ameshkov/legoagh

no IP address in cert, issues with DNS-over-TLS clients

shukryshuk opened this issue · 12 comments

IMG_20221103_121209

how to solve this ?? i need a guide

Don't worry, you can safely ignore this warning: AdguardTeam/AdGuardHome#4927 (comment)

Don't worry, you can safely ignore this warning: AdguardTeam/AdGuardHome#4927 (comment)

I cant connect the dns over tls using asus router.. but im able to connect with android phone.. I found out, if I disable access setting and remove all allowed clients, im able to connect the router using dns over tls, so i assuming, this warning is related to the problem here.. do you mind helping ??

Don't worry, you can safely ignore this warning: AdguardTeam/AdGuardHome#4927 (comment)

I cant connect the dns over tls using asus router.. but im able to connect with android phone.. I found out, if I disable access setting and remove all allowed clients, im able to connect the router using dns over tls, so i assuming, this warning is related to the problem here.. do you mind helping ??

this is why I assumed this is related
IMG_20221104_023058

because I need to fill in the ip address of the domain to connect to dns over tls

Nope, ASUS should work just okay.

You need to fill both the hostname and the IP address and make sure that your ASUS router trusts that certificate. As I recall it trusts let's encrypt certs just okay.

Nope, ASUS should work just okay.

You need to fill both the hostname and the IP address and make sure that your ASUS router trusts that certificate. As I recall it trusts let's encrypt certs just okay.

ya, its only possible to connect if i disabled allowed client in my adguard home server, and everyone can connect to my dns if I dont dissallow their ip or id. do you know why this behaviour happened ??

Well, check that you configured allowed clients properly then.

Enable verbose logging in AdGuard Home to see which clients are getting blocked and why

Well, check that you configured allowed clients properly then.

i configured it properly, i dont know why it wont connect. it seems asus router need to get dns from plain dns first and then it will use TLS after that.

if it uses plain dns first to connect to TLS, i need to allow my isp ip address in adguard home, but my isp dont give static ip, everytime i reboot the ip changed, so i dont know how to solve this. please help

Well, check that you configured allowed clients properly then.

i configured it properly, i dont know why it wont connect. it seems asus router need to get dns from plain dns first and then it will use TLS after that.

if it uses plain dns first to connect to TLS, i need to allow my isp ip address in adguard home, but my isp dont give static ip, everytime i reboot the ip changed, so i dont know how to solve this. please help

let me explain the situation,

yes i can connect through TLS after i changed the dns without rebooting the router, but after reboot, no internet because of the dns, so i need to changed the dns back to 1.1.1.1/one.one.one.one and redo the same process after reboot, in order to connect to my adguardhome dns.

Well, it sounds as if the problem is in the router configuration. Anything useful in the router logs?

Well, it sounds as if the problem is in the router configuration. Anything useful in the router logs?

it cant connect to ntp server because wan is down due to dns error, the router need to connect to ntp server first to establish connection to internet. i tried solution from asus support, but not working, the only way is to change to 1.1.1.1 first and change back to my adguard home dns after the ntp synced.

solved. after allow ALL ip from my isp in agh. thank you for your time