2021-01-01 12:06:41 +00:00
# DOT DOH with haproxy
2021-01-01 12:12:39 +00:00
2021-01-01 12:20:16 +00:00
**!!! denylist.rpz and allowlist.rpz are made for my _private_ use and will _cause_ problem with _some_ domain !!!**
2021-01-01 12:06:41 +00:00
```
Query
Dns-over-TLS
2021-01-11 13:15:52 +00:00
---------------------> Haproxy(Frontend) ----------------------------->
Cluster Listen(TCP/443/853)
---------------------> (HTTP/443) -------> m13253/DOH -------> Knot-resolver
Dns-over-HTTPS Listen(Local/http)Listen(Local/dns)
DNSCrypt v2
---------------------> jedisct1/Encrypted DNS Server ------------------->
Listen(TCP/UDP/8443)
2021-01-01 12:06:41 +00:00
```
2021-01-01 12:29:28 +00:00
# Recommendation
1. [knot-resolver ](https://knot-resolver.cz ) **Recommend** using upstream repository on debian
2021-01-02 14:40:57 +00:00
2. Download.sh **Recommend** if you want to download all the default filters used in kresd.conf(knot-resolver configuration)
2021-01-11 13:15:52 +00:00
3. [jedisct1/Encrypted-dns-server ](https://github.com/jedisct1/encrypted-dns-server ) is recommended if you are looking for an easy way to start a DNSCrypt server
4. [Mozilla ssl-config ](https://ssl-config.mozilla.org/ ) is recommended if you are looking for a sample TLS/SSL configuration for your Server Software
2021-01-02 15:04:04 +00:00
# Mirror / Fork
[notabug.org ](https://notabug.org/lottanorta/doh-dot-haproxy )
2021-01-15 13:00:43 +00:00
2021-01-15 13:00:21 +00:00
[codeberg.org ](https://codeberg.org/DoulpaGllo/doh-dot-haproxy )