Open GFNIAE opened 2 years ago
Hello again, I have found that fdns runs OK if I don't use --net=wlan0 as a firejail option (it was in my ~/firejail/globals.local options file).
So my issue should be changed : is there a way to use fdns as DNS proxy, and network isolation through "net" option in firejail ? Or should I choose one of them ? I believe that "net" option in firejail is great to isolate network and be sure that your sandboxed process can not see what's going on with other connected processes. I would like to have both, network sandwbox and DoH through fdns proxy...
Hello, I found a way to achieve my goal (network isolation with firejail --net=... option, and DoH through fdns) :
But that's not very handy, since you have to use sudo to launch an "everyday" app. WIthout that, fdns listens on 127.1.1.1 (default adress), but cannot see what"s going on inside your filejail network-sandboxed process. You would need a kind of exception in order to let dns requesting go through the sandboxed network to 127.1.1.1. I don't know whether such an exception can be set.
OT
since you have to use sudo to launch an "everyday" app.
Thanks rusty-snake for the link ! That's obviously what I needed.
I found another useful way to start fdns : I wrote a "/usr/bin/fdns --dameonize" file in /etc/network/if-up.d That launches fdns when the network is up, which is nice. That way I don't need to add a command when I launch an app through fdns, and I don't need sudo as well. Of course I have only one fdns running with one port available, so less abilities than with "sudo fdns --options...." for each application.
Surprisingly I didn't manage to switch off fdns in /etc/network/if-down.d, it seems to have no effect (with /usr/bin/pkill fdns). I use connman as my network manager.
Hello,
I use fdns on antiX Linux 21 with runit as a init process, and connman as a connection manager. Standard "sudo fdns --daemonize" then "firejail dns=127.1.1.1 palemoon" works well, and "fdns --monitor" let see the name resolution working.
However on MX Linux 21, I cannot get this working. I added "--nodnsproxy" for connmand options. "sudo fdns" shows this kind of output :
"fdns -monitor"
And palemoon or librewolf don't want to connect to anything. What should I check or change ?