option 23 for DNS over IPv6

    Much more detail here:
    forum.opnsense.org/index.php?t

  11. Can anyone out there who knows #IPv6, #dnsmasq and #OPNsense help me?

    I’m trying to figure out why DHCP clients on my LAN are respecting Option 6 to force IPv4 DNS servers, but not Option 23 for DNS over IPv6

    Much more detail here:
    forum.opnsense.org/index.php?t

  12. Can anyone out there who knows #IPv6, #dnsmasq and #OPNsense help me?

    I’m trying to figure out why DHCP clients on my LAN are respecting Option 6 to force IPv4 DNS servers, but not Option 23 for DNS over IPv6

    Much more detail here:
    forum.opnsense.org/index.php?t

  13. Can anyone out there who knows #IPv6, #dnsmasq and #OPNsense help me?

    I’m trying to figure out why DHCP clients on my LAN are respecting Option 6 to force IPv4 DNS servers, but not Option 23 for DNS over IPv6

    Much more detail here:
    forum.opnsense.org/index.php?t

  14. @rabautz ich habe erst mit #dnsmasq angefangen, wurde aber nicht warm damit. Bei weiterer Recherche kam ich auf #KeaDHCP und ich weis nicht wo ich es gelesen habe aber es wurde als neuer #DHCP Server gefeiert. Und mit Kea bin ich sehr gut klar gekommen und dabei geblieben.

    #OPNsense

  15. @rabautz ich habe erst mit #dnsmasq angefangen, wurde aber nicht warm damit. Bei weiterer Recherche kam ich auf #KeaDHCP und ich weis nicht wo ich es gelesen habe aber es wurde als neuer #DHCP Server gefeiert. Und mit Kea bin ich sehr gut klar gekommen und dabei geblieben.

    #OPNsense

  16. @rabautz ich habe erst mit #dnsmasq angefangen, wurde aber nicht warm damit. Bei weiterer Recherche kam ich auf #KeaDHCP und ich weis nicht wo ich es gelesen habe aber es wurde als neuer #DHCP Server gefeiert. Und mit Kea bin ich sehr gut klar gekommen und dabei geblieben.

    #OPNsense

  17. Hat sich schon wer zwischen #Dnsmasq (DHCP) und #KeaDHCP entschieden? Wenn ja für welches und warum?
    Kann mich gerade nicht entscheiden zu was ich auf meiner #Opnsense migrieren sollte.

  18. Hat sich schon wer zwischen #Dnsmasq (DHCP) und #KeaDHCP entschieden? Wenn ja für welches und warum?
    Kann mich gerade nicht entscheiden zu was ich auf meiner #Opnsense migrieren sollte.

  19. Hat sich schon wer zwischen #Dnsmasq (DHCP) und #KeaDHCP entschieden? Wenn ja für welches und warum?
    Kann mich gerade nicht entscheiden zu was ich auf meiner #Opnsense migrieren sollte.

  20. DoH на роутере OpenWRT, Mikrotik и Asus: пошаговая инструкция от того, кто сам хостит резолвер

    Если коротко, DNS это последний открытый протокол в вашей сети, по которому провайдер (и любой джентльмен в кафе на open WiFi) видит, куда вы ходите. HTTPS закрыли, SNI потихоньку прячут через ECH, а DNS как был в плейне на 53-м порту, так в большинстве домашних сетей и остался. DoH (DNS over HTTPS) это лечит, но не на устройстве, а на роутере, чтобы один раз настроил и забыл про все смартфоны, тостеры и умные лампочки. Я три месяца пилю свой DNS-резолвер с фильтрацией и за это время насмотрелся на чужие конфиги достаточно, чтобы написать инструкцию без воды. Разберу OpenWRT, Mikrotik (RouterOS 7+) и Asus с Merlin, плюс подводные камни, в которые я лично наступил.

    habr.com/ru/articles/1035612/

    #DoH #OpenWRT #Mikrotik #RouterOS #AsuswrtMerlin #dnsmasq #httpsdnsproxy #DNSoverHTTPS #роутер #privacy

  21. DoH на роутере OpenWRT, Mikrotik и Asus: пошаговая инструкция от того, кто сам хостит резолвер

    Если коротко, DNS это последний открытый протокол в вашей сети, по которому провайдер (и любой джентльмен в кафе на open WiFi) видит, куда вы ходите. HTTPS закрыли, SNI потихоньку прячут через ECH, а DNS как был в плейне на 53-м порту, так в большинстве домашних сетей и остался. DoH (DNS over HTTPS) это лечит, но не на устройстве, а на роутере, чтобы один раз настроил и забыл про все смартфоны, тостеры и умные лампочки. Я три месяца пилю свой DNS-резолвер с фильтрацией и за это время насмотрелся на чужие конфиги достаточно, чтобы написать инструкцию без воды. Разберу OpenWRT, Mikrotik (RouterOS 7+) и Asus с Merlin, плюс подводные камни, в которые я лично наступил.

    habr.com/ru/articles/1035612/

    #DoH #OpenWRT #Mikrotik #RouterOS #AsuswrtMerlin #dnsmasq #httpsdnsproxy #DNSoverHTTPS #роутер #privacy

  22. DoH на роутере OpenWRT, Mikrotik и Asus: пошаговая инструкция от того, кто сам хостит резолвер

    Если коротко, DNS это последний открытый протокол в вашей сети, по которому провайдер (и любой джентльмен в кафе на open WiFi) видит, куда вы ходите. HTTPS закрыли, SNI потихоньку прячут через ECH, а DNS как был в плейне на 53-м порту, так в большинстве домашних сетей и остался. DoH (DNS over HTTPS) это лечит, но не на устройстве, а на роутере, чтобы один раз настроил и забыл про все смартфоны, тостеры и умные лампочки. Я три месяца пилю свой DNS-резолвер с фильтрацией и за это время насмотрелся на чужие конфиги достаточно, чтобы написать инструкцию без воды. Разберу OpenWRT, Mikrotik (RouterOS 7+) и Asus с Merlin, плюс подводные камни, в которые я лично наступил.

    habr.com/ru/articles/1035612/

    #DoH #OpenWRT #Mikrotik #RouterOS #AsuswrtMerlin #dnsmasq #httpsdnsproxy #DNSoverHTTPS #роутер #privacy

  23. @openwrt It feels reassuring to see an OpenWRT release a short time after the #dnsmasq security fix with release notes explicitly mentioning said fix.

    #pfSense has been running incredibly stable for years on my home router but its update frequency feels questionable to me. I'm going to migrate to OpenWRT. After using it on some actual WiFi gear I am amazed how much OpenWRT has matured! 🤗

  24. @openwrt It feels reassuring to see an OpenWRT release a short time after the #dnsmasq security fix with release notes explicitly mentioning said fix.

    #pfSense has been running incredibly stable for years on my home router but its update frequency feels questionable to me. I'm going to migrate to OpenWRT. After using it on some actual WiFi gear I am amazed how much OpenWRT has matured! 🤗

  25. @openwrt It feels reassuring to see an OpenWRT release a short time after the #dnsmasq security fix with release notes explicitly mentioning said fix.

    #pfSense has been running incredibly stable for years on my home router but its update frequency feels questionable to me. I'm going to migrate to OpenWRT. After using it on some actual WiFi gear I am amazed how much OpenWRT has matured! 🤗

  26. @openwrt It feels reassuring to see an OpenWRT release a short time after the #dnsmasq security fix with release notes explicitly mentioning said fix.

    #pfSense has been running incredibly stable for years on my home router but its update frequency feels questionable to me. I'm going to migrate to OpenWRT. After using it on some actual WiFi gear I am amazed how much OpenWRT has matured! 🤗

  27. @openwrt It feels reassuring to see an OpenWRT release a short time after the #dnsmasq security fix with release notes explicitly mentioning said fix.

    #pfSense has been running incredibly stable for years on my home router but its update frequency feels questionable to me. I'm going to migrate to OpenWRT. After using it on some actual WiFi gear I am amazed how much OpenWRT has matured! 🤗

  28. Okay, so I’ve been hating on the #Verizon #CR1000A router that was tossed in for free with my #fios internet service. It’s really not THAT bad. From a software standpoint, it’s quite feature rich and powerful being primarily powered by #dnsmasq. It probably uses #Linux. It’s lacking in the hardware department having an anemic CPU but it does have a 10Gbps Ethernet port.

    Overall, I’ll regrade it from a C- to somewhere between a B+/A-. I think Verizon probably realized they underpowered it because the next generation CR1000B is better. I think they’re giving the A out to lower end customers like myself with only the 300Mbps service.

    Nevertheless it can do QoS, VLANs, and more. 👍

  29. Okay, so I’ve been hating on the #Verizon #CR1000A router that was tossed in for free with my #fios internet service. It’s really not THAT bad. From a software standpoint, it’s quite feature rich and powerful being primarily powered by #dnsmasq. It probably uses #Linux. It’s lacking in the hardware department having an anemic CPU but it does have a 10Gbps Ethernet port.

    Overall, I’ll regrade it from a C- to somewhere between a B+/A-. I think Verizon probably realized they underpowered it because the next generation CR1000B is better. I think they’re giving the A out to lower end customers like myself with only the 300Mbps service.

    Nevertheless it can do QoS, VLANs, and more. 👍

  30. CERT/CC just dropped 6 new CVEs for dnsmasq, many found by AI. These critical memory safety and input validation flaws, including heap overflows, affect everything from home routers to Linux distros. The maintainer called it 'a tsunami of AI-generated bug reports,' highlighting a new era of open-source security challenges and the 'Frankenstein' problem of distro updates. Learn how these…

    tpp.blog/xv2t6x0

    #cybersecurity #certcc #dnsmasq

    🤖 This post was AI-generated.

