|1) Install cloudflared using homebrew:|
|brew install cloudflare/cloudflare/cloudflared|
|2) Create /usr/local/etc/cloudflared/config.yaml, with the following content|
|3) Activate cloudflared as a service|
|sudo cloudflared service install|
|dig +short @127.0.0.1 github.com AA|
|5) If OK, change DNS on your mac to 127.0.0.1 (System Preferences->Network->Advanced->DNS)|
cloudflared is documented at https://developers.cloudflare.com/18.104.22.168/dns-over-https/cloudflared-proxy/
Works perfectly. Thank you.
However, when connecting via a VPN, the following issue occurs:
For some reason, when a private address is used, Tunnelblick/OpenVPN is unable to override the default DNS with its own configuration as it is usually able to do.
Note that everything is still working correctly and neither my IP address nor DNS are leaking in a way that should compromise my privacy. Although, even if I decide to trust Cloudflare, I think I would prefer to use my VPN service's DNS server when I'm connected through it.
Anyone else run into this?
@fAS6NWnn7xA429U2, you have to do the following to make your VPN connection change DNS server:
There you go
@V33m — In that case, all I really needed to do was step 3. Thanks!
How do you personally feel about it? Would you rather keep 22.214.171.124 for normal internet activities and then switch it up for VPN use, or just go with 126.96.36.199 for everything to take advantage of its performance?
It's difficult to say the policies Cloudfare are going with. They have an agreement with Mozilla where they limit the logged data and data retention for Firefox users which enable DOH and are using DNS
I advice you to setup different DOH servers for different cases/activities. Here is a list of some possible DOH servers: https://github.com/curl/curl/wiki/DNS-over-HTTPS
New Issue: Tunnelblick will only update the WiFi DNS, not the Ethernet DNS.
I've set the priority to Ethernet-first in the Mac settings, turned off WiFi, and even set it to inactive, but Tunnelblick will not switch to Ethernet.
Is there a way to alter Tunnelblick's network priority or more ideally, have it interact with Ethernet only?