Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DNS Filtering is incompatible with Heimdal security dark layer #4180

Closed
umarmughal opened this issue Mar 29, 2022 · 36 comments
Closed

DNS Filtering is incompatible with Heimdal security dark layer #4180

umarmughal opened this issue Mar 29, 2022 · 36 comments

Comments

@umarmughal
Copy link

DNS Filtering doesn't work in Windows 11, as soon as i enable it my internet disconnects, anyone found this issue and solved please advise, it's quite irritating now.

@adguard-bot adguard-bot changed the title DNS Filtering Not Working - Windows 11 DNS Filtering causes internet connection problems Mar 30, 2022
@Aydinv13
Copy link

Aydinv13 commented Apr 6, 2022

From messages in private chat:
"Hi, i found the problem but not able to fix it, the issue is caused because Network Protection is enabled https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-network-protection?view=o365-worldwide but i am not able to set it to Audit Mode i found key in regedit but when i try to change value from 0 to 2 i get this error "cannot edit enablenetworkprotection. error writing the value's new contents" .. any idea how to fix this?"

2022-03-30_00

@Aydinv13
Copy link

Aydinv13 commented Apr 6, 2022

@umarmughal you may not have the rights to do so. Defender Endpoint implies that it has a computer under the control of the organisation's administrator, who gives permission.

@umarmughal
Copy link
Author

@Aydinv13 it's my system and i have all the rights no need any permission from administration, issue is something else ...

@northis
Copy link
Member

northis commented Apr 7, 2022

@umarmughal Try to set permissions on the registry key like described in this article:
https://www.howtogeek.com/262464/how-to-gain-full-permissions-to-edit-protected-registry-keys/

@umarmughal
Copy link
Author

@northis this idea works but only till i sleep my system, once i wake it up internet gone .. i must restart system again and this is definitely not the solution ...

@umarmughal
Copy link
Author

ok i can confirm that even this trick is not working either, today when i open my system no internet and as soon as i disabled dns filtering laptop connected ...

@northis
Copy link
Member

northis commented Apr 13, 2022

@umarmughal To disable network protection, try this from Microsoft Docs

On a standalone computer, go to Start and then type and select Edit group policy.
...
In the Group Policy Management Editor, go to Computer configuration and select Administrative templates.
Expand the tree to Windows components > Microsoft Defender Antivirus > Windows Defender Exploit Guard > Network >protection.
...
Disable (Default) - The Network protection feature won't work. Users won't be blocked from accessing malicious domains.

@umarmughal
Copy link
Author

@northis even after disabling network protection issue is still there, can not enable dns filtering in adguard .. looks like the issue is heimdal security dark layer (enabled).

@adguard-bot adguard-bot changed the title DNS Filtering causes internet connection problems DNS Filtering is incompatible with Heimdal security dark layer Apr 29, 2022
@Aydinv13
Copy link

@umarmughal how can we get Heimdal Security Darklayer? May be you can share distributive for us to check it on our side? Because it's not reproduced with just Heimdal Security. If you don't mind we can receive it via email devteam@adguard.com

@umarmughal
Copy link
Author

@Aydinv13 you can download the antivirus here www.heimdalsecurity.com and enable darklayer (screenshot attached) to test with AG.

DarkLayer

@Aydinv13
Copy link

Aydinv13 commented May 4, 2022

@umarmughal sorry for a big delay, it seems that the issue is reproduced on our side so it will be easier to trace what's causing it.

@northis
Copy link
Member

northis commented May 26, 2022

@umarmughal This Heimdal software sets their local DNS server as a system one. We are still investigate the problem, because this is real tricky to reproduce. A possible fix for you is to set a custom bootstrap address in the Advanced Settings to a plain working DNS, for ex. 8.8.8.8
image

This address will be used to resolve DNS-over-HTTPS address such as dns.adguard.com or other.

@umarmughal
Copy link
Author

@northis can i set here AG DNS IPs or 8.8.8.8?

@northis
Copy link
Member

northis commented May 29, 2022

@umarmughal it's up to you, any working DNS can be used.

@umarmughal
Copy link
Author

@northis thanks but this is not solving my issue.

@northis
Copy link
Member

northis commented May 30, 2022

@umarmughal Please, send us your logs again.

And we prepared a special build for this issue https://uploads.adguard.com/AdGuard.7.10.3936.gh4180.01.exe
You can set the log level to Debug and install this build. The issue may be fixed. If not - please, send us the logs after.

@umarmughal
Copy link
Author

@northis do i need to uninstall the current version of AG and reinstall this one?

@northis
Copy link
Member

northis commented May 30, 2022

You can install this build over the current version, but better to export your settings before to be able to install the previous version again (like a precaution).
I've updated the download link in my previous message.

@umarmughal
Copy link
Author

@northis damn looks like its working with this build ...

AGDNS

@zubrRB
Copy link

zubrRB commented Aug 28, 2022

У меня тоже в 7.11 beta 1 после проверки начал вылетать UI либо отключаться фильтрация и желтеть значок в трее...

@northis
Copy link
Member

northis commented Aug 29, 2022

У меня тоже в 7.11 beta 1 после проверки начал вылетать UI либо отключаться фильтрация и желтеть значок в трее...

Пожалуйста, отправьте ваши логи с моментом вылета UI/службы нам на почту devteam@adguard.com

@zubrRB
Copy link

zubrRB commented Aug 29, 2022

@northis в конце прошлой недели дважды после аварийного вылета отправлял из приложения и пару минут назад.

@northis
Copy link
Member

northis commented Aug 29, 2022

@zubrRB спасибо за логи

I close this issue because we cannot reproduce the issue with Heimdal. It can be re-opened in any time.

@umarmughal
Copy link
Author

@northis closing the issue because you can't figure out the solution?

@northis
Copy link
Member

northis commented Dec 13, 2022

Sent logs & dumps to Heimdal, we are waiting a response from them.

@northis
Copy link
Member

northis commented Dec 16, 2022

@umarmughal Looks like we have found a fix thanks to the guys at Heimdal. Add tls://8.8.8.8 or tls://1.1.1.1 as bootstrap DNS in Advanced Settings. Plain DNS won't work here. We will automate this soon in the next release.

@northis northis reopened this Dec 16, 2022
@umarmughal
Copy link
Author

@northis looks like this trick fix the issue, so far there is no problem even after putting my system to sleep and wake it up after an hour or so .. it's still connected and DNS filtering is on ...

@umarmughal
Copy link
Author

@northis but why heimdal dark layer started eating system resources now, is it because of this?

Heimdal

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants