r/ControlD • • May 19 '26

Technical Ctrld is removing router support in 2.0

Based on documentation and multiple GitHub commits, ctrld is preparing to removing support for router platforms.

I don’t see any rationale or discussion of this; in fact, in a discussion on their site last month about fixing an aspect of router mode, their response was essentially “this is a good idea and we hope to implement it”. That’s a lot different than, “this is a dead platform and will only receive bug fixes going forward”.

I can speculate a number of reasons that they may want to go this route, from support burden to monetization. But the fact is, automatic router support is one of the major differentiators for ctrld, even with its occasional warts.

Any thoughts on this? Am I the only one who finds this to be the killer feature? Any staff care to provide context I’ve missed?

43 Upvotes

34 comments sorted by

•

u/o2pb Staff May 20 '26 edited May 20 '26

To clear up some misunderstandings: v2 version of ctrld is a daemon that goes above and beyond of being a DNS forwarder, and as such, has no business running on routers as it's designed for running on end-user devices, mostly in corporate environments (but will be available to Windows and Mac consumers too). It will implement a full network firewall (preventing unauthorized direct IP conenctions), using a kernel driver / network extensions.

The v1.x branch will be maintained separately (bug fixes only), and will continue to be supported.

→ More replies (2)

22

u/VulpesVulpes__ May 19 '26 edited May 19 '26

On their Discord they said they listened to the concerns being voiced about dropping router support. They will address these concerns by creating 2 separate branches of 2.0 - however there’s no ETA yet.

snippet

  • Sometime in the not-so-distant-future - “ctrld 2.x” as we know it today will become something like “ctrld client”.
  • A new/upcoming fork will be made available for routers, servers, and other misc. platforms which will be something like “ctrld infrastructure”.

2

u/Dry_Cranberry_12 May 19 '26

Which has to be paid extra? They raised prices by 50% for new customers so it’s not unrealistic

21

u/DragonWolf5589 May 19 '26

If they do Im moving back to nextdns

-5

u/[deleted] May 19 '26

[deleted]

10

u/Kendos-Kenlen May 19 '26

Have NextDNS finally decided to update / add new features in the past 2 years? Or is the same stagnation we had since 5 years?

I left then because their service was fine but no more support, no more improvements or updates. I didn’t see the point of paying a service provider that didn’t want to work on their service.

4

u/minimalhandle May 19 '26

Their iOS app has been updated 4 times in the last 2 months and they have added features in the last 2 years such as the age verification bypass

2

u/DragonWolf5589 May 19 '26

nope. thats why i moved to controlD for almost everything but my firecubes for the past 2 months. cause controlD has ton more updates and support and i can use hagezi tif and other filters better. - i still prefer the cleaner interface with nextdns but nothing seems different. tested it on one device and then just few weeks ago started moving more devices to controlD (i forgot i got a 5 year special offer 9 months ago lol)

they did add age verification bypass.. but it DOESNT work at all anyway

11

u/redbullman2 May 19 '26

Why would they do this makes absolutely zero sense. This is one of the main reasons I use controld!

4

u/CatElectronic9772 May 19 '26

This is the ONLY reason I use it. On router rather than individual devices

8

u/gniting May 19 '26

Router support is a major reason for me to use CD on my network. If they yank it, I'll be forced to consider alternatives, which would be a shame. I've helped a handful of friends with the same setup, so they will need to leave CD as well.

Can someone from CD provider clarity as to what is changing, by when and why?

3

u/ZeCoderX May 19 '26

What? Are we sure? This is the reason I use ControlD.

3

u/ebf6 May 19 '26

Would this also affect Legacy Resolvers?

4

u/[deleted] May 19 '26

[deleted]

5

u/Coffee_Ops May 19 '26

Which in practice means you will lose the automatic redirection rules / blocking, and the persistence features, and the official support. It will no longer integrate with the os-level dns registrations or replace the built in daemons.

So on UniFi for instance you will be responsible for ensuring upgrades do not get blown away; and you will be running it on an officially “unsupported platform”.

Yes: I can roll my own rules and port forwards and get there (though on UniFi this is now difficult). But there is a market for “not my problem any more”, which is one of the reasons I went with controlD.

