-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AdGuardHome Opnsense Plugin 1.7 Stops Internet After Selecting Parental Control and Browsing Security #4184
Comments
Any help would be appreciated to posted issue. |
Hello and thank you for the report! Can you enable verbose logging and look, what kind of logs are printed when this happens? Thanks! |
I have the verbose log while recreating the issue. Few lines from log file 2022/01/21 22:28:05.468466 78519#31 [debug] github.com/AdguardTeam/dnsproxy/proxy.(*Proxy).udpHandlePacket(): error handling DNS (udp) request: talking to dns upstream: failed to check host "catalog.gamepass.com": safe browsing: requesting https://dns-family.adguard.com:443/dns-query: Get "https://dns-family.adguard.com:443/dns-query?dns=9K8BAAABAAAAAAAABDYwNjYEMGJlZQJzYgNkbnMHYWRndWFyZANjb20AABAAAQ": net/http: request canceled (Client.Timeout exceeded while awaiting headers) 2022/01/21 22:28:14.088751 78519#88 [debug] github.com/AdguardTeam/dnsproxy/proxy.(*Proxy).udpHandlePacket(): error handling DNS (udp) request: talking to dns upstream: failed to check host "firebaseremoteconfig.googleapis.com": safe browsing: requesting https://dns-family.adguard.com:443/dns-query: Get "https://dns-family.adguard.com:443/dns-query?dns=uTABAAABAAAAAAAABDcxYjQENGU0YgQ1MTlkAnNiA2RucwdhZGd1YXJkA2NvbQAAEAAB": net/http: request canceled (Client.Timeout exceeded while awaiting headers) 2022/01/21 22:28:14.088875 78519#91 [debug] github.com/AdguardTeam/dnsproxy/proxy.(*Proxy).udpHandlePacket(): error handling DNS (udp) request: talking to dns upstream: failed to check host "firebaseremoteconfig.googleapis.com": safe browsing: requesting https://dns-family.adguard.com:443/dns-query: Get "https://dns-family.adguard.com:443/dns-query?dns=KjgBAAABAAAAAAAABDcxYjQENGU0YgQ1MTlkAnNiA2RucwdhZGd1YXJkA2NvbQAAEAAB": net/http: request canceled (Client.Timeout exceeded while awaiting headers) 2022/01/21 22:28:14.711635 78519#33 [error] shutting down http server "0.0.0.0:443": context deadline exceeded |
@mushtash, this may be due to AdGuard's security services (i.e. parental control and safe browsing) appearing unreachable from your location. Could you please check it with the
Unsuccesful result signs that these services indeed unreachable. In this case see the issue comment. |
Bad Site NSlookup *** fw.mydomain.com can't find pornhub.com: Non-existent domain PS C:\Users\user1> nslookup sex.com https://dns-family.adguard.com:443/dns-query *** fw.mydomain.com can't find sex.com: Non-existent domain Good Site Non-authoritative answer: What is expected when badsite lookup is queried. It should show AG DNS Servers or else what? |
From Opnsense, I don't have dnslookup utility. Is it required to test or just nslookup is fine.
** server can't find pornhub.com: NXDOMAIN |
@mushtash, nslookup is not able to use encrypted DNS. So yes, the dnslookup is required, you may download it from the releases page. The information collected with it is important for troubleshooting the issue. |
From Windows Host dnslookup for badsite ;; QUESTION SECTION: ;; ANSWER SECTION: |
any updates on this issue. I have provided dnslookup results. |
@mushtash, hello again. The dnslookup result looks OK actually. Is it performed from the host machine of AGH? Could you please also clarify what does "internet stops working" means? Does the issue reproduces in another browser? Finally, we'd like to look at the full verbose log. Could you please send it to devteam@adguard.com? Thanks. |
Yes dnslookup was done from windows host behind AGH. |
I have already sent email with required verbose log file. |
@mushtash, judging from the log, the domains are properly resolved with safe browsing and parental control services enabled. Are you sure AGH is the only DNS server in your network? Also, are you able to follow the plain IP address resolved with one of the services? For example, |
Thanks for the updates. PS C:\Users\user1> nslookup
*** fw.mydomain.com can't find family-block.dns.adguard.com: Non-existent domain
*** fw.mydomain.com can't find standard-block.dns.adguard.com: Non-existent domain |
@mushtash, sorry, I've just noticed the timeouts on requesting the safe browsing service in logs. These are probably mean that AGH can't actually reach the safe browsing servers. To confirm, could you please try to reach the security services from AGH's host machine with
|
I'm suspecting Unbound is causing some issue here. |
Any further help on this issue |
@mushtash, have you performed |
Please find the ping results from windows machine behind AGH PS C:\Users\user1> ping 94.140.14.15 Pinging 94.140.14.15 with 32 bytes of data: Ping statistics for 94.140.14.15: Pinging 94.140.15.16 with 32 bytes of data: Ping statistics for 94.140.15.16: |
any further updates on this issue |
No more updates. Any resolution? |
Is there any resolution to this issue? |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
@mushtash Sorry for the long silence! Is this issue still relevant in the latest version? |
I'm not sure which is new version of AGH in Opnsense or are you referring to OPN version 22.7? |
We are not the ones who support the plugin, so you may need to consult those developers. But testing the issue on the latest version would probably provide the necessary information. |
I'm running AdGuardHome Plugin 1.7 for Opnsense by m.a.x. it / mimugmail.
In Opnsense
AGH is listening on port 53
Unbound is listening on port 5353
In AGH Added DNS Upstream Servers
tls://family-filter-dns.cleanbrowsing.org
tls://dns-family.adguard.com
Bootstrap and Private rDNS resolver
Opnsense LAN IP address over 5353
Encryption Enabled with All Certs status valid
In AGH under general settings, if either one or both Parental Control and Browsing Security selected internet stops working.
With unchecked no issues.
Attached screen highlighted options causing internet issue. Host see DNS request Timed Out for nslookup
The text was updated successfully, but these errors were encountered: