[squid-users] Force DNS queries over TCP?

Chris Horry zerbey at gmail.com
Thu Jun 30 19:07:00 UTC 2016



On 06/30/2016 14:55, Alex Crow wrote:
> 
> 
> On 30/06/16 19:40, brendan kearney wrote:
>>
>> Nscd or name server caching daemon may be of help.  I believe you can
>> run your own bind instqnce and point it at the roots, instead of using
>> your isp's broken implementation
>>
>> On Jun 30, 2016 2:21 PM, "Chris Horry" <zerbey at gmail.com
>> <mailto:zerbey at gmail.com>> wrote:
> 
> If the ISP is intercepting and redirecting all connections to UDP/53,
> which seems to be the case, I'm not sure this would help, unless the
> roots support TCP access.
> 
> Chris, can you confirm this seems to be your ISP's behaviour? If so,
> avoiding sending *any* queries in cleartext via UDP/53 is the only way
> to do it.

That is indeed my ISP's behaviour, they force redirect UDP/53 to their
broken implementation so the only option I have is to use TCP.

Chris

-- 
Chris Horry
zerbey at gmail.com
http://www.twitter.com/zerbey
PGP:638C3E7A

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20160630/be41bc61/attachment-0001.sig>


More information about the squid-users mailing list