Static Server
Test suite that connects DUT1 over DUT0 using DoH. Meanwhile, DUT0 establishes a connection with the upstream server and forwards DNS queries to it.
Server With Upstream DoH
Description
Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream server.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server cert file 'running://dns.dut0.crt' set service dns proxy server cert key 'running://dns.dut0.key' set service dns proxy server-name RD set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb set service dns proxy static RD protocol dns-over-https host name remote.dns set service dns proxy static RD protocol dns-over-https ip 10.215.168.1 set service dns resolver local set service dns static host-name teldat.com inet 10.11.12.13 set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:35:59.328937 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.8M free. Sep 17 00:35:59.329422 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:35:59.329486 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:35:59.340853 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:35:59.610065 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:35:59.845850 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:35:59.949210 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:36:00.048613 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:00.126554 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:00.225366 osdx ubnt-cfgd[695112]: inactive Sep 17 00:36:00.260508 osdx INFO[695123]: FRR daemons did not change Sep 17 00:36:00.293441 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:00.347642 osdx WARNING[695194]: No supported link modes on interface eth0 Sep 17 00:36:00.349323 osdx modulelauncher[695194]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:00.349338 osdx modulelauncher[695194]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:00.350872 osdx modulelauncher[695194]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:36:00.350882 osdx modulelauncher[695194]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:36:00.600661 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:00.601850 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:00.645034 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:00.836710 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:36:00.959806 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:02.529818 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:02.593670 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:36:02.711771 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:36:02.783699 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'. Sep 17 00:36:02.873424 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'. Sep 17 00:36:02.936819 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'. Sep 17 00:36:03.035633 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert file running://dns.dut0.crt'. Sep 17 00:36:03.103516 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert key running://dns.dut0.key'. Sep 17 00:36:03.215145 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:36:03.282037 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns static host-name teldat.com inet 10.11.12.13'. Sep 17 00:36:03.388952 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:03.453219 osdx ubnt-cfgd[695304]: inactive Sep 17 00:36:03.476075 osdx INFO[695313]: FRR daemons did not change Sep 17 00:36:03.488347 osdx ca-certificates[695329]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:04.028070 osdx ubnt-cfgd[696341]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:04.036730 osdx ca-certificates[696347]: 1 added, 0 removed; done. Sep 17 00:36:04.039798 osdx ca-certificates[696353]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:04.042795 osdx ca-certificates[696355]: done. Sep 17 00:36:04.173848 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:04.182759 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:04.183310 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:04.195486 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:04.195740 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Network connectivity detected Sep 17 00:36:04.195880 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Dropping privileges Sep 17 00:36:04.198298 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Network connectivity detected Sep 17 00:36:04.198359 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:04.198359 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:04.198359 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Now listening to https://[::]:3000/dns-query [DoH] Sep 17 00:36:04.198359 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Firefox workaround initialized Sep 17 00:36:04.198359 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpc7vjgzhg] Sep 17 00:36:04.215948 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:04.359020 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] [RD] OK (DoH) - rtt: 143ms Sep 17 00:36:04.359020 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] Server with the lowest initial latency: RD (rtt: 143ms) Sep 17 00:36:04.359020 osdx dnscrypt-proxy[696414]: [2026-09-17 00:36:04] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 3: Set the following configuration in DUT1 :
set interfaces ethernet eth0 address 10.215.168.65/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name DUT0 set service dns proxy static DUT0 protocol dns-over-https hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396 set service dns proxy static DUT0 protocol dns-over-https host name dns.dut0 set service dns proxy static DUT0 protocol dns-over-https host port 3000 set service dns proxy static DUT0 protocol dns-over-https ip 10.215.168.64 set service dns static host-name dns.dut0 inet 10.215.168.64 set service ssh set system certificate trust 'running://CA.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Run the command system journal show | cat on DUT1 and check whether the output matches the following regular expressions:
(?m)^.*\[DUT0\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:35:59.293982 osdx systemd-journald[2055]: Runtime Journal (/run/log/journal/db82908865474f16bd4eb2f983136eff) is 944.0K, max 6.4M, 5.5M free. Sep 17 00:35:59.297521 osdx systemd-journald[2055]: Received client request to rotate journal, rotating. Sep 17 00:35:59.297592 osdx systemd-journald[2055]: Vacuuming done, freed 0B of archived journals from /run/log/journal/db82908865474f16bd4eb2f983136eff. Sep 17 00:35:59.306437 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:35:59.568371 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:01.027341 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:01.185993 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.65/24'. Sep 17 00:36:01.255329 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:01.411119 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service ssh'. Sep 17 00:36:01.541668 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:01.619804 osdx ubnt-cfgd[878423]: inactive Sep 17 00:36:01.716277 osdx INFO[878449]: FRR daemons did not change Sep 17 00:36:01.749647 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:01.807065 osdx WARNING[878520]: No supported link modes on interface eth0 Sep 17 00:36:01.809044 osdx modulelauncher[878520]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:01.809065 osdx modulelauncher[878520]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:01.810523 osdx modulelauncher[878520]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off -- Sep 17 00:36:01.810534 osdx modulelauncher[878520]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75. Sep 17 00:36:01.909782 osdx systemd[1]: Starting ssh.service - OpenBSD Secure Shell server... Sep 17 00:36:01.923393 osdx sshd[878581]: Server listening on 0.0.0.0 port 22. Sep 17 00:36:01.923573 osdx sshd[878581]: Server listening on :: port 22. Sep 17 00:36:01.923704 osdx systemd[1]: Started ssh.service - OpenBSD Secure Shell server. Sep 17 00:36:02.101208 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:02.102107 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:02.141434 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:02.310803 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'ping 10.215.168.64 count 1 size 56 timeout 1'. Sep 17 00:36:04.385462 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:04.458355 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns static host-name dns.dut0 inet 10.215.168.64'. Sep 17 00:36:04.550665 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set system certificate trust running://CA.crt'. Sep 17 00:36:04.605119 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy server-name DUT0'. Sep 17 00:36:04.727062 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https host name dns.dut0'. Sep 17 00:36:04.798344 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https host port 3000'. Sep 17 00:36:04.898150 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https ip 10.215.168.64'. Sep 17 00:36:05.008767 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396'. Sep 17 00:36:05.150604 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:05.267973 osdx ubnt-cfgd[878644]: inactive Sep 17 00:36:05.296484 osdx INFO[878653]: FRR daemons did not change Sep 17 00:36:05.317266 osdx ca-certificates[878669]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:05.898944 osdx ubnt-cfgd[879681]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:05.906502 osdx ca-certificates[879687]: 1 added, 0 removed; done. Sep 17 00:36:05.909537 osdx ca-certificates[879693]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:05.912424 osdx ca-certificates[879695]: done. Sep 17 00:36:05.985911 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:05.997846 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:05.998540 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:06.015567 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:06.160126 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:06.161219 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Network connectivity detected Sep 17 00:36:06.161219 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Dropping privileges Sep 17 00:36:06.197148 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Network connectivity detected Sep 17 00:36:06.197300 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:06.197300 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:06.197300 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Firefox workaround initialized Sep 17 00:36:06.197300 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpspffxtd4] Sep 17 00:36:06.198077 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:06.531707 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] [DUT0] OK (DoH) - rtt: 126ms Sep 17 00:36:06.531707 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] Server with the lowest initial latency: DUT0 (rtt: 126ms) Sep 17 00:36:06.531707 osdx dnscrypt-proxy[879702]: [2026-09-17 00:36:06] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 5: Run the command show host lookup teldat.com type A on DUT1 and check whether the output contains the following tokens:
teldat.com has address 10.11.12.13Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 10.11.12.13
Server With Upstream DoH With Stamp
Description
Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream server (generating a DNS stamp and using it to configure the connection).
Scenario
Step 1: Run the command service dns proxy stamp calculate dns-over-https host-name remote.dns host-path /dns-query host-port 443 ip 10.215.168.1 hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb on DUT0 and expect the following output:
Show output
sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCdOPz40xvQyBkJihW3cRIQMjuJPCkSzE3v2K6Ms_uZ-wpyZW1vdGUuZG5zCi9kbnMtcXVlcnk
Step 2: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server cert file 'running://dns.dut0.crt' set service dns proxy server cert key 'running://dns.dut0.key' set service dns proxy server-name RD set service dns proxy static RD stamp 'sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCdOPz40xvQyBkJihW3cRIQMjuJPCkSzE3v2K6Ms_uZ-wpyZW1vdGUuZG5zCi9kbnMtcXVlcnk' set service dns resolver local set service dns static host-name teldat.com inet 10.11.12.13 set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:36:16.305701 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:36:16.308948 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:36:16.309015 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:36:16.317630 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:36:16.560662 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:16.818155 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:16.982962 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:36:17.045862 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:17.164899 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:17.240497 osdx ubnt-cfgd[698187]: inactive Sep 17 00:36:17.292033 osdx INFO[698198]: FRR daemons did not change Sep 17 00:36:17.328990 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:17.390110 osdx WARNING[698269]: No supported link modes on interface eth0 Sep 17 00:36:17.392157 osdx modulelauncher[698269]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:17.392177 osdx modulelauncher[698269]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:17.393817 osdx modulelauncher[698269]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:36:17.393830 osdx modulelauncher[698269]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:36:17.639132 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:17.639774 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:17.687605 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:17.879326 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:36:17.954741 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:19.778945 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-over-https host-name remote.dns host-path /dns-query host-port 443 ip 10.215.168.1 hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'. Sep 17 00:36:19.934393 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:20.007137 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:36:20.144798 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:36:20.249531 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD stamp sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCdOPz40xvQyBkJihW3cRIQMjuJPCkSzE3v2K6Ms_uZ-wpyZW1vdGUuZG5zCi9kbnMtcXVlcnk'. Sep 17 00:36:20.354675 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert file running://dns.dut0.crt'. Sep 17 00:36:20.435476 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert key running://dns.dut0.key'. Sep 17 00:36:20.552742 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns static host-name teldat.com inet 10.11.12.13'. Sep 17 00:36:20.692585 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:36:20.812405 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns static host-name teldat.com inet 10.11.12.13'. Sep 17 00:36:20.944092 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:21.055356 osdx ubnt-cfgd[698381]: inactive Sep 17 00:36:21.084301 osdx INFO[698390]: FRR daemons did not change Sep 17 00:36:21.099695 osdx ca-certificates[698406]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:21.806621 osdx ubnt-cfgd[699418]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:21.815290 osdx ca-certificates[699424]: 1 added, 0 removed; done. Sep 17 00:36:21.819573 osdx ca-certificates[699430]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:21.823886 osdx ca-certificates[699432]: done. Sep 17 00:36:21.953936 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:21.964213 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:21.964810 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:21.976561 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:21.976777 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Network connectivity detected Sep 17 00:36:21.976865 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Dropping privileges Sep 17 00:36:21.979088 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Network connectivity detected Sep 17 00:36:21.979172 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:21.979172 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:21.979172 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Now listening to https://[::]:3000/dns-query [DoH] Sep 17 00:36:21.979172 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Firefox workaround initialized Sep 17 00:36:21.979172 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:21] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpu4tazetd] Sep 17 00:36:21.999216 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:22.129129 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:22] [NOTICE] [RD] OK (DoH) - rtt: 127ms Sep 17 00:36:22.129129 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:22] [NOTICE] Server with the lowest initial latency: RD (rtt: 127ms) Sep 17 00:36:22.129129 osdx dnscrypt-proxy[699491]: [2026-09-17 00:36:22] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 4: Run the command service dns proxy stamp calculate dns-over-https host-name dns.dut0 host-path /dns-query host-port 3000 ip 10.215.168.64 hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396 on DUT1 and expect the following output:
Show output
sdns://AgAAAAAAAAAADTEwLjIxNS4xNjguNjQg8sHqN3uuN9GvZbMR70-wsXn6xdQvS-GB-UiWMD9As5YNZG5zLmR1dDA6MzAwMAovZG5zLXF1ZXJ5
Step 5: Set the following configuration in DUT1 :
set interfaces ethernet eth0 address 10.215.168.65/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name DUT0 set service dns proxy static DUT0 stamp 'sdns://AgAAAAAAAAAADTEwLjIxNS4xNjguNjQg8sHqN3uuN9GvZbMR70-wsXn6xdQvS-GB-UiWMD9As5YNZG5zLmR1dDA6MzAwMAovZG5zLXF1ZXJ5' set service dns static host-name dns.dut0 inet 10.215.168.64 set service ssh set system certificate trust 'running://CA.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 6: Run the command system journal show | cat on DUT1 and check whether the output matches the following regular expressions:
(?m)^.*\[DUT0\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:36:16.291947 osdx systemd-journald[2055]: Runtime Journal (/run/log/journal/db82908865474f16bd4eb2f983136eff) is 928.0K, max 6.4M, 5.5M free. Sep 17 00:36:16.292307 osdx systemd-journald[2055]: Received client request to rotate journal, rotating. Sep 17 00:36:16.292342 osdx systemd-journald[2055]: Vacuuming done, freed 0B of archived journals from /run/log/journal/db82908865474f16bd4eb2f983136eff. Sep 17 00:36:16.302625 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:36:16.532104 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:18.355565 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:18.448232 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.65/24'. Sep 17 00:36:18.522928 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:18.640990 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service ssh'. Sep 17 00:36:18.712214 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:18.806715 osdx ubnt-cfgd[881470]: inactive Sep 17 00:36:18.925660 osdx INFO[881496]: FRR daemons did not change Sep 17 00:36:18.964173 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:19.019068 osdx WARNING[881567]: No supported link modes on interface eth0 Sep 17 00:36:19.021514 osdx modulelauncher[881567]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:19.021531 osdx modulelauncher[881567]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:19.023232 osdx modulelauncher[881567]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off -- Sep 17 00:36:19.023247 osdx modulelauncher[881567]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75. Sep 17 00:36:19.124506 osdx systemd[1]: Starting ssh.service - OpenBSD Secure Shell server... Sep 17 00:36:19.137242 osdx sshd[881628]: Server listening on 0.0.0.0 port 22. Sep 17 00:36:19.137265 osdx sshd[881628]: Server listening on :: port 22. Sep 17 00:36:19.137395 osdx systemd[1]: Started ssh.service - OpenBSD Secure Shell server. Sep 17 00:36:19.322619 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:19.323255 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:19.353899 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:19.521184 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'ping 10.215.168.64 count 1 size 56 timeout 1'. Sep 17 00:36:22.218039 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-over-https host-name dns.dut0 host-path /dns-query host-port 3000 ip 10.215.168.64 hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396'. Sep 17 00:36:22.367832 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:22.428831 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns static host-name dns.dut0 inet 10.215.168.64'. Sep 17 00:36:22.517783 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set system certificate trust running://CA.crt'. Sep 17 00:36:22.572143 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy server-name DUT0'. Sep 17 00:36:22.671294 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 stamp sdns://AgAAAAAAAAAADTEwLjIxNS4xNjguNjQg8sHqN3uuN9GvZbMR70-wsXn6xdQvS-GB-UiWMD9As5YNZG5zLmR1dDA6MzAwMAovZG5zLXF1ZXJ5'. Sep 17 00:36:22.734439 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:22.831312 osdx ubnt-cfgd[881691]: inactive Sep 17 00:36:22.856701 osdx INFO[881700]: FRR daemons did not change Sep 17 00:36:22.870496 osdx ca-certificates[881716]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:23.407924 osdx ubnt-cfgd[882728]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:23.418369 osdx ca-certificates[882734]: 1 added, 0 removed; done. Sep 17 00:36:23.421565 osdx ca-certificates[882740]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:23.424726 osdx ca-certificates[882742]: done. Sep 17 00:36:23.500763 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:23.518303 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:23.519112 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:23.536260 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:23.590557 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:23.590557 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Network connectivity detected Sep 17 00:36:23.590557 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Dropping privileges Sep 17 00:36:23.593466 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Network connectivity detected Sep 17 00:36:23.593552 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:23.593552 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:23.593552 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Firefox workaround initialized Sep 17 00:36:23.593626 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Loading the set of cloaking rules from [/tmp/tmp9ao7k20g] Sep 17 00:36:23.722976 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:23.790786 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] [DUT0] OK (DoH) - rtt: 120ms Sep 17 00:36:23.790786 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] Server with the lowest initial latency: DUT0 (rtt: 120ms) Sep 17 00:36:23.790786 osdx dnscrypt-proxy[882749]: [2026-09-17 00:36:23] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 7: Run the command show host lookup teldat.com type A on DUT1 and check whether the output contains the following tokens:
teldat.com has address 10.11.12.13Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 10.11.12.13
Server With Upstream DNSCrypt
Description
Configures DUT0 to connect, using DNSCrypt over an upstream server.
Scenario
Step 1: Run the command service dns proxy dnscrypt public-key running://dnscrypt.crt on DUT0 and expect the following output:
Show output
30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2
Step 2: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server cert file 'running://dns.dut0.crt' set service dns proxy server cert key 'running://dns.dut0.key' set service dns proxy server-name RD set service dns proxy static RD protocol dns-crypt ip 10.215.168.1 set service dns proxy static RD protocol dns-crypt port 8443 set service dns proxy static RD protocol dns-crypt provider name 2.dnscrypt-cert.remote.dns set service dns proxy static RD protocol dns-crypt provider public-key '30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2' set service dns resolver local set service dns static host-name teldat.com inet 10.11.12.13 set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DNSCrypt\) - rtt: \d+ms$Show output
Sep 17 00:36:33.400569 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:36:33.401839 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:36:33.402096 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:36:33.416638 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:36:33.763832 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:34.122321 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:34.248649 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:36:34.301859 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:34.423882 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:34.489799 osdx ubnt-cfgd[701267]: inactive Sep 17 00:36:34.514501 osdx INFO[701278]: FRR daemons did not change Sep 17 00:36:34.541784 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:34.591631 osdx WARNING[701349]: No supported link modes on interface eth0 Sep 17 00:36:34.593436 osdx modulelauncher[701349]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:34.593452 osdx modulelauncher[701349]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:34.594756 osdx modulelauncher[701349]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:36:34.594765 osdx modulelauncher[701349]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:36:34.797379 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:34.798549 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:34.825073 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:34.981810 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:36:35.053570 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:36.398887 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy dnscrypt public-key running://dnscrypt.crt'. Sep 17 00:36:36.541014 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:36.600772 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:36:36.694585 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:36:36.752610 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt ip 10.215.168.1'. Sep 17 00:36:36.853115 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt port 8443'. Sep 17 00:36:36.909127 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt provider name 2.dnscrypt-cert.remote.dns'. Sep 17 00:36:37.008373 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt provider public-key 30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2'. Sep 17 00:36:37.057797 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:36:37.155168 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert file running://dns.dut0.crt'. Sep 17 00:36:37.210566 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert key running://dns.dut0.key'. Sep 17 00:36:37.306521 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns static host-name teldat.com inet 10.11.12.13'. Sep 17 00:36:37.373984 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:37.464851 osdx ubnt-cfgd[701462]: inactive Sep 17 00:36:37.488274 osdx INFO[701471]: FRR daemons did not change Sep 17 00:36:37.501639 osdx ca-certificates[701487]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:38.103797 osdx ubnt-cfgd[702499]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:38.111754 osdx ca-certificates[702504]: 1 added, 0 removed; done. Sep 17 00:36:38.115505 osdx ca-certificates[702511]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:38.119256 osdx ca-certificates[702513]: done. Sep 17 00:36:38.242301 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:38.251764 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:38.252318 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:38.263100 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:38.263371 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Network connectivity detected Sep 17 00:36:38.263456 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Dropping privileges Sep 17 00:36:38.266063 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Network connectivity detected Sep 17 00:36:38.266127 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:38.266127 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:38.266127 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Now listening to https://[::]:3000/dns-query [DoH] Sep 17 00:36:38.266127 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Firefox workaround initialized Sep 17 00:36:38.266191 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Loading the set of cloaking rules from [/tmp/tmp9skg8n_1] Sep 17 00:36:38.271041 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:38.368901 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] [RD] OK (DNSCrypt) - rtt: 102ms Sep 17 00:36:38.368901 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] Server with the lowest initial latency: RD (rtt: 102ms) Sep 17 00:36:38.368901 osdx dnscrypt-proxy[702573]: [2026-09-17 00:36:38] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 4: Set the following configuration in DUT1 :
set interfaces ethernet eth0 address 10.215.168.65/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name DUT0 set service dns proxy static DUT0 protocol dns-over-https hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396 set service dns proxy static DUT0 protocol dns-over-https host name dns.dut0 set service dns proxy static DUT0 protocol dns-over-https host port 3000 set service dns proxy static DUT0 protocol dns-over-https ip 10.215.168.64 set service dns static host-name dns.dut0 inet 10.215.168.64 set service ssh set system certificate trust 'running://CA.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 5: Run the command system journal show | cat on DUT1 and check whether the output matches the following regular expressions:
(?m)^.*\[DUT0\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:36:33.408936 osdx systemd-journald[2055]: Runtime Journal (/run/log/journal/db82908865474f16bd4eb2f983136eff) is 952.0K, max 6.4M, 5.5M free. Sep 17 00:36:33.419917 osdx systemd-journald[2055]: Received client request to rotate journal, rotating. Sep 17 00:36:33.420003 osdx systemd-journald[2055]: Vacuuming done, freed 0B of archived journals from /run/log/journal/db82908865474f16bd4eb2f983136eff. Sep 17 00:36:33.429747 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:36:33.728184 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:35.128674 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:35.257383 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.65/24'. Sep 17 00:36:35.337763 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:35.423961 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service ssh'. Sep 17 00:36:35.539211 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:35.595268 osdx ubnt-cfgd[884515]: inactive Sep 17 00:36:35.674833 osdx INFO[884541]: FRR daemons did not change Sep 17 00:36:35.711475 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:35.763934 osdx WARNING[884612]: No supported link modes on interface eth0 Sep 17 00:36:35.765463 osdx modulelauncher[884612]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:35.765569 osdx modulelauncher[884612]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:35.766854 osdx modulelauncher[884612]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off -- Sep 17 00:36:35.766919 osdx modulelauncher[884612]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75. Sep 17 00:36:35.859965 osdx systemd[1]: Starting ssh.service - OpenBSD Secure Shell server... Sep 17 00:36:35.872710 osdx sshd[884673]: Server listening on 0.0.0.0 port 22. Sep 17 00:36:35.872734 osdx sshd[884673]: Server listening on :: port 22. Sep 17 00:36:35.872849 osdx systemd[1]: Started ssh.service - OpenBSD Secure Shell server. Sep 17 00:36:36.022711 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:36.023582 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:36.041781 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:36.186474 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'ping 10.215.168.64 count 1 size 56 timeout 1'. Sep 17 00:36:38.439151 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:38.495812 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns static host-name dns.dut0 inet 10.215.168.64'. Sep 17 00:36:38.588022 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set system certificate trust running://CA.crt'. Sep 17 00:36:38.646415 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy server-name DUT0'. Sep 17 00:36:38.751157 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https host name dns.dut0'. Sep 17 00:36:38.807017 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https host port 3000'. Sep 17 00:36:38.902924 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https ip 10.215.168.64'. Sep 17 00:36:38.958395 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 protocol dns-over-https hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396'. Sep 17 00:36:39.062238 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:39.128598 osdx ubnt-cfgd[884736]: inactive Sep 17 00:36:39.157838 osdx INFO[884745]: FRR daemons did not change Sep 17 00:36:39.171618 osdx ca-certificates[884761]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:39.794294 osdx ubnt-cfgd[885773]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:39.805900 osdx ca-certificates[885778]: 1 added, 0 removed; done. Sep 17 00:36:39.809907 osdx ca-certificates[885785]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:39.814255 osdx ca-certificates[885787]: done. Sep 17 00:36:39.938044 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:39.961905 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:39.962726 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:39.997448 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:40.113963 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:40.114326 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Network connectivity detected Sep 17 00:36:40.114326 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Dropping privileges Sep 17 00:36:40.117147 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Network connectivity detected Sep 17 00:36:40.117240 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:40.117240 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:40.117240 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Firefox workaround initialized Sep 17 00:36:40.117240 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpf32z2pf9] Sep 17 00:36:40.223814 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:40.445225 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] [DUT0] OK (DoH) - rtt: 118ms Sep 17 00:36:40.445225 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] Server with the lowest initial latency: DUT0 (rtt: 118ms) Sep 17 00:36:40.445225 osdx dnscrypt-proxy[885794]: [2026-09-17 00:36:40] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 6: Run the command show host lookup teldat.com type A on DUT1 and check whether the output contains the following tokens:
teldat.com has address 10.11.12.13Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 10.11.12.13
Server With Upstream DNSCrypt With Stamp
Description
Configures DUT0 to connect, using DNSCrypt over an upstream server (generating a DNS stamp and using it to configure the connection).
Scenario
Step 1: Run the command service dns proxy dnscrypt public-key running://dnscrypt.crt on DUT0 and expect the following output:
Show output
30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2
Step 2: Run the command service dns proxy stamp calculate dns-crypt provider-name 2.dnscrypt-cert.remote.dns provider-key 30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2 ip 10.215.168.1 port 8443 on DUT0 and expect the following output:
Show output
sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIDB5Vjz-HdxuM_wh0XMOPMh3SXasfjdA67N_s6xDxMSiGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z
Step 3: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server cert file 'running://dns.dut0.crt' set service dns proxy server cert key 'running://dns.dut0.key' set service dns proxy server-name RD set service dns proxy static RD stamp 'sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIDB5Vjz-HdxuM_wh0XMOPMh3SXasfjdA67N_s6xDxMSiGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z' set service dns resolver local set service dns static host-name teldat.com inet 10.11.12.13 set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 4: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[RD\] OK \(DNSCrypt\) - rtt: \d+ms$Show output
Sep 17 00:36:49.302245 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 17 00:36:49.303109 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 17 00:36:49.303169 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 17 00:36:49.314050 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:36:49.536513 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:49.777812 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:49.861959 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Sep 17 00:36:49.935033 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:49.995406 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:50.083455 osdx ubnt-cfgd[704346]: inactive Sep 17 00:36:50.107253 osdx INFO[704357]: FRR daemons did not change Sep 17 00:36:50.135036 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:50.181165 osdx WARNING[704428]: No supported link modes on interface eth0 Sep 17 00:36:50.182921 osdx modulelauncher[704428]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:50.182938 osdx modulelauncher[704428]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:50.184458 osdx modulelauncher[704428]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off -- Sep 17 00:36:50.184466 osdx modulelauncher[704428]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75. Sep 17 00:36:50.384150 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:50.384761 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:50.400249 osdx OSDxCLI[538347]: User 'admin' left the configuration menu. Sep 17 00:36:50.545972 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Sep 17 00:36:50.649726 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:52.140683 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy dnscrypt public-key running://dnscrypt.crt'. Sep 17 00:36:52.237829 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-crypt provider-name 2.dnscrypt-cert.remote.dns provider-key 30:79:56:3c:fe:1d:dc:6e:33:fc:21:d1:73:0e:3c:c8:77:49:76:ac:7e:37:40:eb:b3:7f:b3:ac:43:c4:c4:a2 ip 10.215.168.1 port 8443'. Sep 17 00:36:52.407964 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu. Sep 17 00:36:52.486808 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Sep 17 00:36:52.592186 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'. Sep 17 00:36:52.663385 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD stamp sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIDB5Vjz-HdxuM_wh0XMOPMh3SXasfjdA67N_s6xDxMSiGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z'. Sep 17 00:36:52.780388 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns resolver local'. Sep 17 00:36:52.846644 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert file running://dns.dut0.crt'. Sep 17 00:36:52.951553 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server cert key running://dns.dut0.key'. Sep 17 00:36:53.003160 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns static host-name teldat.com inet 10.11.12.13'. Sep 17 00:36:53.105149 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:53.171277 osdx ubnt-cfgd[704541]: inactive Sep 17 00:36:53.194790 osdx INFO[704550]: FRR daemons did not change Sep 17 00:36:53.206857 osdx ca-certificates[704566]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:53.743464 osdx ubnt-cfgd[705578]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:53.752225 osdx ca-certificates[705583]: 1 added, 0 removed; done. Sep 17 00:36:53.755443 osdx ca-certificates[705590]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:53.758560 osdx ca-certificates[705592]: done. Sep 17 00:36:53.895507 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:53.905120 osdx cfgd[1899]: [538347]Completed change to active configuration Sep 17 00:36:53.905688 osdx OSDxCLI[538347]: User 'admin' committed the configuration. Sep 17 00:36:53.918542 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:53.918739 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Network connectivity detected Sep 17 00:36:53.918889 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Dropping privileges Sep 17 00:36:53.921554 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Network connectivity detected Sep 17 00:36:53.921615 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:53.921615 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:53.921615 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Now listening to https://[::]:3000/dns-query [DoH] Sep 17 00:36:53.921615 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Firefox workaround initialized Sep 17 00:36:53.921615 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpj1k51pxp] Sep 17 00:36:53.922319 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] [RD] OK (DNSCrypt) - rtt: 0ms Sep 17 00:36:53.922385 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] Server with the lowest initial latency: RD (rtt: 0ms) Sep 17 00:36:53.922385 osdx dnscrypt-proxy[705651]: [2026-09-17 00:36:53] [NOTICE] dnscrypt-proxy is ready - live servers: 1 Sep 17 00:36:53.937605 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Step 5: Run the command service dns proxy stamp calculate dns-over-https host-name dns.dut0 host-path /dns-query host-port 3000 ip 10.215.168.64 hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396 on DUT1 and expect the following output:
Show output
sdns://AgAAAAAAAAAADTEwLjIxNS4xNjguNjQg8sHqN3uuN9GvZbMR70-wsXn6xdQvS-GB-UiWMD9As5YNZG5zLmR1dDA6MzAwMAovZG5zLXF1ZXJ5
Step 6: Set the following configuration in DUT1 :