  31. 🚨 OMG, #dnsmasq is exploding! 🚨 In a shocking twist of fate, CERT drops six #CVEs on lazy vendors who didn't realize their software was a ticking time bomb. Apparently, "longstanding bugs" means "we've ignored this for years, but now it's an emergency" 😂.
    lists.thekelleys.org.uk/piperm #cybersecurity #softwarebugs #vendorresponsibility #emergencyfix #HackerNews #ngated

  32. 🚨 OMG, #dnsmasq is exploding! 🚨 In a shocking twist of fate, CERT drops six #CVEs on lazy vendors who didn't realize their software was a ticking time bomb. Apparently, "longstanding bugs" means "we've ignored this for years, but now it's an emergency" 😂.
    lists.thekelleys.org.uk/piperm #cybersecurity #softwarebugs #vendorresponsibility #emergencyfix #HackerNews #ngated

  33. 🚨 OMG, #dnsmasq is exploding! 🚨 In a shocking twist of fate, CERT drops six #CVEs on lazy vendors who didn't realize their software was a ticking time bomb. Apparently, "longstanding bugs" means "we've ignored this for years, but now it's an emergency" 😂.
    lists.thekelleys.org.uk/piperm #cybersecurity #softwarebugs #vendorresponsibility #emergencyfix #HackerNews #ngated

  34. 🚨 OMG, #dnsmasq is exploding! 🚨 In a shocking twist of fate, CERT drops six #CVEs on lazy vendors who didn't realize their software was a ticking time bomb. Apparently, "longstanding bugs" means "we've ignored this for years, but now it's an emergency" 😂.
    lists.thekelleys.org.uk/piperm #cybersecurity #softwarebugs #vendorresponsibility #emergencyfix #HackerNews #ngated

  35. 🚨 OMG, #dnsmasq is exploding! 🚨 In a shocking twist of fate, CERT drops six #CVEs on lazy vendors who didn't realize their software was a ticking time bomb. Apparently, "longstanding bugs" means "we've ignored this for years, but now it's an emergency" 😂.
    lists.thekelleys.org.uk/piperm #cybersecurity #softwarebugs #vendorresponsibility #emergencyfix #HackerNews #ngated

  36. Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq

    Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.

    habr.com/ru/articles/1033562/

    #iptables #bonding #dns #linux #dnsmasq

  37. Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq

    Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.

    habr.com/ru/articles/1033562/

    #iptables #bonding #dns #linux #dnsmasq

  38. Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq

    Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.

    habr.com/ru/articles/1033562/

    #iptables #bonding #dns #linux #dnsmasq

  39. So it turns out #FreeBSD via #PXE only uses #TFTP for the initial boot but expects `/boot/lua/loader.lua` to be loaded via #NFS, the root of which it expects to get via #DHCP but #dnsmasq won't supply this when in proxy mode.

    Joy.

  40. So it turns out #FreeBSD via #PXE only uses #TFTP for the initial boot but expects `/boot/lua/loader.lua` to be loaded via #NFS, the root of which it expects to get via #DHCP but #dnsmasq won't supply this when in proxy mode.

    Joy.

  41. So neither .iso nor .img will boot #FreeBSD off of a USB thumbdrive or another, ventoy or raw.
    The #ThinkCentre M73 freezes at installer boot screen.

    #PXE it is. Weirdly #dnsmasq changes the boot file (#wireshark showed me it appends `.0`) in the proxy ACK, but not in the original offer. Whatever, `cp`.

    But now it seems like the file size is erroneously transfered, and therefore the #TFTP transfer gleefully halts mid-file.

    At least now it's stalled at a blinking cursor instead of freezing.

    Sigh...

    #homelab #selfhosting #bsd

  42. So neither .iso nor .img will boot #FreeBSD off of a USB thumbdrive or another, ventoy or raw.
    The #ThinkCentre M73 freezes at installer boot screen.

    #PXE it is. Weirdly #dnsmasq changes the boot file (#wireshark showed me it appends `.0`) in the proxy ACK, but not in the original offer. Whatever, `cp`.

    But now it seems like the file size is erroneously transfered, and therefore the #TFTP transfer gleefully halts mid-file.

    At least now it's stalled at a blinking cursor instead of freezing.

    Sigh...

    #homelab #selfhosting #bsd

  43. @lattera

    Do you really want to use software distributed via unauthenticated channels (looks like it isn't anymore)? I suggested the authors years ago and he flat out said he did didn't want to and didn't see any value in using https.

    I don't trust people who have that attitude about security to write software that I run.

    #dnsmasq

  44. @lattera

    Do you really want to use software distributed via unauthenticated channels (looks like it isn't anymore)? I suggested the authors years ago and he flat out said he did didn't want to and didn't see any value in using https.

    I don't trust people who have that attitude about security to write software that I run.

    #dnsmasq

  45. @lattera

    Do you really want to use software distributed via unauthenticated channels (looks like it isn't anymore)? I suggested the authors years ago and he flat out said he did didn't want to and didn't see any value in using https.

    I don't trust people who have that attitude about security to write software that I run.

    #dnsmasq