Lede 上设置 Ubound DOH 的疑问 - V2EX
首页
注册
登录
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
现在注册
已注册用户请
登录
DNS 参考资料
List of DNS Record Types
dig 使用说明
djbdns
DNS Parameters
dnslib for Python
广告
V2EX
span class="chevron">
DNS
Lede 上设置 Ubound DOH 的疑问
imswing
2019-06-22 13:06:32 +08:00
via iPhone 6661 次点击
这是一个创建于 2302 天前的主题,其中的信息可能已经有所发展或是发生改变。
lean 的源码编译的固件,加入了 Ubound 和$$R,Unbound 本地监听 5335,$$R 里和 dnsmasq 设置的 DNS 转发是 127.0.0.1#5335,但是一开启 tcp-upstream 和 ssl-upstream 就不能上网,是我的使用姿势不对吗? Ubound 配置文件如下:
```
server:
port: 5335
access-control: 10.0.0.0/8 allow
access-control: 127.0.0.0/8 allow
access-control: 192.168.0.0/16 allow
cache-max-ttl: 14400
cache-min-ttl: 900
do-tcp: yes
do-udp: yes
hide-identity: yes
hide-version: yes
interface: 0.0.0.0
minimal-responses: yes
prefetch: yes
qname-minimisation: yes
rrset-roundrobin: yes
ssl-upstream: no
tcp-upstream: yes
use-caps-for-id: yes
verbosity: 1
do-ip4: yes
do-ip6: yes
outgoing-port-permit: "10240-65335"
outgoing-range: 60
num-queries-per-thread: 30
msg-buffer-size: 8192
infra-cache-numhosts: 200
msg-cache-size: 100k
rrset-cache-size: 100k
key-cache-size: 100k
neg-cache-size: 10k
target-fetch-policy: "2 1 0 0 0 0"
harden-large-queries: yes
harden-short-bufsize: yes
include: "/etc/unbound/accelerated-domains.china.unbound.conf"
include: "/etc/unbound/apple.china.unbound.conf"
include: "/etc/unbound/google.china.unbound.conf"
forward-zone:
name: "."
forward-addr: 1.1.1.1@853
forward-addr: 8.8.8.8@853
forward-addr: 114.114.114.114
```
yes
unbound
ubound
allow
13 条回复
2019-06-24 09:02:30 +08:00
1
Alozxy
2019-06-22 15:18:03 +08:00 via Android
114dns 不支持 doh,换 cloudflare 地址
2
Alozxy
2019-06-22 15:31:39 +08:00 via Android
还有,853 是 dot 的端口,443 才是 doh 的
3
imswing
OP
2019-06-22 15:45:31 +08:00 via iPhone
@
Alozxy
那我上面 include 的 china list 里面用 114 可以吗?
4
Alozxy
2019-06-22 15:53:47 +08:00 via Android
@
imswing
不知道你文件内容,不过要分流的话直接用 dnsmasq 分流应该更好,脚本很成熟了
5
qcts33
2019-06-22 16:59:10 +08:00
unbound 支持 doh 了吗?我记得是只支持 dot 的,doh 似乎是还在弄
6
love4taylor
PRO
2019-06-22 17:47:37 +08:00
forward-ssl-upstream: yes 哪去了.... 以及 DoT 为啥和普通 DNS 混用...
7
love4taylor
PRO
2019-06-22 17:49:14 +08:00
1
具体写法参照
https://github.com/dns-sb/DoT/blob/master/example/unbound.conf
8
imswing
OP
2019-06-22 21:32:35 +08:00 via iPhone
@
Love4Taylor
谢谢,我是看着网上的配置,太老了。
9
zimonianhua
2019-06-23 00:44:28 +08:00 via Android
可以参考这个,
https://github.com/xyzmos/GeekDNS
10
love4taylor
PRO
2019-06-23 07:40:41 +08:00 via Android
@
zimonianhua
这种方案还是别了吧, 题主不向外提供服务, 要用 DoH 直接一个 https_dns_proxy 就行.
11
imswing
OP
2019-06-23 23:24:11 +08:00 via iPhone
@
Love4Taylor
```
server:
port: 5335
hide-version: yes
interface: 127.0.0.1
prefetch: yes
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
tls-upstream: yes
forward-zone:
name: "."
forward-tls-upstream: yes
forward-addr: 8.8.4.4@853
forward-addr: 1.0.0.1@853
```
这样改了还是不行
12
johnjiang8
2019-06-24 08:59:43 +08:00
interface:127.0.0.1@5335
interface:127.0.0.1@853
13
johnjiang85
2019-06-24 09:02:30 +08:00
@
johnjiang85
忽略
关于
帮助文档
自助推广系统
博客
API
FAQ
Solana
6061 人在线
最高记录 6679
Select Language
创意工作者们的社区
World is powered by solitude
VERSION: 3.9.8.5 25ms
UTC 02:19
PVG 10:19
LAX 19:19
JFK 22:19
Do have faith in what you're doing.
ubao
snddm
index
pchome
yahoo
rakuten
mypaper
meadowduck
bidyahoo
youbao
zxmzxm
asda
bnvcg
cvbfg
dfscv
mmhjk
xxddc
yybgb
zznbn
ccubao
uaitu
acv
GXCV
ET
GDG
YH
FG
BCVB
FJFH
CBRE
CBC
GDG
ET54
WRWR
RWER
WREW
WRWER
RWER
SDG
EW
SF
DSFSF
fbbs
ubao
fhd
dfg
ewr
dg
df
ewwr
ewwr
et
ruyut
utut
dfg
fgd
gdfgt
etg
dfgt
dfgd
ert4
gd
fgg
wr
235
wer3
we
vsdf
sdf
gdf
ert
xcv
sdf
rwer
hfd
dfg
cvb
rwf
afb
dfh
jgh
bmn
lgh
rty
gfds
cxv
xcv
xcs
vdas
fdf
fgd
cv
sdf
tert
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
sdf
shasha9178
shasha9178
shasha9178
shasha9178
shasha9178
liflif2
liflif2
liflif2
liflif2
liflif2
liblib3
liblib3
liblib3
liblib3
liblib3
zhazha444
zhazha444
zhazha444
zhazha444
zhazha444
dende5
dende
denden
denden2
denden21
fenfen9
fenf619
fen619
fenfe9
fe619
sdf
sdf
sdf
sdf
sdf
zhazh90
zhazh0
zhaa50
zha90
zh590
zho
zhoz
zhozh
zhozho
zhozho2
lislis
lls95
lili95
lils5
liss9
sdf0ty987
sdft876
sdft9876
sdf09876
sd0t9876
sdf0ty98
sdf0976
sdf0ty986
sdf0ty96
sdf0t76
sdf0876
df0ty98
sf0t876
sd0ty76
sdy76
sdf76
sdf0t76
sdf0ty9
sdf0ty98
sdf0ty987
sdf0ty98
sdf6676
sdf876
sd876
sd876
sdf6
sdf6
sdf9876
sdf0t
sdf06
sdf0ty9776
sdf0ty9776
sdf0ty76
sdf8876
sdf0t
sd6
sdf06
s688876
sd688
sdf86