Dnscrypt-proxi
Содержание:
- GUIs for dnscrypt-proxy
- Description
- Instructions
- Simple DNSCrypt
- More info on DNSCrypt or SimpleDNSCrypt ?
- Introducing DNSCrypt
- При возникновении проблем
- При возникновении проблем
- Специальная сборка для архитектуры ar71xx от black-roland
- GUIs for dnscrypt-proxy
- О продукте
- Небезопасные DNS запросы
- Значение DNSCrypt или SimpleDNSCrypt?
- DNSCrypt review
- Настройка WireGuard на сервере
- Using DNSCrypt in combination with a DNS cache
- Using DNSCrypt in combination with a DNS cache
- Специальная сборка для архитектуры ar71xx от black-roland
- Installation
- Usage
- Extras
GUIs for dnscrypt-proxy
If you need a simple graphical user interface in order to start/stop
the proxy and change your DNS settings, check out the following
projects:
-
DNSCrypt OSX Client:
A tool to easily use DNSCrypt with OpenDNS, configure plugins and
define resolvers for specific domains. It has been implemented as a
collection of shell scripts with a user interface in Objective C. -
DNSCrypt WinClient:
Easily enable/disable DNSCrypt on multiple adapters. Supports
different ports and protocols, IPv6, parental controls and the proxy
can act as a gateway service. Windows only, written in .NET. -
DNSCrypt Win Client:
Official GUI for Windows, by OpenDNS. Also known as «OpenDNSCrypt».
Description
DNSCurve improves the confidentiality and integrity of DNS requests using
high-speed high-security elliptic-curve cryptography. Best of all,
DNSCurve has very low overhead and adds virtually no latency to
queries.
DNSCurve aims at securing the entire chain down to authoritative
servers. However, it only works with authoritative servers that explicitly
support the protocol. And unfortunately, DNSCurve hasn’t received much
adoption yet.
The DNSCrypt protocol is very similar to DNSCurve, but focuses on
securing communications between a client and its first-level resolver.
While not providing end-to-end security, it protects the local
network (which is often the weakest link in the chain) against
man-in-the-middle attacks. It also provides some confidentiality to
DNS queries.
The DNSCrypt daemon acts as a DNS proxy between a regular client, like
a DNS cache or an operating system stub resolver, and a DNSCrypt-aware
resolver, like OpenDNS.
Instructions
Install the packages and configure DNS encryption.
# Install packages
opkg update
opkg install dnsmasq dnscrypt-proxy
# Configure DNSCrypt provider
uci set dnscrypt-proxy.@dnscrypt-proxy.resolver="cisco"
uci set dnscrypt-proxy.@dnscrypt-proxy.address="127.0.0.1"
uci set dnscrypt-proxy.@dnscrypt-proxy.port="5253"
uci commit dnscrypt-proxy
etcinit.ddnscrypt-proxy restart
# Enable DNS encryption
uci -q delete dhcp.@dnsmasq.server
DNSCRYPT_ADDR="$(uci get dnscrypt-proxy.@dnscrypt-proxy.address)"
DNSCRYPT_PORT="$(uci get dnscrypt-proxy.@dnscrypt-proxy.port)"
DNSCRYPT_SERV="${DNSCRYPT_ADDR//[][]/}#${DNSCRYPT_PORT}"
uci add_list dhcp.@dnsmasq.server="${DNSCRYPT_SERV}"
# Enforce DNS encryption for LAN clients
uci set dhcp.@dnsmasq.noresolv="1"
uci commit dhcp
etcinit.ddnsmasq restart
LAN clients should use Dnsmasq as a primary resolver.
Dnsmasq forwards DNS queries to dnscrypt-proxy which encrypts DNS traffic.
Simple DNSCrypt
Simple DNSCrypt позволяет легко и просто изменить настройки сетевой карты так, чтобы все запросы шли к DNS серверам с поддержкой DNSSEC. Эта технология позволяет избежать подмены IP-адресов. Как бонус, будут использоваться только уважающие приватность серверы имён, т.е. не сохраняющие обращения пользователей.
Программа ставится просто. Главное правильно выбрать 32- или 64-битную версию, смотря какой разрядности у вас Windows. Разрядность можно посмотреть в Панели управления — Система (в Windows 10 — Параметры — Система — О программе).

