<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>dns &#8211; 中年韭菜的自我关爱</title>
	<atom:link href="https://www.muyunyying.top/tag/dns/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.muyunyying.top</link>
	<description>一枚番茄爹的碎碎念</description>
	<lastBuildDate>Sun, 24 May 2020 13:13:29 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
<site xmlns="com-wordpress:feed-additions:1">153092130</site>	<item>
		<title>日常脑力游戏vsGFW，抵抗dns污染</title>
		<link>https://www.muyunyying.top/2020/05/23/%e6%97%a5%e5%b8%b8%e8%84%91%e5%8a%9b%e6%b8%b8%e6%88%8fvsgfw%ef%bc%8c%e6%8a%b5%e6%8a%97dns%e6%b1%a1%e6%9f%93/</link>
					<comments>https://www.muyunyying.top/2020/05/23/%e6%97%a5%e5%b8%b8%e8%84%91%e5%8a%9b%e6%b8%b8%e6%88%8fvsgfw%ef%bc%8c%e6%8a%b5%e6%8a%97dns%e6%b1%a1%e6%9f%93/#respond</comments>
		
		<dc:creator><![CDATA[muyunyying]]></dc:creator>
		<pubDate>Sat, 23 May 2020 13:31:10 +0000</pubDate>
				<category><![CDATA[建站]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[hyper-v]]></category>
		<category><![CDATA[nas]]></category>
		<category><![CDATA[vps]]></category>
		<guid isPermaLink="false">https://www.muyunyying.top/?p=1868</guid>

					<description><![CDATA[搜了一圈以后的方案（其实就是抄的） 环境：centos7.5 dnsmasq + dnscrypt-proxy [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>搜了一圈以后的方案（其实就是抄的）</p>
<p>环境：centos7.5</p>
<p>dnsmasq + dnscrypt-proxy(走dns over https负责解析墙外）+  dnsmasq-china-list（负责解析墙内）</p>
<p>1.dnscrypt-proxy安装<br />
<code><br />
wget https://github.com/DNSCrypt/dnscrypt-proxy/releases/download/2.0.42/dnscrypt-proxy-linux_x86_64-2.0.42.tar.gz<br />
tar xf dnscrypt-proxy-linux_x86_64-2.0.42.tar.gz<br />
cd linux-x86_64<br />
mv example-dnscrypt-proxy.toml dnscrypt-proxy.toml<br />
vim dnscrypt-proxy.toml<br />
修改：<br />
listen_addresses = ['127.0.0.1:35353']  #修改默认53端口为35353<br />
dnscrypt_servers = false #关闭dnscrypt，只使用doh<br />
修改完毕<br />
./dnscrypt-proxy -service install<br />
./dnscrypt-proxy -service start<br />
systemctl status dnscrypt-proxy #check服务运行没有<br />
nslookup tp.m-team.cc 127.0.0.1 -port=35353 #测试解析<br />
or dig @127.0.0.1 -p 35353 tp.m-team.cc<br />
</code></p>
<p>2.dnsmasq修改<br />
<code><br />
vim /etc/dnsmasq.conf<br />
修改：<br />
no-resolv<br />
no-poll<br />
no-hosts<br />
server=127.0.0.1#35335<br />
cache-size=4096<br />
修改完毕<br />
netstat -nautp #检查端口占用，发现已有一个dnsmasq进程<br />
ps aux | grep dnsmasq #发现libvirt服务启动了dnsmasq<br />
yum remove libvirt-daemon<br />
systemctl enable dnsmasq #添加开机启动<br />
</code></p>
<p>3.dnsmasq-china-list<br />
<code><br />
wget https://github.com/felixonmars/dnsmasq-china-list/blob/master/install.sh<br />
bash install.sh<br />
#检查/etc/dnsmasq.d/目录，有没有多出来的文件<br />
</code></p>
<p>4.查看dnsmasq解析日志<br />
<code><br />
vim /etc/dnsmasq.conf<br />
log-queries<br />
log-facility=/var/log/dnsmasq.log<br />
#查看日志，国内域名forward到114，国外域名forward到本机dnscrypt-proxy(doh)<br />
May 23 21:11:56 dnsmasq[2626]: query[A] sina.com from 127.0.0.1<br />
May 23 21:11:56 dnsmasq[2626]: forwarded sina.com to 180.76.76.76<br />
May 23 21:11:56 dnsmasq[2626]: forwarded sina.com to 114.114.115.115<br />
May 23 21:11:56 dnsmasq[2626]: forwarded sina.com to 114.114.114.114<br />
May 23 21:11:56 dnsmasq[2626]: reply sina.com is 66.102.251.24<br />
May 23 21:12:22 dnsmasq[2626]: query[A] youtube.com from 127.0.0.1<br />
May 23 21:12:22 dnsmasq[2626]: forwarded youtube.com to 127.0.0.1<br />
May 23 21:12:22 dnsmasq[2626]: reply youtube.com is 172.217.161.78<br />
</code></p>
<p>5.打开防火墙53端口<br />
<code><br />
firewall-cmd --permanent --add-service=dns<br />
systemctl restart firewalld<br />
</code></p>
<p>通过其他ip nslookup到192.168.1.202成功</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.muyunyying.top/2020/05/23/%e6%97%a5%e5%b8%b8%e8%84%91%e5%8a%9b%e6%b8%b8%e6%88%8fvsgfw%ef%bc%8c%e6%8a%b5%e6%8a%97dns%e6%b1%a1%e6%9f%93/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1868</post-id>	</item>
	</channel>
</rss>
