Secure DNS queries using DNSCrypt - XIYO/asuswrt-merlin.ng-kr GitHub Wiki

이 νŠœν† λ¦¬μ–Όμ€ asuswrt λΌμš°ν„°μ—μ„œ dnscryptλ₯Ό ν™œμ„±ν™”ν•˜λŠ” 방법에 λŒ€ν•΄ μ„€λͺ…ν•©λ‹ˆλ‹€.

Entware μ„€μΉ˜ν•˜κΈ°, κ·Έ λ‹€μŒ ν•„μš”ν•œ νŒ¨ν‚€μ§€λ“€μ„ μ„€μΉ˜ν•©λ‹ˆλ‹€:

opkg install dnscrypt-proxy fake-hwclock

λΌμš°ν„°μ— μƒˆλ‘œμš΄ 리쑸버 μ‚¬μš©μ„ μ§€μ‹œν•©λ‹ˆλ‹€:

echo -e "#!/bin/sh\nsed -i '/^servers-file=.*/d' \$1" > /jffs/scripts/dnsmasq.postconf
chmod 755 /jffs/scripts/dnsmasq.postconf
echo "no-resolv" > /jffs/configs/dnsmasq.conf.add
echo "server=127.0.0.1#65053" >> /jffs/configs/dnsmasq.conf.add

λΌμš°ν„° λΆ€νŒ… μ‹œ dnscrypt μ‹œμž‘ν•˜κΈ°

echo "/opt/etc/init.d/S09dnscrypt-proxy start" >> /jffs/scripts/services-start

μ˜¬λ°”λ₯Έ syslog μ‹œκ°„μ„ μœ„ν•΄ νƒ€μž„μ‘΄ λ³€μˆ˜ μ„€μ •

echo "export TZ=$(cat /etc/TZ)" >> /opt/etc/profile

(선택사항) λ‹€λ₯Έ DNS μ„œλ²„λ₯Ό μ‚¬μš©ν•˜μ—¬ ν΄λΌμ΄μ–ΈνŠΈμ— λ¦¬λ””λ ‰μ…˜ν•˜κΈ°: firewall-start λ˜λŠ” nat-start에 μΆ”κ°€ν•˜κΈ°

iptables -t nat -A PREROUTING -i br0 -p udp --dport 53 -j DNAT --to $(nvram get lan_ipaddr)
iptables -t nat -A PREROUTING -i br0 -p tcp --dport 53 -j DNAT --to $(nvram get lan_ipaddr)

λ³€κ²½ 사항을 μ μš©ν•˜κΈ° μœ„ν•΄ λΌμš°ν„° μž¬λΆ€νŒ…:

reboot

μž‘λ™ν•˜λŠ”μ§€ ν™•μΈν•˜κΈ°

dnscrypt μ„œλΉ„μŠ€ 쀑지

/opt/etc/init.d/S09dnscrypt-proxy stop

예λ₯Ό λ“€μ–΄ URL을 ping 해보기

ping bing.com

DNS 해석이 μž‘λ™ν•˜μ§€ μ•Šμ•„μ•Ό ν•©λ‹ˆλ‹€ λ‹€μ‹œ 켜기

/opt/etc/init.d/S09dnscrypt-proxy start

더 λ§Žμ€ 정보 및 토둠은 μ—¬κΈ°μ—μ„œ 확인할 수 μžˆμŠ΅λ‹ˆλ‹€.