I finally figured out how to virtualize my OPNsense firewall. Suck it, Roku.

AdventuringAardvark@lemmy.one to Selfhosted@lemmy.world – 225 points –

Blocked that hard-coded google dns garbage.

39

You are viewing a single comment

I do a DNS redirect on my Mikrotik router.

It's going to suck when DoH and DoT becomes more prevalent.

I think the solution is to avoid tech that you don't control. Its a hard pill to swallow for some but at the end of the day there are tons of ways a device could bypass networking restrictions

Best you can do is maintain a list of public DoH IPs and block them. Redirect all port 53 traffic to your own DNS server.