Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
495 Pages « < 213 214 215 216 217 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
kwss
post Aug 8 2024, 12:10 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
DNS wall climbing for beginner
This quick guide will teach you how to use CDN to front DoH server using Amazon CloudFront.
The benefit this provides over other method is the difficulty of the censor to block this kind of setup without blocking the whole CDN provider.

Requirements:
AWS Account
Browser / OS / resolver supporting DoH

Login to your AWS account and search for CloudFront. Create a new distribution.
Refer to the setting below and put in your desired DoH server:
user posted image

After you are done creating the distribution, wait for it to finish deploying:
user posted image

Put the address and the full path into your browser / OS / resolver:
user posted image

Finally test your resolver:
user posted image
kwss
post Aug 8 2024, 12:23 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
DNS wall climbing stealth setup
This is a setup for people who are already using CloudFront for their business and wish to hide DoH inside it.
I am using ControlD here instead of Cloudflare DNS. The "/dns-query" in cloudflare is "/p0" in controld.

First add an Origin like below:
user posted image

Then add a Behavior:
user posted image

Wait for it to finish deploying. You will access it via https://mydomain.com/bkaj41f

For people wondering what is my "DoH-fronting" policy, here is it:
user posted image
Rhetoric
post Aug 8 2024, 12:44 AM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
Omg twitch lagging again.
Kadaj
post Aug 8 2024, 01:35 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
QUOTE(zellleonhart @ Aug 7 2024, 11:46 PM)
Yeah like kwss said, it's free, I have my own home server on a thin client that hosts a few services such as Home Assistant, Adguard Home, some docker containers and stuff. Just pay for the electricity. I can also use the VPS that hosts my static website but for the time being I prefer to use my home server.

I also have a VPN already but I don't connect to VPN all the time because some sites/games need me to turn off VPN. But the primary reason I set up Adguard Home is to block ads and stuff. The DNS stuff is an after thought and just happened to integrate quite well.
*
I thought you're using VPS + domain coz you mention about unbound, and if i'm not mistaken unbound is actually unencrypted so the ISP still can eavesdrop your unbound queries unless you setup your unbound in foreign country VPS and then DoH back to your devices.
QUOTE(kwss @ Aug 7 2024, 11:06 PM)
I think since he already has a domain, he must also have something already running. So the cost is free. It is just additional path configuration in nginx and whatever software behind the scene.

Even if you do not have a domain, do not have any cloud instance, you can still create a CloudFront Distribution and Amazon will assign you something like dxxxxxxxxxxxxx.cloudfront.net.
1TB egress per month is free. USD $0.02/GB for origin request. Let's say you use 5GB of DNS request traffic per month, it is only USD $0.10 per month. I never heard of any home user with 5GB per month of DNS request. DNS response is free and covered under 1TB quota.

I think the free 10 millions request per month is more than enough for DNS requests.
*
Thanks for your tutorials above, it really help me a lot. notworthy.gif
I'll try to set it up.
blackbox14
post Aug 8 2024, 02:32 AM

Casual
***
Junior Member
347 posts

Joined: Jul 2012
QUOTE(kwss @ Aug 8 2024, 12:10 AM)
DNS wall climbing for beginner
This quick guide will teach you how to use CDN to front DoH server using Amazon CloudFront.
The benefit this provides over other method is the difficulty of the censor to block this kind of setup without blocking the whole CDN provider.

Requirements:
AWS Account
Browser / OS / resolver supporting DoH
*
Just want to ask. Isn't this illegal or against the ToS of these cloud service providers? I've heard of domain fronting before and I thought it was mostly restricted. Or is that a different thing altogether?
junsheng
post Aug 8 2024, 03:18 AM

---> pokemon ftw <---
******
Senior Member
1,257 posts

Joined: Apr 2011
From: Penang Malaysia, sometime KL


QUOTE(blackbox14 @ Aug 8 2024, 02:32 AM)
Just want to ask. Isn't this illegal or against the ToS of these cloud service providers? I've heard of domain fronting before and I thought it was mostly restricted. Or is that a different thing altogether?
*
if it's discovered / reported you just get a ban
then proceed to created another new account for the same thing
junsheng
post Aug 8 2024, 03:27 AM

---> pokemon ftw <---
******
Senior Member
1,257 posts

Joined: Apr 2011
From: Penang Malaysia, sometime KL


QUOTE(blacktubi @ Aug 7 2024, 02:36 PM)
They can implement a blanket block on both DoT and DoH for public DNS if they want. But for now, DoT works.

If they enforce a strict block, just get a cloud instance in SG for $5 a month and VPN everything there.
*
yes they can,

but looking at the hours of what TM did on may and june, if they decided to flip the switch with same configuration
dot won't work, since majority of dot servers only do it on port 853
unless the consumers resorted to those that support dot on port 443 and get a performance hit as most of those are just small player and test server

This post has been edited by junsheng: Aug 8 2024, 03:37 AM
blackbox14
post Aug 8 2024, 03:35 AM

Casual
***
Junior Member
347 posts

Joined: Jul 2012
QUOTE(junsheng @ Aug 8 2024, 03:18 AM)
if it's discovered / reported you just get a ban
then proceed to created another new account for the same thing
*
I still think the risk that you can get banned for domain fronting should be highlighted in the guide since you need to input credit card info, real name/address, etc. to register for AWS.
kwss
post Aug 8 2024, 03:41 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(blackbox14 @ Aug 8 2024, 03:35 AM)
I still think the risk that you can get banned for domain fronting should be highlighted in the guide since you need to input credit card info, real name/address, etc. to register for AWS.
*
This is not domain fronting as i do not spoof SNI anywhere. The SNI and Host header are the same throughout the connection.

