Cloudflare

How to Configure DNS over TLS (DoT) Using Unbound DNS in OPNsense

How to Configure DNS over TLS (DoT) Using Unbound DNS in OPNsense

Increase the security and privacy of DNS requests? Yes please...

Previously, I wrote about how to configure DNS over HTTPS using DNSCrypt-Proxy. Since Unbound DNS in OPNsense does not support DNS over HTTPS (DoH) directly, it was necessary to use the DNSCrypt-Proxy plugin. The plugin also supports DNS over TLS (DoT). However, I discovered while browsing Reddit that Unbound gained native support for DoT at some point in time, which is very nice. Because of built-in support for DoT, the configuration of DNS over TLS becomes pretty trivial.
How to Configure DNS over HTTPS (DoH) Using DNSCrypt-Proxy in OPNsense

How to Configure DNS over HTTPS (DoH) Using DNSCrypt-Proxy in OPNsense

Add more privacy by encrypting your DNS queries!

Historically, DNS is a service that was designed to be unencrypted. Whenever a device from your network is trying to go to a web address, it needs to determine the IP address of the website in order to access it. With the increasing levels of tracking and data sharing/selling, a growing awareness that having DNS traffic unencrypted is not a good idea from a privacy and security standpoint. ISPs and other entities are able to know which sites you visit even if all of your web traffic is encrypted.
Enabling Rocket Loader on Cloudflare Interfered with the Nextcloud web login page

Enabling Rocket Loader on Cloudflare Interfered with the Nextcloud web login page

Using Cloudflare to access your Nextcloud web interface? Beware of pitfalls...

When setting up Cloudflare for this website, I decided to try it out on some sites that I had setup on my home network. In particular, my Nextcloud web portal. All was going well until I began enabling various optimization features that are available in the free Cloudflare account. I noticed when accessing the Nextcloud web page from my work computer that it would not allow me to log in. The login button was visible but disabled.