4 ms·
Dnsmasq is amazing. I spend quite the amount of time learning its config when hacking DD-WRTs. One thing that always bothered me is how hard it is to set Dnsma
by WirelessGigabit 2y ago
Dnsmasq is amazing. I spend quite the amount of time learning its config when hacking DD-WRTs.
One thing that always bothered me is how hard it is to set Dnsmasq to do SLAAC but no RDNS.
You see, if you set
enable-ra
[0], it defaults to using link-local address of the machine as the rDNS server.
You can set another one by setting
dhcp-option=option6:dns-server,[2001:4860:4860::8844]
If you don't enable DHCPv6 that entry is used as the rdns entry.
BUT...
That means that if you read through this there is no easy way to prevent a DNS address from being distributed, and it is quite common to want to do that. One of the reasons is that I want my clients to use IPv4 so I can track them, but still allow them to use SLAAC (and thus privacy protections) to talk to the outside world. But if they use SLAAC to talk to my DNS, I get WAY too many addresses in there.
The trick is to set:
dhcp-option=option6:dns-server
an empty value... Not sure if you can add the comma or not.
I could only find 1 reference online: https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2020q4/014521.html https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/20...
I firmly believe that this design choice has made it as such that no commercially available, customer router has support for SLAAC without rDNS.
[0] https://dnsmasq.org/docs/dnsmasq-man.html#:~:text=By%20default%2C%20the%20relevant%20link%2Dlocal%20address%20of%20the%20machine%20running%20dnsmasq%20is%20sent%20as%20recursive%20DNS%20server https://dnsmasq.org/docs/dnsmasq-man.html#:~:text=By%20defau....
- devman0 2y agoI've seen IPv6 deployments where internal names use ULA addresses for tracking/monitoring purposes, but outbound traffic SLAAC is used by hosts since having multiple IPv6 address per an interface is somewhat normal.