QUOTE(Kadaj @ May 30 2024, 10:28 AM)
This is default plaintext method, which doesn't work for me.
This is when i connected to VPN and it works.
I tweak the unbound config to go through DoT method, and it works without vpn.
Just sharing my experience here.

Hi, do you want to give my configuration a try? Stop unbound. Backup your /var/lib/unbound and /etc/unbound and replace with mine.
All my config is in /etc/unbound/conf.d/my-setup.conf
Everything under /var/lib/unbound is the DNSSEC public key and bootstrap address for root server
Test 1 (list root):
CODE
$ dig +short @127.0.0.1 -p 5335
h.root-servers.net.
i.root-servers.net.
j.root-servers.net.
k.root-servers.net.
l.root-servers.net.
m.root-servers.net.
a.root-servers.net.
b.root-servers.net.
c.root-servers.net.
d.root-servers.net.
e.root-servers.net.
f.root-servers.net.
g.root-servers.net.
Test 2 (DNSSEC OK):
CODE
$ dig +short @127.0.0.1 -p 5335 sigok.ippacket.stream
sigok.rsa2048-sha256.ippacket.stream.
195.201.14.36
Test 3 (DNSSEC Failure. There must be no output for the test to pass!):
CODE
$ dig +short @127.0.0.1 -p 5335 sigfail.ippacket.stream
QUOTE(go626201 @ May 30 2024, 11:57 AM)
Yes, it does resolve new address with domain name host. Should be follow the ttl, i think.
I gotta say upfront I have no knowledge on smokeping.
If you are a Cloudflare customer, open a ticket and see what they say?
Not exactly sure if you want to try calling TM NOC directly to complain.
QUOTE(surrodox2001 @ May 30 2024, 09:27 PM)
(Apologies for late reply) Hello fellow FOSS users!
Yeah, if you got the resources, some preparations are good, like that's also why fault-tolerant network links uses satellite as backup?
Hi to you!
Starlink would be great to have as a backup for all cases including censorship but I am not ready to pay the price yet considering I have Maxis fiber and Celcom mobile right now.
I think I will go with 2 anti-censorship method:
Obfs4 proxy:
It is resistant to probing and when combined with Tor, it is undetectable.
But I think it can be discovered if you are targeted. It cannot be possible that you only use 1 IP address all the time.
Domain fronting:
I already have a AWS Cloudfront Distribution. I just need to add another Origin under the Distribution. I am hoping to find something that can work with AWS Lambda so I pay nothing if I never use it. Just as a backup.
The downside is obvious. In the event of forceful MITM, it will be discovered.
Attached File(s)
etc.unbound.tar.gz ( 28.47k )
Number of downloads: 4
var.lib.unbound.tar.gz ( 1.5k )
Number of downloads: 4