14 ms·
Really neat idea but using nextDNS is so much easier without the need for a VPN of any sort.
by syntaxing 4y ago
Really neat idea but using nextDNS is so much easier without the need for a VPN of any sort.
- mtremsal 4y agoAgreed! In fact, I have NextDNS listed as an alternative in the README. To be fair though, the "VPN" here is peer-to-peer and, in the case of the Pi-hole, only used for DNS. We're not talking about tunneling all traffic. According to https://ping.nextdns.io/ https://ping.nextdns.io/ the latency is similar. I'd also imagine that on iOS the NextDNS app is implemented as a VPN, no? How else would they enforce the DNS config across networks? How would they avoid annoying tricks like ISP intercepting DNS? But overall, I agree my setup probably only makes if you're already using tailscale for other things. :p
- syntaxing 4y agoVery fair point, it is a VPN on android but you don’t have to use the app and set the DNS manually in the settings. As for iOS, it is not a VPN but a network profile (?, not sure what the exact name is). My home setup has nextDNS CLI locally running with all DNS request piped through iptables and masquerading.
- mtremsal 4y agoVery interesting! This made me realize that if someone is willing to give up the NextDNS apps and simply rely on their DNS nameservers, then they might still want to use Tailscale as a way to automatically enforce NextDNS nameservers for all enrolled devices. Kind of the best of both worlds.
- syntaxing 4y agoVery true, the magicDNS on tailscale is pretty amazing. Though the downside of this method is that when tailscale is off, the internet most likely will stop working (which might be a good thing in this case)