x64 — 64-битная, x86 — 32-битная
После установки и запуска с ярлыка на Рабочем столе настройки менять не нужно. Просто нажмите кнопку «Применить».

Вы увидите, что переключатель пункта «Служба DNSCrypt» установится в зелёное положение «Вкл». Значит, в Windows запустилась новая служба, суть которой — выступать прокси-сервером всех DNS-запросов, перенаправляя их на безопасные сервера (их список есть на вкладке «Резольверы», там ничего трогать не надо).
После нужно лишь щёлкнуть мышью по всем сетевым картам, видимым в нижней части окна, чтобы на них появилась галочка справа вверху.

На этом всё! Защита запросов заработает сразу. Программа будет работать сама по себе.
Если вы продвинутый пользователь и хотите проверить, работает ли DNSCrypt на вашем компьютере, откройте свойства протокола TCP/IPv4 сетевого соединения. DNS-сервер должен быть локальный — 127.0.0.1.

Если при использовании сервера имён 127.0.0.1 сайты открываются — утилита dnscrypt-proxy работает, никто ваши запросы не пишет и провайдер запросы не отслеживает.
Удаляется программа, как и все остальные — через Панель управления.
More info on DNSCrypt or SimpleDNSCrypt ?
До! ) Любая информация о плюсах и минусах была бы вашим опытом? Похоже, SimpleDNSCrypt 0.4.2 активно обновляется, но DNSCrypt 0.0.6 показывает только несколько (косвенных) упоминаний. Что такое SimpleDNSCrypt? ….
Проблемы с SimpleDnsCrypt
Я спрашиваю, потому что хотя Primary Resolver поддерживает другие, используйте SimpleDnsCrypt?
Кажется, что тесты DNSSEC показывают, что они не работают. Кто-нибудь знает, что работает без (сложного) обходного пути?
Кто-нибудь получил его для поддержки:Вторичный преобразователь недоступен. Первичный резольвер с DNSSEC?
DNSCrypt
Также это полезно, если вы подключаетесь к определенной ссылкеНе пробовал, но первое, что приходит на мой пробный DNSCrypt? Кто-то, кто слушает наше соединение, может, например, определить, что мы подключаемся к прослушиванию вашего соединения. DNSCrypt — это небольшой шаг вперед. Как мы все знаем, DNS используется для извлечения
У кого-нибудь есть IP-адрес сервера, к которому мы подключаемся. Поэтому, когда дело доходит до защиты вашей конфиденциальности от кого-то еще, но все же немного скептически. ум заключается в том, что традиционный DNS можно рассматривать как проблему конфиденциальности. Мне любопытно узнать веб-сайт с использованием SSL, иначе остальная часть трафика не будет зашифрована.
некоторые сайты, даже если мы подключаемся с использованием SSL, потому что традиционный DNS не зашифрован.
OpenDNS DNSCrypt
OpenDNS DNSCrypt: Encrypt DNS Traffic, Secure Yourself From Eavesdropping, Man-in-the-middle Attacks
Простой DnsCrypt
Поэтому я решил взглянуть на шифрование моих DNS-соединений, учитывая Кто-нибудь использует такую программу раньше? Нажмите, чтобы развернуть … Я считаю это здорово, но моего опыта с ним не было. Я думаю, что @Umbra все еще использует приложение.
Тем не менее, разрешение DNS, как правило, остается в силе. Я пробовал, что я не хочу использовать VPN, и я наткнулся на Simple DnsCrypt. Я нашел его простым в использовании и настройке один раз. Я не уверен, что это закончится через несколько минут.
cmd .. проблема с путём к DNSCrypt
Goto Explorer перейдите в каталог файла. »), где необходимо). Не забывайте (есть ли проблемы, которые вы используете?
Выберите файл и убедитесь, что его панель маршрута. Какая команда Run … В любом случае, адрес (путь).
с дорожкой? Нажмите, чтобы развернуть … Введите команду, а затем вставьте (щелкните правой кнопкой мыши) скопированный путь к файлу, указанный в строке пути проводника. Откройте путь администратора. (Убедитесь, что синтаксис верен — например, щелкните правой кнопкой мыши копию командной строки.
Простой Dnscrypt не работает после обновления Творца
Все больше работает.
Я обычно использую SDcrypt для решения? заранее спасибо
Гаго
SDcrypt не сразу после установки обновления Creator.
Он просто отлично работает раньше, но обходит заблокированный сайт и даже игру.
Introducing DNSCrypt
Background: The need for a better DNS security
That said, the class of problems that the Kaminsky Vulnerability related to were a result of some of the underlying foundations of the DNS protocol that are inherently weak — particularly in the “last mile.” The “last mile”
is the portion of your Internet connection between your computer and your ISP. DNSCrypt is our way of securing the “last mile” of DNS traffic and resolving (no pun intended) an entire class of serious security concerns with the DNS protocol.
As the world’s Internet connectivity becomes increasingly mobile and more and more people are connecting to several different WiFi networks in a single day, the need for a solution is mounting.
There have been numerous examples of tampering, or man-in-the-middle attacks, and snooping of DNS traffic at the last mile and it represents a serious security risk that we’ve always wanted to fix. Today we can.
Why DNSCrypt is so significant
In the same way the SSL turns HTTP web traffic into HTTPS encrypted Web traffic, DNSCrypt turns regular DNS traffic into encrypted DNS traffic that is secure from eavesdropping and man-in-the-middle attacks. It doesn’t require any changes to domain
names or how they work, it simply provides a method for securely encrypting communication between our customers and our DNS servers in our data centers. We know that claims alone don’t work in the security world, however, so we’ve opened
up the source to our DNSCrypt code base and it’s available on GitHub.
DNSCrypt has the potential to be the most impactful advancement in Internet security since SSL, significantly improving every single Internet user’s online security and privacy.
Frequently Asked Questions (FAQ):
1. In plain English, what is DNSCrypt?
DNSCrypt is a piece of lightweight software that everyone should use to boost online privacy and security. It works by encrypting all DNS traffic between the user and OpenDNS, preventing any spying, spoofing or man-in-the-middle attacks.
2. How can I use DNSCrypt today?
We’ve opened up the source to our DNSCrypt code base and it’s available on GitHub. The graphical interfaces are no longer in development; however, the open source community is still providing unofficial updates
to the technical preview.
Tips: If you have a firewall or other middleware mangling your packets, you should try enabling DNSCrypt with TCP over port 443. This will make most firewalls think it’s HTTPS traffic and leave it alone.
If you prefer reliability over security, enable fallback to insecure DNS. If you can’t reach us, we’ll try using your DHCP-assigned or previously configured DNS servers. This is a security risk though.
3. What about DNSSEC? Does this eliminate the need for DNSCrypt?
No. DNSCrypt and DNSSEC are complementary. DNSSEC does a number of things. First, it provides authentication. (Is the DNS record I’m getting a response for coming from the owner of the domain name I’m asking about or has it been tampered
with?) Second, DNSSEC provides a chain of trust to help establish confidence that the answers you’re getting are verifiable. But unfortunately, DNSSEC doesn’t actually provide encryption for DNS records, even those signed by DNSSEC. Even
if everyone in the world used DNSSEC, the need to encrypt all DNS traffic would not go away. Moreover, DNSSEC today represents a near-zero percentage of overall domain names and an increasingly smaller percentage of DNS records each day as the Internet
grows.
That said, DNSSEC and DNSCrypt can work perfectly together. They aren’t conflicting in any way. Think of DNSCrypt as a wrapper around all DNS traffic and DNSSEC as a way of signing and providing validation for a subset of those records. There
are benefits to DNSSEC that DNSCrypt isn’t trying to address. In fact, we hope DNSSEC adoption grows so that people can have more confidence in the entire DNS infrastructure, not just the link between our customers and OpenDNS.
4. Is this using SSL? What’s the crypto and what’s the design?
При возникновении проблем
Проверяем используемый DNS-сервер
- посмотреть IP-адрес используемого в настоящий момент сервера можно на сайтах DNS leak test или DNS randomness test. Здесь можно проверить какому сервису принадлежит IP-адрес (IP-адрес следует вводить в поле search).
- DNSSEC resolver test покажет поддерживает ли DNS-сервер проверку DNSSEC-подписей.
- если вы можете зайти на DNSCrypt.bit, то DNS-сервер поддерживает доменные имена Namecoin.
Проверяем, отправляются ли DNS-запросы через »dnscrypt-proxy»
Выполняем на маршрутизаторе:
pkill -STOP dnscrypt-proxy
После этого DNS-запросы должны перестать работать.
Возвращаем службу в рабочее состояние:
pkill -CONT dnscrypt-proxy
Проверяем корректно ли работает »dnscrypt-proxy»
Простейший способ — посмотреть системный журнал:
-
проверяем, что использует только dnscrypt-proxy. Нас интересует только последний блок DNS-серверов:
-
logread | grep -n "using nameserver"
-
132:Jan 1 01:01:00 openwrt daemon.info dnsmasq: using nameserver 208.67.222.222#53 for domain pool.ntp.org 133:Jan 1 01:01:00 openwrt daemon.info dnsmasq: using nameserver 127.0.0.1#5353
-
-
проверяем, что работает:
-
logread | grep "Proxying from"
-
Jul 1 12:00:00 openwrt daemon.info dnscrypt-proxy: Proxying from 127.0.0.1:5353 to 208.67.220.220:443
-
При возникновении проблем убедитесь, что порт, используемый , не занят другим процессом (например mDNS ZeroConf Daemon (avahi)).
Получен подозрительный сертификат
При наличии сообщений о “подозрительном” сертификате
проверяем точность даты и времени, установленных на маршрутизаторе.
При возникновении проблем
Проверяем используемый DNS-сервер
- посмотреть IP-адрес используемого в настоящий момент сервера можно на сайтах DNS leak test или DNS randomness test. Здесь можно проверить какому сервису принадлежит IP-адрес (IP-адрес следует вводить в поле search).
- DNSSEC resolver test покажет поддерживает ли DNS-сервер проверку DNSSEC-подписей.
- если вы можете зайти на DNSCrypt.bit, то DNS-сервер поддерживает доменные имена Namecoin.
Проверяем, отправляются ли DNS-запросы через »dnscrypt-proxy»
Выполняем на маршрутизаторе:
pkill -STOP dnscrypt-proxy
После этого DNS-запросы должны перестать работать.
Возвращаем службу в рабочее состояние:
pkill -CONT dnscrypt-proxy
Проверяем корректно ли работает »dnscrypt-proxy»
Простейший способ — посмотреть системный журнал:
-
проверяем, что использует только dnscrypt-proxy. Нас интересует только последний блок DNS-серверов:
-
logread | grep -n "using nameserver"
-
132:Jan 1 01:01:00 openwrt daemon.info dnsmasq: using nameserver 208.67.222.222#53 for domain pool.ntp.org 133:Jan 1 01:01:00 openwrt daemon.info dnsmasq: using nameserver 127.0.0.1#5353
-
-
проверяем, что работает:
-
logread | grep "Proxying from"
-
Jul 1 12:00:00 openwrt daemon.info dnscrypt-proxy: Proxying from 127.0.0.1:5353 to 208.67.220.220:443
-
При возникновении проблем убедитесь, что порт, используемый , не занят другим процессом (например mDNS ZeroConf Daemon (avahi)).
Получен подозрительный сертификат
При наличии сообщений о “подозрительном” сертификате
проверяем точность даты и времени, установленных на маршрутизаторе.
Специальная сборка для архитектуры ar71xx от black-roland
Сборка от black-roland имеет ряд преимуществ перед официальным репозиторием Chaos Calmer: пакеты dnscrypt-proxy и libsodium более свежие (и поддерживают Barrier Breaker), dnscrypt-proxy поддерживает использование эфемерных ключей, procd и позволяет одновременно запускать несколько копий себя (если первый DNS-сервер по каким-либо причинам будет недоступен, система использует второй).
Добавляем в файл источник в зависимости от используемой версии OpenWrt. Для этого выполняем в консоли следующие команды:
Trunk:
Уже содержит актуальную версию dnscrypt-proxy с поддержкой запуска нескольких копий. Ничего добавлять не требуется.
opkg update opkg install dnscrypt-proxy
Chaos Calmer:
cd /tmp wget 'http://exopenwrt.roland.black/exopenwrt.pub' opkg-key add exopenwrt.pub echo '/etc/opkg/keys/1a929a1dd62138c1' >> /etc/sysupgrade.conf echo 'src/gz exopenwrt http://exopenwrt.roland.black/chaos_calmer/15.05.1/ar71xx/packages/exopenwrt' >> /etc/opkg.conf
Barrier Breaker:
echo 'src/gz exopenwrt http://exopenwrt.roland.black/barrier_breaker/14.07/ar71xx/packages/exopenwrt' >> /etc/opkg.conf
Обновляем список пакетов и устанавливаем и . Примечание: без обновленной библиотеки служба не запустится (по крайней мере в мультисерверном варианте), при недостатке места библиотеку следует удалить принудительно.
opkg update opkg remove libsodium --force-depends opkg install dnscrypt-proxy libsodium
GUIs for dnscrypt-proxy
If you need a simple graphical user interface in order to start/stop
the proxy and change your DNS settings, check out the following
projects:
-
DNSCrypt OSX Client:
a preferences pane, a menu bar indicator and a service to change the
DNS settings. OSX only, written in Objective C. Experimental. -
DNSCrypt WinClient:
Easily enable/disable DNSCrypt on multiple adapters. Supports
different ports and protocols, IPv6, parental controls and the proxy
can act as a gateway service. Windows only, written in .NET. -
DNSCrypt Win Client:
Official GUI for Windows, by OpenDNS. Also known as «OpenDNSCrypt».
О продукте
Программа создана немецким разработчиком Кристианом Херманном и распространяется на условиях бесплатной лицензии. Он работает только под Windows, есть модификации для 32 и 64- битных версий ОС. Программу не стоит устанавливать тем пользователям, которые применяют Яндекс-браузер, у него DNScrypt уже встроен и работает, шифруя данные, автоматически. Если на компьютере не установлена какая-либо программа, содержащая DNScrypt, а пользователь регулярно пользуется общественными и незащищенными Wi-Fi сетями, использование Simple DNSCrypt становится объективной необходимостью, упоминают о случаях, когда вместо популярного сайта пользователь входил на подменный домен, задачей которого становится сбор паролей. Управляя трафиком, программа решает задачу, чтобы запросы шли только к DNS серверам с поддержкой DNSSEC, в этом случае доменные имена становятся недоступными.
Преимущества и недостатки
При изучении отзывов пользователей становятся очевидными достоинства и минусы программы.
| Преимущества |
|
| Недостатки |
|
Установка и настройка
Продукт достаточно легко устанавливается, а вот настройка Simple DNSCrypt потребует некоторых профессиональных знаний. Необходимо ориентировать в резольверах – DNS-серверах, к которым будет происходить обращение программы. Если своих предпочтений нет, программа по умолчанию установит свой вариант. Минусом автоматического выбора становится невозможность контролировать скорость работы, программа может использовать сервера, находящиеся в географическом удалении, например, в Новой Зеландии, а это существенно замедляет скорость подключения. Желательно выбирать европейские серверы, которые есть в выпадающем списке, вводить адреса не надо, достаточно поставить галочку напротив выбранного.

Небезопасные DNS запросы
Для общения устройств используется способ передачи данных TCP/IP. Это не протокол или набор программ, а концепция (модель) того, как это общение должно происходить.
У TCP/IP много недостатков, но, так как модель «пластичная», её латают и дорабатывают на протяжении более 40 лет своего существования. Например, чтобы никто не видел, что вы вводите на сайтах и получаете в ответ, многие сайты массово перешли на шифрованный протокол HTTPS.
К сожалению, уязвимостей в TCP/IP пока предостаточно. Одно из больных мест — система доменных имён (Domain Name System, DNS).
Когда вы открываете в адресной строке сайт, компьютеру нужно узнать, на какой сервер послать запрос. Для этого он обращается к серверам DNS, хранящих записи о том, на какой цифровой IP-адрес сервера обратиться, чтобы получить нужную страничку.
Проблема в том, что компьютеры безоговорочно доверяют серверам DNS. Если вы подключитесь к публичной Wi-Fi сети в кафе, владелец которой поднял собственный сервер с ложными адресами, есть шанс, что вместо Вконтакте вы откроете обманку, собирающую пароли.
Способов защитить запросы к серверам имён несколько, но операционные системы их не используют. Нужно дорабатывать ОС самостоятельно с помощью отдельных программ.
Значение DNSCrypt или SimpleDNSCrypt?
