Page 1 of 1

DoH configured but apparently not working

Posted: Mon Aug 05, 2024 1:29 pm
by wedwo1
I'm on RouterOS 7.8 on a Mikrotik I configured DoH on my Routerboard as per the instructions here which seem logical:
https://www.medo64.com/2021/08/dns-over ... -mikrotik/

The process seems to go fine, but for some reason when I visit https://one.one.one.one/help/ it reports DNS over HTTPS is not being used.
On my workstation (Windows 11), an ipconfig /all reveals my DNS servers to be 1.1.1.3 and 1.0.0.3
I've checked in every place I can think of in Windows and DNS is all set to automatic. ipconfig reports my DHCP server to be the routerboard device so I'm baffled as to where windows is getting these DNS servers from. Right now I have no IPv4 DNS servers setup in the mikrotik box.


https://one.one.one.one/help/#eyJpc0NmI ... MzMzUifQ==

Image

Any assistance is appreciated!

Re: DoH configured but apparently not working

Posted: Mon Aug 05, 2024 1:38 pm
by erlinden
Did you succesfully import the certificate that is used? Anything in the log that might give an indication? Does it work if you (temporarily) disable certificate check?
Can you also check if https://1.1.1.1/dns-query does work?

Re: DoH configured but apparently not working

Posted: Tue Aug 06, 2024 4:21 pm
by wedwo1
Did you succesfully import the certificate that is used? Anything in the log that might give an indication? Does it work if you (temporarily) disable certificate check?
Can you also check if https://1.1.1.1/dns-query does work?
Yes, the certificate imported fine. https://1.1.1.1/dns-query returns a 400 error. Strangely my iPhone reports all is fine, so I assume this is related to Windows, though I can't for the life of me find where it's getting the DNS servers 1.1.1.3 and 1.0.0.3 that it's assigning my PC. Disabling certificate verification seems to have no effect.

*EDIT* OK, I found it - I didn't check the bridge I created - the DNS servers were set up there. I removed those and now DoH is working!
Thanks!

Image

Re: DoH configured but apparently not working

Posted: Tue Aug 06, 2024 4:38 pm
by ToTheFull
lol, just about to post what do you have here...
ip/dhcp-server/network/print