All CDN already blocked domain fronting.
junsheng
post Aug 8 2024, 03:47 AM

---> pokemon ftw <---
******
Senior Member
1,257 posts

Joined: Apr 2011
From: Penang Malaysia, sometime KL


QUOTE(blackbox14 @ Aug 8 2024, 03:35 AM)
I still think the risk that you can get banned for domain fronting should be highlighted in the guide since you need to input credit card info, real name/address, etc. to register for AWS.
*
few k/ did it neumerous times
blackbox14
post Aug 8 2024, 04:02 AM

Casual
***
Junior Member
347 posts

Joined: Jul 2012
QUOTE(kwss @ Aug 8 2024, 03:41 AM)
This is not domain fronting as i do not spoof SNI anywhere. The SNI and Host header are the same throughout the connection.

All CDN already blocked domain fronting.
*
Thanks for clarifying. Wanted to be sure since it sounded very similar to that, but I didn't know the technical differences.
zellleonhart
post Aug 8 2024, 10:22 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(Kadaj @ Aug 8 2024, 01:35 AM)
I thought you're using VPS + domain coz you mention about unbound, and if i'm not mistaken unbound is actually unencrypted so the ISP still can eavesdrop your unbound queries unless you setup your unbound in foreign country VPS and then DoH back to your devices.

Thanks for your tutorials above, it really help me a lot.  notworthy.gif
I'll try to set it up.
*
Yeah I thought of doing it at first but the latency should be quite high since the VPS is in the US.

Yeah unbound queries are unencrypted but I have now configured unbound upstream to DnsCrypt or Oblivious DoH instead of direct querying the root servers, so unbound is just doing the forwarding and caching.

This post has been edited by zellleonhart: Aug 8 2024, 10:23 AM
TheBladeRunner
post Aug 8 2024, 11:42 AM

Getting Started
**
Junior Member
199 posts

Joined: Jan 2013
Hey all, I need to ask about applying new unifi line.

Can I apply for new installation from another state? Let's say I'm in Sabah working but would like to apply unifi from TM point at another home in Johor.

Appreciate feedback on this.
tng55
post Aug 8 2024, 01:20 PM

Regular
******
Senior Member
1,443 posts

Joined: Sep 2021


QUOTE(Raymond T. @ Aug 7 2024, 08:56 PM)
Asus brand better then TP-Link ? I remember back old days using Asus Router very fast spoiled
*
mine asus router not very fast spoiled already long usage asus router i think over 7 years running strong
ASUS RT-AC68U still going strong over
YoungMan
post Aug 8 2024, 02:33 PM

Look at all my stars!!
*******
Senior Member
6,815 posts

Joined: Oct 2008
From: Kuala Lumpur



QUOTE(TheBladeRunner @ Aug 8 2024, 11:42 AM)
Hey all, I need to ask about applying new unifi line.

Can I apply for new installation from another state? Let's say I'm in Sabah working but would like to apply unifi from TM point at another home in Johor.

Appreciate feedback on this.
*
Untested, but logically can. Just need to make sure someone is at home in Johor during installation. Otherwise, just apply online through Unifi website.
sHawTY
post Aug 8 2024, 05:00 PM

Frequent Reporter
********
All Stars
14,909 posts

Joined: Jul 2005

QUOTE(TheBladeRunner @ Aug 8 2024, 11:42 AM)
Can I apply for new installation from another state? Let's say I'm in Sabah working but would like to apply unifi from TM point at another home in Johor.
Possible with ALLO (tested it myself) for my in-laws internet

Not sure about UniFi though
hazairi
post Aug 8 2024, 06:03 PM

Look at all my stars!!
*******
Senior Member
2,694 posts

Joined: Feb 2007
From: KL


Anybody went to TMPOINT recently? What's the latest SWU package they provide?
NagaK
post Aug 8 2024, 06:11 PM

Regular
******
Senior Member
1,194 posts

Joined: Sep 2018


Guys help for this price is actually worth?
I'm planning to upgrade from TP Link AX73

Normal price is about RM1000.00
I guess

This post has been edited by NagaK: Aug 8 2024, 06:13 PM


Attached thumbnail(s)
Attached Image
A183RT0
post Aug 8 2024, 07:33 PM

Getting Started
**
Junior Member
108 posts

Joined: Nov 2008
From: Labuan


Is something wrong with TM this week??
This problem happens on last Friday, so i contact TM from Facebook (Since 3 of the customer service number is useless and no one is picking up)
their representative gives me the EasyFix Guide and i told them already tried(turn off router, they reset the port and etc) still the same
so they make a report number and the technician came to my home on this Monday, checked the cables and make speed test with their temporary account but end up also the same.
my plan is 500Mbps and yet i keep getting below 100Mbps

so now, what i am trying to say is, WHAT THE HECK IS GOING ON??

here is today's speed test result
user posted image

i can't even watch streams using the UnifiTV app

This post has been edited by A183RT0: Aug 8 2024, 07:35 PM
denver1347
post Aug 8 2024, 08:09 PM

Getting Started
**
Junior Member
252 posts

Joined: Apr 2006


QUOTE(kcl2006ch @ Aug 7 2024, 11:02 PM)
need login into router using admin password
*
Yes, after login with TMadmin account.
I only see my unifi id password in "dot dot dot".

How to know the real password. notworthy.gif notworthy.gif

495 Pages « < 213 214 215 216 217 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0327sec    0.68    6 queries    GZIP Disabled
Time is now: 13th December 2025 - 12:26 AM