Draytek 2862ac - DNSSEC Query

Associate
Joined
1 May 2019
Posts
5
Location
Yorkshire
New to the forum, but not firewalls etc :)

Just got myself a lovely 2862ac to replace an ageing Cisco RV134W unit. Internet access, wifi, DHCP, MAC binding, bandwidth management, outbound packet filters and service objects all sorted without issues.

My question is around DNS Security. I'd like my router to act as the DNS server on my network, fulfilling requests via DNSSEC against googles 8.8.8.8. I can't seem to find how to specify my WAN DNS servers, without using the option of 'force router to use the DNS servers settings from LAN1'. In this instance the router is then configured to connect to 8.8.8.8 using DNSSEC fine, however my clients also then get dished 8.8.8.8 for DNS, and bypass the router for queries.

Any clues anyone?
 
Thanks for the response.

However, in this scenario, local machines don't take advantage of DNS Security natively. If I swap a client to use the draytek as its DNS server, I see the DNS cache build on the draytek which would indicate requests being served by it. If i then clear that cache and use the DNS server dished by the drayteks DHCP scope (8.8.8.8) the requests go directly out and aren’t fulfilled by the draytek itself.

The ideal I'm looking for, is to set the DCHP scope to advertise the draytek as the clients DNS server, and the draytek use 8.8.8.8 securely. This is possible, although only by manually repointing the clients DNS servers which is not ideal.
 
Last edited:
Thanks for all the advice, Ive got it working/resolved I believe. Still testing completely however.

The trick it turns out, is to utilise the conditional DNS forwarding feature. I created a parameter of *.* (as it supports wildcards) and pointed it at the IP of the Draytek. I can see the cache building on the router in response to queries I make on clients, even though the clients are configured with 8.8.8.8 as their DNS server. The ‘force router to use DNS settings’ feature is still enabled, and looking at 8.8.8.8 with DNS Security confirming the green padlock.

Still need to somehow verify all this mind!!
 
Last edited:
Back
Top Bottom