On 01/12/2019 05.31, Bernd Wechner wrote:
I wonder if this is possible. The Knot Resolver
certainly looks
powerful, and I use it on my Omnia Router of course. But the
documentation
<https://knot-resolver.readthedocs.io/en/stable/index.html>which I have
perused and read quickly, hasn't helped me understand this alas.
It leaves me with a couple of interesting questions:
1. How are nameservers configured? Interestingly my running instance of
kresd is on the Omnia and it receives nameservers via a dhcp request
on my ISP I imagine, though I don't see them in /etc/resolv.conf
Hi.
Knot Resolver itself doesn't configure forwarding or any resolvers to
forward to. If you want to configure forwarding, you have to provide
Knot Resolver with IP address for the policy.FORWARD() or
policy.TLS_FORWARD() function in kresd.conf. See policy module
documentation for details [1].
Are you asking how does Turris configure Knot Resolver with the ISP's
DNS resolver as a forwarder? That, I don't know, but a proper place to
ask would probably be the Turris forum [2] or support.
2. Is it possible configure a number of nameservers on
a the basis of
query them all (akin to dnsmasq's --all-servers) and return the
first affirmative response?
No.
My interest is acutely related to:
https://superuser.com/questions/1505755/can-one-configure-name-resolution-t…
And I'd happily use kresd on my local machine(s) as well as on my LAN
DNS (The Omnia) to help resolve names on my .lan while on a VPN!
Do you need to use the VPN's DNS resolvers? If so, why? Are there some
zones that can be resolved only on their DNS resolver? Are you concerned
about "DNS leak" when using VPN?
If you don't actually need to use the VPN's DNS resolvers, your problems
could be solved by configuring your VPN software not to change your
default local resolver (in /etc/resolv.conf). In that case, you'll use
the Turris Omnia's resolver (configured by DHCP) which is able to
resolve you local .lan addresses.
[1] -
https://knot-resolver.readthedocs.io/en/stable/modules.html#query-policies
[2] -
https://forum.turris.cz/
--
Tomas Krizek
PGP: 4A8B A48C 2AED 933B D495 C509 A1FB A5F7 EF8C 4869