Hi,
I noticed something that prevents me from using DoH properly on a corporate network.
I have a router/firewall with two fiber Internet connections on it.
If I put my two Internet connections in load balancing mode, DoH to the forwarders doesn't work very well, because I understand that it opens an encrypted tunnel between Technitium and the resolver in order to go faster.
I have the same problem if I put one Internet connection active and the other on standby. If the main link goes down, DNS resolution in DoT makes errors.
Every time this happens, my various Technitium servers are lost and make errors continuously until I restart them so that they relaunch their connections via my other Internet link. Basically, my entire network goes down completely, and no DNS resolution works, even if the entries are cached.
To solve the problem, I know I can force my various Technitiums to go through a single fiber connection and manage that way, but this is not ideal for load balancing and maintaining activity.
The classic DNS mode on port 53 does not pose any particular problems since there is no control.
If you have any ideas for solving this problem technically, perhaps we need a way to declare our various public IP addresses in Technitium so that it can establish a connection at the DoH level when an internet connection is no longer working. (At least for active/passive connections; I have little hope for load balancing with DoH technology.)
Regards
Hi,
I noticed something that prevents me from using DoH properly on a corporate network.
I have a router/firewall with two fiber Internet connections on it.
If I put my two Internet connections in load balancing mode, DoH to the forwarders doesn't work very well, because I understand that it opens an encrypted tunnel between Technitium and the resolver in order to go faster.
I have the same problem if I put one Internet connection active and the other on standby. If the main link goes down, DNS resolution in DoT makes errors.
Every time this happens, my various Technitium servers are lost and make errors continuously until I restart them so that they relaunch their connections via my other Internet link. Basically, my entire network goes down completely, and no DNS resolution works, even if the entries are cached.
To solve the problem, I know I can force my various Technitiums to go through a single fiber connection and manage that way, but this is not ideal for load balancing and maintaining activity.
The classic DNS mode on port 53 does not pose any particular problems since there is no control.
If you have any ideas for solving this problem technically, perhaps we need a way to declare our various public IP addresses in Technitium so that it can establish a connection at the DoH level when an internet connection is no longer working. (At least for active/passive connections; I have little hope for load balancing with DoH technology.)
Regards