https://bendews.com/posts/implement-dns-over-https/, from the comment from apnar
putty dans /mnt/cache/cache_only/work/cloudflaredX
docker run --rm -v "$PWD":/usr/src/myapp -w /usr/src/myapp -e GOOS=linux -e GOARCH=mips golang bash -c "go get -v github.com/cloudflare/cloudflared/cmd/cloudflared; GOOS=linux GOARCH=mips go build -v -x github.com/cloudflare/cloudflared/cmd/cloudflared"
copier le binaire sur le USG
scp cloudflared brutus@192.168.1.1:~
- copy the MIPS cloudflared into /config/scripts/ on USG
cp /home/brutus/cloudflared /config/scripts/
- make sure it's executable:
chmod +x /config/scripts/cloudflared
/config/scripts/post-config.d
#!/bin/bash # start DNS proxy to Cloud Flare /usr/bin/pkill cloudflared nohup /config/scripts/cloudflared --no-autoupdate --proxy-dns --proxy-dns-port 5053 &>/var/log/cloudflared.log &
- make sure startup script is executable:
chmod +x /config/scripts/post-config.d/cloudflare-dns.sh
- add a custom config.gateway.json file on your controller so DNS config carries over on provisioning, here is what the relevant section of mine is:
/mnt/cache/cache_only/appdata/unifi-controller/config
{
"service":{
"dns":{
"forwarding": {
"options": [
"no-resolv",
"strict-order",
"server=127.0.0.1#5053",
"server=1.1.1.1",
"server=1.0.0.1",
"domain=patatemagique.biz,192.168.1.1/24,local"
]
}
},
"nat":{
"rule":{
"11":{
"description":"Force Redirect to PiHole",
"destination":{
"port":"53"
},
"inbound-interface":"eth1",
"inside-address":{
"address":"192.168.1.253"
},
"source":{
"address":"!192.168.1.253"
},
"log":"disable",
"protocol":"tcp_udp",
"type":"destination"
},
"6000":{
"description":"Translate DNS to Internal",
"destination":{
"address":"192.168.1.253",
"port":"53"
},
"log":"disable",
"outbound-interface":"eth1",
"protocol":"tcp_udp",
"type":"masquerade"
}
}
}
}
}
- make sure the domain name in the file is the same as the one in Settings → Network → edit → Domain Name, and the IP range matches as well.
- force a reprovision of your USG and reboot it to make sure everything starts up correctly
- supposedly everything in /config/scripts survives a firmware upgrade so that's why I picked that location
- scripts in /config/scripts/post-config.d seem to run on boot
- since you're using no-resolv, resolv.conf won't be read at all, so you need to manually set domain name for short names to work
- I added direct connections to cloudflare's DNS servers as 2nd and 3rd, but use strict-order so they will only be used if there is a problem with the DoH proxy
- the log file flag to cloudflared doesn't seem to work when using it for dns-proxy so need to use redirect to capture log info
- haven't done anything about log rotation yet, but cloudflared doesn't seem to chatty