DNSCrypt или SimpleDNSCrypt? это имя ошибки, содержащее сведения об ошибке, в том числе о том, почему это произошло, какой системный компонент или приложение вышло из строя, чтобы вызвать эту ошибку вместе с некоторой другой информацией. Численный код в имени ошибки содержит данные, которые могут быть расшифрованы производителем неисправного компонента или приложения. Ошибка, использующая этот код, может возникать во многих разных местах внутри системы, поэтому, несмотря на то, что она содержит некоторые данные в ее имени, пользователю все же сложно определить и исправить причину ошибки без особых технических знаний или соответствующего программного обеспечения.
DNSCrypt review
What is DNSCrypt – Why Do I Need It
You know about the VPNs that encrypt your data and exchanges it in a secure tunnel created between your computer and the host. Though VPNs provide better security and privacy of DNSCrypt, they often slow down your browsing. Proxies are for accessing sites (by changing your IP address). They don’t provide encryption in most cases. We also discussed certain DNS (example OpenDNS) that provide content filtering in addition to a secure (anti-malware) connections. You know that not all websites are not safe. Comodo and OpenDNS perform a check when you request a website connection and will inform you if the website is dangerous. OpenDNS also offers content filtering that can be called Parental Controls over the network. You do not need to configure it on all computers.
NOTE: In some cases where you select your DNS other than the ones listed in DNSCrypt, it creates problems connecting to the Internet. I would recommend using popular DNS servers, as they pose fewer problems. If you select the ones listed in the DNSCrypt, you might not face any problem at all.
DNSCrypt will encrypt and protect data

Where to download DNSCrypt
There are many sites offering DNScrypt download. The main source is at GITHUB that also contains the code of the program so that you can check whether it is programmed to encrypt the data or not.
But downloading from GITHUB gives you a confusing version of DNSCrypt. The link to download is towards the bottom right corner of the screen – marked as “Download ZIP”. This ZIP file contains many folders that need to be extracted to some safe place so that your copy of DNSCrypt keeps working. See the image above for an idea of how extracted files look.
There is another site from where you can download DNSCrypt so that you can install it as a Windows Service. This is also a DNSCrypt ZIP file containing only four files. The link to download DNSCrypt Windows Service leads you to a website of a programmer named Simon Clausen – simonclausen.dk. The page also tells you about the benefits of the program. I prefer downloading it from Simon Clausen’s website rather than GITHUB. The latter is a bit complicated as it has too many files and you may not know which one to run first.
Read: What is DNSCrypt Protocol.
How To Install DNSCrypt
If you downloaded the ZIP file from GITHUB and extracted the contents, get the following folders. They look confusing, but you open the DNSCrypt folder and the run the only executable there. There is an upgrade folder when you extract it, but I was not able to understand what it meant. Maybe it was patched or maybe upgrades with new features. There are some six upgrade files. I could not find details about this.
If you downloaded the ZIP file from Simon Clausen’s website, all you need to do is to extract the files and run dnscrypt-winservicemgr.exe. You will get a graphical Interface as shown in the image below. You can choose your adaptor, type of communication (UDP or TCP) and also service providers (such as OpenDNS, etc.) before clicking Enable. After you click Enable, simply close the window. The process runs in the background, and you can view it in Windows Task Manager -> Process Tab.

How to remove DNSCrypt Windows Service
Always create a restore point before installing such software because if anything goes wrong (such as incorrect configuration), you can restore your computer back to before the program was installed. In the case of DNSCrypt, you will not find any entry in Programs and Features.
System Restore is the only way to remove it. Alternatively, you can go to Services from Control Panel -> Administrative Tools and disable the dnscrypt service. Right-click on the service listed as dnscrypt-proxy and click on Disable or Manual Start.
Conclusion
Similar tool: Simple DNS Crypt.

Tags: DNS, Encrypt, Freeware
Настройка WireGuard на сервере
Я проделываю всё на Ubuntu 18.04, но в официальной документации есть инструкции по установке для всех известных и не очень ОС.
Установка
Генерируем ключи для сервера. Ключи сохраним в директории WireGuard для удобства
Соответственно в файле privatekey-server будет приватный ключ, а в publickey-server — публичный.
Так же сгенерируем сразу ключ для клиента:
Конфигурация
Конфиг хранится в /etc/wireguard/wg0.conf. Серверная часть выглядит так:
Address — адрес для интерфейса wg (адрес внутри туннеля)PrivateKey — Приватный ключ (privatekey-server)ListenPort — Порт на котором служба ожидает подключения
Ну и делаем маскарадинг, потому что мы будем использовать этот сервер для выхода в интернет
Обратите внимание, что имя интерфейса в вашем случае может отличаться:
Клиентская часть
PublicKey — публичный ключ нашего роутера (publickey-client)AllowedIPs — подсети, которые будут доступны через этот туннель. Серверу требуется доступ только до адреса клиента.
Обе части хранятся в одном конфиге.
Включаем автозапуск при перезагрузке:
Делаем сервер маршрутизатором:
Настроим фаервол. Предположим, что у нас на сервере только WireGuard и ssh:
Сохраним конфигурацию iptables:
Поднимаем wg интерфейс первый раз вручную:
WireGuard сервер готов.
UPD 27.06.19 Если ваш провайдер до сих пор использует PPoE, то нужно добавить правило. Спасибо denix123
Using DNSCrypt in combination with a DNS cache
The DNSCrypt proxy is not a DNS cache. This means that incoming
queries will not be cached and every single query will require a
round-trip to the upstream resolver.
For optimal performance, the recommended way of running DNSCrypt is to
run it as a forwarder for a local DNS cache, like or
.
Both can safely run on the same machine as long as they are listening
to different IP addresses (preferred) or different ports.
If your DNS cache is , all you need is to edit the
file and add the following lines at the end of the
section:
The first line is not required if you are using different IP addresses
instead of different ports.
Then start , telling it to use a specific port (, in
this example):
Using DNSCrypt in combination with a DNS cache
The DNSCrypt proxy is not a DNS cache. This means that incoming
queries will not be cached and every single query will require a
round-trip to the upstream resolver.
For optimal performance, the recommended way of running DNSCrypt is to
run it as a forwarder for a local DNS cache, like or
.
Both can safely run on the same machine as long as they are listening
to different IP addresses (preferred) or different ports.
If your DNS cache is , all you need is to edit the
file and add the following lines at the end of the
section:
The first line is not required if you are using different IP addresses
instead of different ports.
Then start , telling it to use a specific port (, in
this example):
Специальная сборка для архитектуры ar71xx от black-roland
Сборка от black-roland имеет ряд преимуществ перед официальным репозиторием Chaos Calmer: пакеты dnscrypt-proxy и libsodium более свежие (и поддерживают Barrier Breaker), dnscrypt-proxy поддерживает использование эфемерных ключей, procd и позволяет одновременно запускать несколько копий себя (если первый DNS-сервер по каким-либо причинам будет недоступен, система использует второй).
Добавляем в файл источник в зависимости от используемой версии OpenWrt. Для этого выполняем в консоли следующие команды:
Trunk:
Уже содержит актуальную версию dnscrypt-proxy с поддержкой запуска нескольких копий. Ничего добавлять не требуется.
opkg update opkg install dnscrypt-proxy
Chaos Calmer:
cd /tmp wget 'http://exopenwrt.roland.black/exopenwrt.pub' opkg-key add exopenwrt.pub echo '/etc/opkg/keys/1a929a1dd62138c1' >> /etc/sysupgrade.conf echo 'src/gz exopenwrt http://exopenwrt.roland.black/chaos_calmer/15.05.1/ar71xx/packages/exopenwrt' >> /etc/opkg.conf
Barrier Breaker:
echo 'src/gz exopenwrt http://exopenwrt.roland.black/barrier_breaker/14.07/ar71xx/packages/exopenwrt' >> /etc/opkg.conf
Обновляем список пакетов и устанавливаем и . Примечание: без обновленной библиотеки служба не запустится (по крайней мере в мультисерверном варианте), при недостатке места библиотеку следует удалить принудительно.
opkg update opkg remove libsodium --force-depends opkg install dnscrypt-proxy libsodium
Installation
The daemon is known to work on recent versions of OSX, OpenBSD,
Bitrig, NetBSD, Dragonfly BSD, FreeBSD, Linux, iOS (requires a
jailbroken device), Android (requires a rooted device), Solaris
(SmartOS) and Windows (requires MingW).
Compile and install it using the standard procedure:
Replace with whatever number of CPU cores you want to use for the
compilation process.
Running in the directory is also highly
recommended.
The proxy will be installed as by default.
Command-line switches are documented in the man page.
Note: gcc 3.4.6 (and probably other similar versions) is known to
produce broken code on Mips targets with the -Os optimization level.
Use a different level (-O and -O2 are fine) or upgrade the compiler.
Thanks to Adrian Kotelba for reporting this.
Usage
Having a dedicated system user, with no privileges and with an empty
home directory, is highly recommended. For extra security, DNSCrypt
will chroot() to this user’s home directory and drop root privileges
for this user’s uid as soon as possible.
The easiest way to start the daemon is:
The proxy will accept incoming requests on 127.0.0.1, tag them with an
authentication code, forward them to OpenDNS resolvers, and validate
each answer before passing it to the client.
Given such a setup, in order to actually start using DNSCrypt, you
need to update your file and replace your current
set of resolvers with:
Other common command-line switches include:
- in order to run the server as a background process.
-
in order to locally bind a different IP
address than 127.0.0.1 -
in order to write log data to a dedicated file. By
default, logs are sent to stdout if the server is running in foreground,
and to syslog if it is running in background. -
to set the maximum number of active
requests. The default value is 250. - in order to store the PID number to a file.
- in order to chroot()/drop privileges.
DNSCrypt comes pre-configured for OpenDNS, although the
,
and can be specified in
order to change the default settings.
Extras
Web interface
Install the necessary packages if you want to manage the settings via web interface.
# Install packages opkg update opkg install luci-app-dnscrypt-proxy
- Navigate to LuCI → Network → DHCP and DNS to configure Dnsmasq.
- Navigate to LuCI → Services → DNSCrypt-Proxy to configure dnscrypt-proxy.
DNSCrypt provider
dnscrypt-proxy is configured with Cisco DNS.
You can change it to DNSCrypt.eu or any other DNSCrypt provider.
Make sure the provider supports DNSSEC validation if required.
Specify several servers to improve fault tolerance.
# Update DNSCrypt provider database
sed -i -e "/^dnscrypt\.eu-nl,/a $(sed -n -e "
^dnscrypt\.eu-nl,{
sdnscrypt\.eu-nl\-ipv6
sDNSCrypt\.eu Holland\ over IPv6
s176\.56\.237\.1712a00:d880:3:1::a6c1:2e89:443p}
" /usr/share/dnscrypt-proxy/dnscrypt-resolvers.csv)" \
usrsharednscrypt-proxydnscrypt-resolvers.csv
# Configure DNSCrypt provider
while uci -q delete dnscrypt-proxy.@dnscrypt-proxy; do :; done
uci set dnscrypt-proxy.dns6a="dnscrypt-proxy"
uci set dnscrypt-proxy.dns6a.resolver="dnscrypt.eu-dk-ipv6"
uci set dnscrypt-proxy.dns6a.address=""
uci set dnscrypt-proxy.dns6a.port="5253"
uci set dnscrypt-proxy.dns6b="dnscrypt-proxy"
uci set dnscrypt-proxy.dns6b.resolver="dnscrypt.eu-nl-ipv6"
uci set dnscrypt-proxy.dns6b.address=""
uci set dnscrypt-proxy.dns6b.port="5254"
uci set dnscrypt-proxy.dnsa="dnscrypt-proxy"
uci set dnscrypt-proxy.dnsa.resolver="dnscrypt.eu-dk"
uci set dnscrypt-proxy.dnsa.address="127.0.0.1"
uci set dnscrypt-proxy.dnsa.port="5255"
uci set dnscrypt-proxy.dnsb="dnscrypt-proxy"
uci set dnscrypt-proxy.dnsb.resolver="dnscrypt.eu-nl"
uci set dnscrypt-proxy.dnsb.address="127.0.0.1"
uci set dnscrypt-proxy.dnsb.port="5256"
uci commit dnscrypt-proxy
etcinit.ddnscrypt-proxy restart
uci -q delete dhcp.@dnsmasq.server
while
DNSCRYPT_ADDR="$(uci -q get dnscrypt-proxy.@dnscrypt-proxy.address)"
DNSCRYPT_PORT="$(uci -q get dnscrypt-proxy.@dnscrypt-proxy.port)"
DNSCRYPT_SERV="${DNSCRYPT_ADDR//[][]/}#${DNSCRYPT_PORT}"
uci -q delete dnscrypt-proxy.@dnscrypt-proxy
do uci add_list dhcp.@dnsmasq.server="${DNSCRYPT_SERV}"
done
uci revert dnscrypt-proxy
uci commit dhcp
etcinit.ddnsmasq restart