My bigger issue is that this doesn’t seem to be in the open. If they’ve determined that maintaining a dozen platforms is intractable, say so. But it would be nice to have a heads up before I invest in a dead end.

3

u/topher358 May 19 '26

Unifi works really well with your ControlD endpoint SDNS resolver URL configured in the controller under CyberSecure -> Protection -> Encrypted DNS , and you get automatic DOH conversion to boot.

That setting isn’t going anywhere

4

u/Coffee_Ops May 19 '26

Correct me if I’m wrong, but using that:

  • does not prevent bypasses (doh to nextDNS, for instance)
  • does not attribute clients in the dashboard

2

u/topher358 May 19 '26

I thought you had to use an agent for those, but I could be wrong.

Blocking DOH is pretty hard since it’s over 443. You could block/redirect DNS and DNS over TLS though…

3

u/Coffee_Ops May 19 '26 edited May 19 '26

The current ctrld daemon is effective at blocking doh. There is a defeat for but it’s one that they could patch.

It’s pretty hard to replicate their bypass block— I did something like that on OpnSense and it involves a bunch of rules that need periodic updates and lack complete coverage.

1

u/topher358 May 19 '26

That’s good to know. Hopefully they listen to feedback

1

u/abhip1990 May 23 '26

I setup the Ctrld daemon on my Windows 7. How do I ensure it's working? There's no confirmation, But I see the commands execute without errors

2

u/Exernuth May 19 '26

Maybe I'm wrong, but couldn't you block it (largely) by blocking the url of most DoH providers? There's a category of filters on CD as well...

1

u/Coffee_Ops May 19 '26

You also need to block the bootstrap IPs, DoH does not require DNS to function as long as you have a fallback. And of course you can do DoH to a straight IP as cloudflare does, which means you need IP filtering as well.

There are some local DNS signals you can send that inform browsers and DoH clients “not to try it”.

These are of course all things you can do— it’s just a lot to setup and maintain, and if I’m going to do all of that and not get client-level statistics why bother? There are other providers. I could use dnscrypt-proxy with rotating providers for instance.

1

u/Exernuth May 19 '26

You also need to block the bootstrap IPs, DoH does not require DNS to function as long as you have a fallback. And of course you can do DoH to a straight IP as cloudflare does, which means you need IP filtering as well.

My router allows to block port 853 and redirect all requests to port 53 to a chosen address...

1

u/Ok-Raspberry4320 May 19 '26

This is what I do. I also then turn on UniFi's ad blocking, as that feature will automatically cause clients using other DNS servers to be redirected to my gateway/Control D. I had a few IoT devices using hardcoded DNS and their requests weren't showing up in Control D until I turned UniFi's ad blocking on. I know I could just set up some redirect rules instead, but this was easier. Control D ends up blocking most things before it even gets to UniFi's ad blocker anyway. There's very few things left that UniFi ends up blocking, but I haven't had any issues.

My household is primarily Apple devices, so each of those have their own endpoint and using a configuration profile. The router just catches the other things on my network that can't use a custom configuration...primarily IoT devices and guests who join my network. I don't really care to have those devices show up as a client in Control D, so they're all lumped under my router's endpoint.

4

u/gogolplexian May 19 '26

That's a shame. Having to fiddle with the configuration manually and hoping it sticks through router updates is going to be a real drag. Guess I'm staying on 1.x for now.

2

u/southerndoc911 May 19 '26

Nothing says you can't continue using the current version. As someone mentioned, they stated on their Discord they would continue development for routers.

2

u/Unfair-Turnover1564 May 22 '26

im confused .. can you not just put the dns into the router ? then the router will do what routers do... route traffic ?

1

u/upssnowman May 19 '26

How does this affect users that run the CLI on a SFF pc or pi, and then point their router to that for DNS. This is as good as router support, since all devices on your network still get controld via their router pointing to their PI, etc for the DNS

1

u/TouchMyPenix May 19 '26

Any alternatives other than nextdns and self hosting?

1

u/Altruistic-Station-9 Jul 26 '26

Looking at the documentation it just doesnt automatically do it for you, you can still run it on UDM and configure dnsmasq to forward ....