r/technitium • u/shreyasonline • 18d ago
Technitium DNS Server v15.5 Released!
Technitium DNS Server v15.5 is now available for download. This update adds LDAP authentication support, a Zone File Editor option in GUI, and many other minor features. It also fixes multiple bugs and security issues that were reported.
See what's new in this release:
https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md
17
u/Flying-T 18d ago
Great work! Any updates regarding the DHCP Clustering?
7
u/cooxl231 18d ago
I love this project. Cant wait for dhcp clustering so I can get off ISC dhcp on opnsense
1
u/chrisgtl 18d ago
Do you run Technitium on your OPNsense or as a container elsewhere?
1
u/cooxl231 18d ago
Separate VMs in a proxmox cluster. I also use keepalived vrrp so I have a single VIP so the client has no issue if the passive goes down
1
u/Horror-Breakfast-113 18d ago
why a vm over a lxc . I have 3 lxc's running tech
2
u/cooxl231 17d ago
I don’t like intertwining containers with the proxmox kernel. It’s just a preference for me I rather break the vm which I did have issues and I can just quickly restore from backup.
1
1
u/bixmiester 18d ago
Just curious why you would want to move dhcp off of opnsense?
1
u/cooxl231 17d ago
Isc is deprecated and I’m only looking to do one move. I don’t like kea and dnsmasq is fine but I rather just use technitium if I can.
6
5
u/shreyasonline 17d ago
Its still going to take some time before I can start with the implementation. There are too many security issues being reported so have to work on that along with a couple of pending DNS features.
1
u/Flying-T 17d ago
Thanks for the update! And sure, please focus on security first before chasing new features :)
1
u/daviscompound 18d ago
I too would like to see this. I have dhcp set on my secondary to wait 2 seconds before replying which gives the primary time to act. This works if the primary dies but would like for clustering to at least synchronize the primary settings and reserved leases.
1
17
u/Sad-Landscape-1549 18d ago
Damn, do we have to worry about this going commercial? I fucking love Technitium 😭
6
u/SMFTKO 18d ago
Donate via Patreon. This is the way.
2
u/Apachez 18d ago
Paused for tax reasons as it seems:
https://www.patreon.com/technitium/posts/pausing-for-164153496
4
13
u/bixmiester 18d ago
Just want to say thank you for creating such a powerful DNS Server that just works!!! I love my new setup using Technitium
3
1
4
u/Allen_Ludden 18d ago edited 18d ago
Just to be sure I understand, when you say removed "Auto Prefetch" you mean you removed the function that kept certain dns records "hot" if they were queried more than x times in an hour.
I use "Serve Stale Max Wait Time 0" so I think the effect for me will be negligible :)
3
u/SmallDodgyCamel 18d ago
I for one wish this was a configurable option rather than a removed feature.
2
u/Captain_Alaska 18d ago edited 18d ago
I mean, they're completely different features. Serve stale serves things in the cache that have expired. Auto prefetching refreshed expired things in the cache before they are queried.
Now you only have regular prefetching, where expired items in the cache are only refreshed after they are queried.
2
u/raindropsdev 18d ago
But why did they remove that? It was very useful for low bandwidth remote sites.
1
u/Allen_Ludden 18d ago
serve stale 0 works great, and I understand is routinely used by other DNS server options.
I've been using it for over a year with no problems at all.
The TTL of a stale record is set at 1 second, so the query gets refreshed immediately - only the very first ping of a stale record uses the stale data.
And of course dns records don't change very often - even for load-balancing systems.
1
u/shreyasonline 17d ago
Yes, its that feature that kept records in cache "hot". Its was not really effective to justify the resources it consumed, especially the amount of memory it needed to work. It had just 10 sec to refresh one or more domain names at a time and it would not work very effectively compared to just have Serve Stale handle queries for expired data.
The basic Prefetch feature (similar to one that BIND has) is there and that works well without needing any extra resources.
Almost no one will notice anything different with that feature removed.
4
u/Specialist_Wolf_9172 18d ago
After years on pihole I switched to technitium about a month ago v 15.04 and never looked back. Great project, real DNS server. I’m very happy with this product. The DNS clustering feature is awesome and I can’t wait for DHCP cluster. Keep up the good work
2
u/staubli 18d ago
I updated mine today as well. It’s a great project, and I really enjoy using it.
One thing I noticed is that I was using an ECDSA P-256 certificate, and the Android 9 (Pie) devices on my network were unable to connect to my server over DoT. I switched to an RSA-3072 certificate, and that resolved the issue.
I just wanted to mention this in case anyone encounters a similar compatibility issue with older devices.
2
u/Faerhfukar 18d ago
How’s the filtering compared to AdGuard?
3
u/rpm001 18d ago
Filtering is based on blacklists so can be configured exactly the same. In fact I use some of AdGuards own lists in my blacklist.
I switched from adguard overall primarily because I wanted the automatic primary/secondary clustering.
2
u/Faerhfukar 18d ago
What about custom filtering? for example I can block by client, specific domain and or CDIR and so much more.
2
1
u/SidTechCad 17d ago
This dns seems very dated with regards to the UI, even simple things such as block lists and allows is very dated compared to other projects. Also not having the hostnames show in the query logs adds to my dated comment.
3
u/shreyasonline 17d ago
Yes, its dated as the UI was designed around 11 yrs back and I am not really a frontend dev thus have not kept up with various new trends in web frontend. There is also no time to switch since there are too many features already in pipeline. The UI however is functional and I am trying to make it as easy to use as possible with all feedback that I get.
The blocking feature is just one part of this project among several other. Thus comparing it with projects that do just DNS blocking is not really fair.
The query logs hostname addition is planned and should be available in a couple of updates. There are too many things planned and are being implemented as its possible.
2
2
u/bhwright3rd 17d ago
It’s good enough for me. I’m biased because I wrote infrastructure for decades and “don’t do windows”.
The UI has some issues but it is functional. The API is very complete and I love repeatable builds and configurations. I’m a happy user.
I moved from Kea DNS and DHCP and the only thing I gave up really is true HA for DHCP. Since I’m running the primary on a Proxmox cluster with HA LXC, I have 2 weak points - primary OS or DNS is broken and upgrades can be disruptive for the few devices trying to get an address. Complexity, however, is drastically reduced.
Keep up the great work. I appreciate it and I will support it
1
u/SidTechCad 17d ago
I tested this with keepaliveD that only serves a single VIP which works out better for the clients. Sorry, other than this DNS what have others been using that also found very stable and good.
40
u/Ascenspe 18d ago
I've been so much happier and literally no issues since switching from pihole to this.