Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] The ability to set forward-tls-upstream for some forward addresses in the same forward zone #1097

Open
AppleSheeple opened this issue Jun 29, 2024 · 0 comments

Comments

@AppleSheeple
Copy link

Current behavior

In a forward zone, the option forward-tls-upstream affects all forward-addrs. This is quite limiting, especially for the . zone.

Describe the desired feature

The ability to use DoT for some but not all forward addresses in the same forward zone.

One possible solution is to support an auto value for forward-tls-upstream, and infer whether to enable DoT based on each forward address. Addresses with @853 and/or #<dom> parts will use DoT, and others won't.

Potential use-case

Some secure/encrypted networks (e.g. using WireGuard) may provide an internal DNS address with fast query times. TLS is not enabled in this case since its not needed from a security PoV, and to avoid any performance overhead. But users may still want to use DoT for fallback addresses.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant