Static
Validation test suite using one of the DNS options available in an upstream server
DNS-over-HTTPS Server
Description
Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream server.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name RD set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb set service dns proxy static RD protocol dns-over-https host name remote.dns set service dns proxy static RD protocol dns-over-https ip 10.215.168.1 set service dns resolver local set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:37:11.335972 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:37:11.337634 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:37:11.337696 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:37:11.347611 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:37:11.584291 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:37:11.871455 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:11.961774 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:37:12.028922 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:12.133640 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:12.191002 osdx ubnt-cfgd[707841]: inactive Sep 17 00:37:12.217598 osdx INFO[707852]: FRR daemons did not change Sep 17 00:37:12.253626 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:37:12.297794 osdx WARNING[707923]: No supported link modes on interface eth0 Sep 17 00:37:12.299312 osdx modulelauncher[707923]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:37:12.299326 osdx modulelauncher[707923]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:37:12.300632 osdx modulelauncher[707923]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:37:12.300642 osdx modulelauncher[707923]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:37:12.518890 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:12.519539 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:12.540090 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:12.688534 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:37:12.754055 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:37:12.892070 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:12.948598 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:37:13.055340 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:37:13.137945 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'. Sep 17 00:37:13.232399 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'. Sep 17 00:37:13.301840 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'. Sep 17 00:37:13.390072 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:37:13.459905 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:13.557542 osdx ubnt-cfgd[708030]: inactive Sep 17 00:37:13.581905 osdx INFO[708039]: FRR daemons did not change Sep 17 00:37:13.595805 osdx ca-certificates[708054]: Updating certificates in /etc/ssl/certs... Sep 17 00:37:14.149078 osdx ubnt-cfgd[709067]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:37:14.157534 osdx ca-certificates[709073]: 1 added, 0 removed; done. Sep 17 00:37:14.160314 osdx ca-certificates[709079]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:37:14.162921 osdx ca-certificates[709081]: done. Sep 17 00:37:14.266112 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:37:14.277305 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:14.277990 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:14.293411 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:37:14.293688 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Network connectivity detected Sep 17 00:37:14.293764 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Dropping privileges Sep 17 00:37:14.296236 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Network connectivity detected Sep 17 00:37:14.296314 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:37:14.296314 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:37:14.296314 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Firefox workaround initialized Sep 17 00:37:14.296314 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpw6bs5bbj] Sep 17 00:37:14.299871 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:14.444801 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] [RD] OK (DoH) - rtt: 130ms Sep 17 00:37:14.444801 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] Server with the lowest initial latency: RD (rtt: 130ms) Sep 17 00:37:14.444801 osdx dnscrypt-proxy[709137]: [2026-09-17 00:37:14] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 3: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:
teldat.com has address 19.18.17.16Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 19.18.17.16
DNS-over-HTTPS Server Trusting Fails
Description
Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream without setting up certificates.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Note
The above commands set the network topology to interact with the DNS server
Step 2: Modify the following configuration lines in DUT0 :
set service dns proxy server-name RD set service dns proxy static RD protocol dns-over-https host name remote.dns set service dns proxy static RD protocol dns-over-https ip 10.215.168.1 set service dns resolver local
Note
The above commands set up the DNS server to be used.
Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:
: x509: certificate signed by unknown authorityShow output
Sep 17 00:37:20.317791 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:37:20.318844 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:37:20.318892 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:37:20.327228 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:37:20.542947 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:37:20.803442 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:20.907875 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:37:20.990006 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:21.061860 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:21.166437 osdx ubnt-cfgd[710912]: inactive Sep 17 00:37:21.192042 osdx INFO[710923]: FRR daemons did not change Sep 17 00:37:21.222850 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:37:21.273332 osdx WARNING[710994]: No supported link modes on interface eth0 Sep 17 00:37:21.274785 osdx modulelauncher[710994]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:37:21.274801 osdx modulelauncher[710994]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:37:21.275954 osdx modulelauncher[710994]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:37:21.275963 osdx modulelauncher[710994]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:37:21.492309 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:21.492796 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:21.520959 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:21.685930 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:37:21.759492 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:37:21.938426 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:22.020251 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:22.173080 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:22.253276 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:22.322125 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:22.505518 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:22.565115 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:37:22.673914 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'. Sep 17 00:37:22.742089 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'. Sep 17 00:37:22.868690 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:37:22.988678 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show changes'. Sep 17 00:37:23.087358 osdx ubnt-cfgd[711108]: inactive Sep 17 00:37:23.108692 osdx INFO[711115]: FRR daemons did not change Sep 17 00:37:23.219231 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:37:23.227469 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:23.227973 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:23.243468 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:23.250372 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:37:23.250584 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Network connectivity detected Sep 17 00:37:23.250643 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Dropping privileges Sep 17 00:37:23.252920 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Network connectivity detected Sep 17 00:37:23.252966 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:37:23.252966 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:37:23.252966 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Firefox workaround initialized Sep 17 00:37:23.252966 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] Loading the set of cloaking rules from [/tmp/tmphsbumzv4] Sep 17 00:37:23.269614 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [ERROR] Get "https://remote.dns/dns-query?dns=yv4BAAABAAAAAAABAAACAAEAACkQAAAAAAAAFAAMABDvSnrUqIjsm87likvKcYFn": x509: certificate signed by unknown authority Sep 17 00:37:23.269614 osdx dnscrypt-proxy[711173]: [2026-09-17 00:37:23] [NOTICE] dnscrypt-proxy is waiting for at least one server to be reachable
Step 4: Run the command show host lookup teldat.com type A on DUT0 and expect the following output:
Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused ;; communications error to 127.0.0.1#53: timed out ;; no servers could be reached CLI Error: Command error
Note
The above command attempts to resolve the hostname but fails because the certificate cannot be verified
DNS-over-HTTPS Server Trusting
Description
Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream without checking its certificate authority.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Note
The above commands set the network topology to interact with the DNS server
Step 2: Modify the following configuration lines in DUT0 :
set service dns proxy server-name RD set service dns proxy ssl-allow-insecure set service dns proxy static RD protocol dns-over-https host name remote.dns set service dns proxy static RD protocol dns-over-https ip 10.215.168.1 set service dns resolver local
Note
The above commands set up the DNS server to be used, we skip certificate validation using set service dns proxy ssl-allow-insecure
Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:37:33.289746 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:37:33.292056 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:37:33.292116 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:37:33.300369 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:37:33.545280 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:37:33.911890 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:34.065864 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:37:34.151236 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:34.277056 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:34.396715 osdx ubnt-cfgd[711475]: inactive Sep 17 00:37:34.432541 osdx INFO[711486]: FRR daemons did not change Sep 17 00:37:34.468169 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:37:34.544357 osdx WARNING[711557]: No supported link modes on interface eth0 Sep 17 00:37:34.546409 osdx modulelauncher[711557]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:37:34.546424 osdx modulelauncher[711557]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:37:34.547955 osdx modulelauncher[711557]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:37:34.547968 osdx modulelauncher[711557]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:37:34.830861 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:34.831498 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:34.854876 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:35.052379 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:37:35.170946 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:37:35.395485 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:35.486310 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:35.603223 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:35.694972 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:35.805823 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:35.962698 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:36.023380 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:37:36.133210 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'. Sep 17 00:37:36.214184 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'. Sep 17 00:37:36.306188 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy ssl-allow-insecure'. Sep 17 00:37:36.415847 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:37:36.499521 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show changes'. Sep 17 00:37:36.595586 osdx ubnt-cfgd[711672]: inactive Sep 17 00:37:36.617363 osdx INFO[711679]: FRR daemons did not change Sep 17 00:37:36.720505 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:37:36.730672 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:36.731333 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:36.743014 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:37:36.743256 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Network connectivity detected Sep 17 00:37:36.743286 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Dropping privileges Sep 17 00:37:36.745526 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Network connectivity detected Sep 17 00:37:36.745526 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:37:36.745526 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:37:36.745526 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Firefox workaround initialized Sep 17 00:37:36.745526 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpmgzqvjof] Sep 17 00:37:36.755870 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:36.864324 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] [RD] OK (DoH) - rtt: 111ms Sep 17 00:37:36.864324 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] Server with the lowest initial latency: RD (rtt: 111ms) Sep 17 00:37:36.864324 osdx dnscrypt-proxy[711737]: [2026-09-17 00:37:36] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 4: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:
teldat.com has address 19.18.17.16Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 19.18.17.16
DNS-over-HTTPS Server With Stamp
Description
Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream server (generating a DNS stamp and using it to configure the connection).
Scenario
Step 1: Run the command service dns proxy stamp calculate dns-over-https host-name remote.dns host-path /dns-query host-port 443 ip 10.215.168.1 hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb on DUT0 and expect the following output:
Show output
sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCdOPz40xvQyBkJihW3cRIQMjuJPCkSzE3v2K6Ms_uZ-wpyZW1vdGUuZG5zCi9kbnMtcXVlcnk
Step 2: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name RD set service dns proxy static RD stamp 'sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCdOPz40xvQyBkJihW3cRIQMjuJPCkSzE3v2K6Ms_uZ-wpyZW1vdGUuZG5zCi9kbnMtcXVlcnk' set service dns resolver local set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:37:43.300382 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:37:43.304356 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:37:43.304416 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:37:43.312321 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:37:43.527669 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:37:43.757786 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:43.877487 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:37:43.938174 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:44.056222 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:44.130956 osdx ubnt-cfgd[712040]: inactive Sep 17 00:37:44.159572 osdx INFO[712051]: FRR daemons did not change Sep 17 00:37:44.196350 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:37:44.251448 osdx WARNING[712122]: No supported link modes on interface eth0 Sep 17 00:37:44.253250 osdx modulelauncher[712122]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:37:44.253265 osdx modulelauncher[712122]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:37:44.254630 osdx modulelauncher[712122]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:37:44.254640 osdx modulelauncher[712122]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:37:44.499535 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:44.500283 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:44.525402 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:44.669955 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:37:44.770803 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:37:44.958231 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-over-https host-name remote.dns host-path /dns-query host-port 443 ip 10.215.168.1 hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'. Sep 17 00:37:45.151621 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:45.275909 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:37:45.424009 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:37:45.491564 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD stamp sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCdOPz40xvQyBkJihW3cRIQMjuJPCkSzE3v2K6Ms_uZ-wpyZW1vdGUuZG5zCi9kbnMtcXVlcnk'. Sep 17 00:37:45.581241 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:37:45.648924 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:45.745321 osdx ubnt-cfgd[712231]: inactive Sep 17 00:37:45.769319 osdx INFO[712240]: FRR daemons did not change Sep 17 00:37:45.783309 osdx ca-certificates[712256]: Updating certificates in /etc/ssl/certs... Sep 17 00:37:46.325024 osdx ubnt-cfgd[713268]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:37:46.332957 osdx ca-certificates[713274]: 1 added, 0 removed; done. Sep 17 00:37:46.335802 osdx ca-certificates[713280]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:37:46.338694 osdx ca-certificates[713282]: done. Sep 17 00:37:46.436729 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:37:46.445894 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:46.446393 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:46.462365 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:37:46.462627 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Network connectivity detected Sep 17 00:37:46.462768 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Dropping privileges Sep 17 00:37:46.462980 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:46.465412 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Network connectivity detected Sep 17 00:37:46.465468 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:37:46.465468 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:37:46.465468 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Firefox workaround initialized Sep 17 00:37:46.465468 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpcv4xj44g] Sep 17 00:37:46.608853 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:37:46.681237 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] [RD] OK (DoH) - rtt: 196ms Sep 17 00:37:46.681237 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] Server with the lowest initial latency: RD (rtt: 196ms) Sep 17 00:37:46.681237 osdx dnscrypt-proxy[713338]: [2026-09-17 00:37:46] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 4: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:
teldat.com has address 19.18.17.16Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 19.18.17.16
DNSCrypt Server
Description
Configures DUT0 to connect, using DNSCrypt over an upstream server.
Scenario
Step 1: Run the command service dns proxy dnscrypt public-key running://dnscrypt.crt on DUT0 and expect the following output:
Show output
30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2
Step 2: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name RD set service dns proxy static RD protocol dns-crypt ip 10.215.168.1 set service dns proxy static RD protocol dns-crypt port 8443 set service dns proxy static RD protocol dns-crypt provider name 2.dnscrypt-cert.remote.dns set service dns proxy static RD protocol dns-crypt provider public-key '30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2' set service dns resolver local set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DNSCrypt\) - rtt: \d+ms$Show output
Sep 17 00:37:54.334343 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:37:54.335132 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:37:54.335172 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:37:54.345600 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:37:54.563642 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:37:54.846462 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:54.941718 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:37:55.019261 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:37:55.130705 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:55.192430 osdx ubnt-cfgd[715117]: inactive Sep 17 00:37:55.221022 osdx INFO[715128]: FRR daemons did not change Sep 17 00:37:55.251128 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:37:55.298349 osdx WARNING[715199]: No supported link modes on interface eth0 Sep 17 00:37:55.300013 osdx modulelauncher[715199]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:37:55.300027 osdx modulelauncher[715199]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:37:55.301275 osdx modulelauncher[715199]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:37:55.301288 osdx modulelauncher[715199]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:37:55.504719 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:55.505365 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:55.533849 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:37:55.731723 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:37:55.818352 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:37:55.940825 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy dnscrypt public-key running://dnscrypt.crt'. Sep 17 00:37:56.135460 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:37:56.257087 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:37:56.337747 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:37:56.481138 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt ip 10.215.168.1'. Sep 17 00:37:56.557395 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt port 8443'. Sep 17 00:37:56.656600 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt provider name 2.dnscrypt-cert.remote.dns'. Sep 17 00:37:56.716669 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt provider public-key 30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2'. Sep 17 00:37:56.805687 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:37:56.899162 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:37:56.990420 osdx ubnt-cfgd[715309]: inactive Sep 17 00:37:57.015676 osdx INFO[715318]: FRR daemons did not change Sep 17 00:37:57.029913 osdx ca-certificates[715334]: Updating certificates in /etc/ssl/certs... Sep 17 00:37:57.593248 osdx ubnt-cfgd[716346]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:37:57.602091 osdx ca-certificates[716352]: 1 added, 0 removed; done. Sep 17 00:37:57.605009 osdx ca-certificates[716358]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:37:57.608574 osdx ca-certificates[716360]: done. Sep 17 00:37:57.715524 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:37:57.725141 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:37:57.725723 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:37:57.736563 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:37:57.736809 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Network connectivity detected Sep 17 00:37:57.736871 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Dropping privileges Sep 17 00:37:57.739880 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Network connectivity detected Sep 17 00:37:57.739959 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:37:57.739959 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:37:57.739959 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Firefox workaround initialized Sep 17 00:37:57.739959 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpws4mb1d_] Sep 17 00:37:57.740720 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] [RD] OK (DNSCrypt) - rtt: 0ms Sep 17 00:37:57.740720 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] Server with the lowest initial latency: RD (rtt: 0ms) Sep 17 00:37:57.740720 osdx dnscrypt-proxy[716418]: [2026-09-17 00:37:57] [NOTICE] dnscrypt-proxy is ready - live servers: 1 Sep 17 00:37:57.741054 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Step 4: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:
teldat.com has address 19.18.17.16Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 19.18.17.16
DNSCrypt Server With Stamp
Description
Configures DUT0 to connect, using DNSCrypt over an upstream server (generating a DNS stamp and using it to configure the connection).
