AdguardTeam / AdguardTeam/dnsproxy

DNS Proxy as DoH Server with NGINX

Offen
#188 13 Kommentare 0 Reaktionen 1 zugewiesene Person Beansprucht von @Chinaski1 Auf GitHub ansehen
Priority: P4
Vorherrschende Sprache
Go
Sterne
3.3k
Forks
343
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Hi,

I'm trying to configure a DNS Server using the dnsproxy as forwarder for the dns-queries. The configuration i have is the following:

Client : dnsproxy as a DoH client
Server : dnsproxy as a forwarder : the idea is that it takes the DNS query from the HTTP and then replies with the corresponding DNS response by using the desired upstream, for the certificates validation I use NGINX with let's encrypt certs.

I have the following configuration:

Client:
```
verbose: true
output: /home/ivan/client.txt
listen-addrs:
- 127.0.0.3
listen-ports:
- 53
tls-min-version: 1.3
upstream:
- "https://dohauth.iot-roam.net/dns-query"
bootstrap:
- '8.8.8.8:53'
cache-size: 64000
ratelimit: 0
ipv6-disabled: false
udp-buf-size: 0
max-go-routines: 0
version: false
```
Server:
```
---
bootstrap:
- "8.8.8.8:53"
listen-addrs:
- "127.0.0.1"
listen-ports:
- 53
- 8053
max-go-routines: 0
ratelimit: 0
udp-buf-size: 0
upstream:
- "8.8.8.8:53"
https-port:
- 443
verbose: true
output: "/home/ivan/server.txt"
```
Then, if I run tshark I can actually see the DNS query arriving:
```
Running as user "root" and group "root". This could be dangerous.
Capturing on 'Loopback: lo'
1 0.000000000 127.0.0.1 → 127.0.0.1 TCP 74 32902 → 8053 [SYN] Seq=0 Win=65495 Len=0 MSS=65495 SACK_PERM=1 TSval=1702772584 TSecr=0 WS=128
2 0.000015800 127.0.0.1 → 127.0.0.1 TCP 74 8053 → 32902 [SYN, ACK] Seq=0 Ack=1 Win=65483 Len=0 MSS=65495 SACK_PERM=1 TSval=1702772584 TSecr=1702772584 WS=128
3 0.000031916 127.0.0.1 → 127.0.0.1 TCP 66 32902 → 8053 [ACK] Seq=1 Ack=1 Win=65536 Len=0 TSval=1702772584 TSecr=1702772584
4 0.000443476 127.0.0.1 → 127.0.0.1 HTTP 387 GET /dns-query?dns=l0YBIAABAAAAAAABBmdvb2dsZQNjb20AAAEAAQAAKRAAAAAAAAAMAAoACFlUCwOWR0Cg HTTP/1.1
```
But there is no successful DNS resolution

I attached both, the server and client side traces

[client.txt](https://github.com/AdguardTeam/dnsproxy/files/7547762/client.txt)
[server.txt](https://github.com/AdguardTeam/dnsproxy/files/7547826/server.txt)

Maybe I'm misunderstanding something?
Thanks for your help !

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.