Setup Cloudflare as a DoH (DNS over HTTPS) resolver on Mikrotik devices (RouterOS v7.0.2+)

Temporarily add a normal upstream DNS resolver
/ip dns set servers=1.1.1.1,1.0.0.1CA certificates extracted from Mozilla
/tool fetch url=https://curl.se/ca/cacert.pemImport the downloaded ca-store (127 certificates)
/certificate import file-name=cacert.pem passphrase=""Set the DoH resolver to cloudflare
/ip dns set use-doh-server=https://1.1.1.1/dns-query verify-doh-cert=yesRemove the old upstream DNS resolvers
/ip dns set servers=""Delete the certificate file
/file remove cacert.pemOPTIONAL - Disable DDNS
/ip dhcp-client set use-peer-dns=no # Enter 0 as a number if it asks youIf you are connection over LTE (for exmaple with a chateau)
/interface lte apn set use-peer-dns=no # Enter 0 as a number if it asks youVerify, that DynDNS is disabled
/ip dns print
Komentar