set interfaces ethernet eth0 address 10.215.168.65/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name DUT0 set service dns proxy static DUT0 stamp 'sdns://AgAAAAAAAAAADTEwLjIxNS4xNjguNjQg8sHqN3uuN9GvZbMR70-wsXn6xdQvS-GB-UiWMD9As5YNZG5zLmR1dDA6MzAwMAovZG5zLXF1ZXJ5' set service dns static host-name dns.dut0 inet 10.215.168.64 set service ssh set system certificate trust 'running://CA.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 7: Run the command system journal show | cat on DUT1 and check whether the output matches the following regular expressions:
(?m)^.*\[DUT0\] OK \(DoH\) - rtt: \d+ms$Show output
Sep 17 00:36:49.280939 osdx systemd-journald[2055]: Runtime Journal (/run/log/journal/db82908865474f16bd4eb2f983136eff) is 832.0K, max 6.4M, 5.6M free. Sep 17 00:36:49.284065 osdx systemd-journald[2055]: Received client request to rotate journal, rotating. Sep 17 00:36:49.284128 osdx systemd-journald[2055]: Vacuuming done, freed 0B of archived journals from /run/log/journal/db82908865474f16bd4eb2f983136eff. Sep 17 00:36:49.293519 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal clear'. Sep 17 00:36:49.521612 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system coredump delete all'. Sep 17 00:36:50.759093 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:50.900319 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.65/24'. Sep 17 00:36:50.990258 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Sep 17 00:36:51.084872 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service ssh'. Sep 17 00:36:51.187425 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:51.260036 osdx ubnt-cfgd[887564]: inactive Sep 17 00:36:51.359657 osdx INFO[887590]: FRR daemons did not change Sep 17 00:36:51.392490 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Sep 17 00:36:51.445976 osdx WARNING[887661]: No supported link modes on interface eth0 Sep 17 00:36:51.448021 osdx modulelauncher[887661]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Sep 17 00:36:51.448129 osdx modulelauncher[887661]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Sep 17 00:36:51.449760 osdx modulelauncher[887661]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off -- Sep 17 00:36:51.449831 osdx modulelauncher[887661]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75. Sep 17 00:36:51.560446 osdx systemd[1]: Starting ssh.service - OpenBSD Secure Shell server... Sep 17 00:36:51.575783 osdx sshd[887722]: Server listening on 0.0.0.0 port 22. Sep 17 00:36:51.576021 osdx sshd[887722]: Server listening on :: port 22. Sep 17 00:36:51.576224 osdx systemd[1]: Started ssh.service - OpenBSD Secure Shell server. Sep 17 00:36:51.755151 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:51.764887 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:51.839545 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:51.957195 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'ping 10.215.168.64 count 1 size 56 timeout 1'. Sep 17 00:36:54.128428 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-over-https host-name dns.dut0 host-path /dns-query host-port 3000 ip 10.215.168.64 hash f2c1ea377bae37d1af65b311ef4fb0b179fac5d42f4be181f94896303f40b396'. Sep 17 00:36:54.265803 osdx OSDxCLI[844846]: User 'admin' entered the configuration menu. Sep 17 00:36:54.333123 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns static host-name dns.dut0 inet 10.215.168.64'. Sep 17 00:36:54.439960 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set system certificate trust running://CA.crt'. Sep 17 00:36:54.498283 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy server-name DUT0'. Sep 17 00:36:54.602287 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'set service dns proxy static DUT0 stamp sdns://AgAAAAAAAAAADTEwLjIxNS4xNjguNjQg8sHqN3uuN9GvZbMR70-wsXn6xdQvS-GB-UiWMD9As5YNZG5zLmR1dDA6MzAwMAovZG5zLXF1ZXJ5'. Sep 17 00:36:54.695129 osdx OSDxCLI[844846]: User 'admin' added a new cfg line: 'show working'. Sep 17 00:36:54.769890 osdx ubnt-cfgd[887785]: inactive Sep 17 00:36:54.791703 osdx INFO[887794]: FRR daemons did not change Sep 17 00:36:54.805096 osdx ca-certificates[887810]: Updating certificates in /etc/ssl/certs... Sep 17 00:36:55.378008 osdx ubnt-cfgd[888822]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Sep 17 00:36:55.387607 osdx ca-certificates[888828]: 1 added, 0 removed; done. Sep 17 00:36:55.390818 osdx ca-certificates[888834]: Running hooks in /etc/ca-certificates/update.d... Sep 17 00:36:55.393864 osdx ca-certificates[888836]: done. Sep 17 00:36:55.488743 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Sep 17 00:36:55.504746 osdx cfgd[1770]: [844846]Completed change to active configuration Sep 17 00:36:55.505800 osdx OSDxCLI[844846]: User 'admin' committed the configuration. Sep 17 00:36:55.536141 osdx OSDxCLI[844846]: User 'admin' left the configuration menu. Sep 17 00:36:55.718468 osdx OSDxCLI[844846]: User 'admin' executed a new command: 'system journal show | cat'. Sep 17 00:36:55.869151 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] dnscrypt-proxy 2.0.45 Sep 17 00:36:55.869548 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Network connectivity detected Sep 17 00:36:55.869832 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Dropping privileges Sep 17 00:36:55.872710 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Network connectivity detected Sep 17 00:36:55.872861 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Sep 17 00:36:55.872908 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Sep 17 00:36:55.872964 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Firefox workaround initialized Sep 17 00:36:55.873000 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:55] [NOTICE] Loading the set of cloaking rules from [/tmp/tmp3t7cqjfn] Sep 17 00:36:56.197878 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:56] [NOTICE] [DUT0] OK (DoH) - rtt: 123ms Sep 17 00:36:56.197878 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:56] [NOTICE] Server with the lowest initial latency: DUT0 (rtt: 123ms) Sep 17 00:36:56.197878 osdx dnscrypt-proxy[888843]: [2026-09-17 00:36:56] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Step 8: Run the command show host lookup teldat.com type A on DUT1 and check whether the output contains the following tokens:
teldat.com has address 10.11.12.13Show output
;; communications error to ::1#53: connection refused ;; communications error to ::1#53: connection refused teldat.com has address 10.11.12.13