Scenario
Step 1: Run the command service dns proxy dnscrypt public-key running://dnscrypt.crt on DUT0 and expect the following output:
Show output
30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2
Step 2: Run the command service dns proxy stamp calculate dns-crypt provider-name 2.dnscrypt-cert.remote.dns provider-key 30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2 ip 10.215.168.1 port 8443 on DUT0 and expect the following output:
Show output
sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIDB5Vjz-HdxuM_wh0XMOPMh3SXasfjdA67N_s6xDxMSiGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z
Step 3: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name RD set service dns proxy static RD stamp 'sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIDB5Vjz-HdxuM_wh0XMOPMh3SXasfjdA67N_s6xDxMSiGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z' set service dns resolver local set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DNSCrypt\) - rtt: \d+ms$Show output
Sep 17 00:38:03.362327 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:38:03.365510 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:38:03.365663 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:38:03.373316 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:38:03.624887 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:38:03.842445 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:38:03.933238 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:38:04.010081 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:38:04.124867 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:38:04.188593 osdx ubnt-cfgd[718194]: inactive Sep 17 00:38:04.219761 osdx INFO[718205]: FRR daemons did not change Sep 17 00:38:04.257508 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:38:04.309016 osdx WARNING[718276]: No supported link modes on interface eth0 Sep 17 00:38:04.310853 osdx modulelauncher[718276]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:38:04.310869 osdx modulelauncher[718276]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:38:04.312384 osdx modulelauncher[718276]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:38:04.312394 osdx modulelauncher[718276]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:38:04.515472 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:38:04.516056 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:38:04.541751 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:38:04.697746 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:38:04.776180 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:38:04.891197 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy dnscrypt public-key running://dnscrypt.crt'. Sep 17 00:38:04.996666 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-crypt provider-name 2.dnscrypt-cert.remote.dns provider-key 30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2 ip 10.215.168.1 port 8443'. Sep 17 00:38:05.152165 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:38:05.224351 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:38:05.331453 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:38:05.411904 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD stamp sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIDB5Vjz-HdxuM_wh0XMOPMh3SXasfjdA67N_s6xDxMSiGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z'. Sep 17 00:38:05.518215 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:38:05.647932 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:38:05.710170 osdx ubnt-cfgd[718386]: inactive Sep 17 00:38:05.734060 osdx INFO[718395]: FRR daemons did not change Sep 17 00:38:05.747465 osdx ca-certificates[718410]: Updating certificates in /etc/ssl/certs... Sep 17 00:38:06.346238 osdx ubnt-cfgd[719423]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:38:06.354846 osdx ca-certificates[719429]: 1 added, 0 removed; done. Sep 17 00:38:06.357804 osdx ca-certificates[719435]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:38:06.360537 osdx ca-certificates[719437]: done. Sep 17 00:38:06.485898 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:38:06.495332 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:38:06.495851 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:38:06.509751 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:38:06.509751 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Network connectivity detected Sep 17 00:38:06.510124 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Dropping privileges Sep 17 00:38:06.512403 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Network connectivity detected Sep 17 00:38:06.512479 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:38:06.512479 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:38:06.512538 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Firefox workaround initialized Sep 17 00:38:06.512538 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpyw1if_g4] Sep 17 00:38:06.513386 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] [RD] OK (DNSCrypt) - rtt: 0ms Sep 17 00:38:06.513386 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] Server with the lowest initial latency: RD (rtt: 0ms) Sep 17 00:38:06.513486 osdx dnscrypt-proxy[719493]: [2026-09-17 00:38:06] [NOTICE] dnscrypt-proxy is ready - live servers: 1 Sep 17 00:38:06.523976 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Step 5: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:
teldat.com has address 19.18.17.16Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 19.18.17.16