cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
237
Views
0
Helpful
10
Replies

OpenDNS not working on Netgear router

mworthen1
Level 1
Level 1

Hi all,

I have a Netgear router (a newer AC model - it is about a year old) and want to use OpenDNS.  I made sure the firmware was up-to-date on the router (it needed an update) and then setup the alternate DNS sites and said to use those sites rather than the default.  No go.  It doesn't seem to work.  Have rebooted both the router (twice) and the computer (multiple times).

The router came with Parental Control so I thought I would use that.  However, it also uses OpenDNS but the Netgear program asks me to log into OpenDNS but then fails telling me the name or password is unrecognized.  However, I can use the same user/pw combo and log into OpenDNS directly just fine.

Two approaches to the same issue but can't seem to get it working.

Any thoughts or ideas would be much appreciated.

Not at home now so can't provide details but can later if needed in regard to router model, firmware, etc.

Thank you.

 Mark.

10 Replies 10

rotblitz
Level 6
Level 6

You cannot use Netgear LPC and OpenDNS Home at the same time, because these are incompatible.  Use either the one or the other.

"Have rebooted both the router (twice) and the computer (multiple times)."

If something doesn't work once, repeating it doesn't work either.  That's normal in life.

To help you further, I need to see the complete plain text outputs of these diagnostic commands:

nslookup -type=txt debug.opendns.com. 208.67.222.222
nslookup -type=txt which.opendns.com.
nslookup whoami.akamai.net.

 

mworthen1
Level 1
Level 1

Thank you.  I tried OpenDNS originally and when I couldn't get it working, thought I would try LPC.  Would rather just use OpenDNS.  I don't think LPC is turned on as it wouldn't get past the OpenDNS sign-on.

Perhaps I am using the wrong OpenDNS addresses?  I had 208.67.220.123 & 208.67.222.123.  

rotblitz
Level 6
Level 6

These addresses are the so called FamilyShield addresses where "adult" categories and the Proxy/Anonymizer category are being blocked by default.  These addresses are not really "wrong" but may not be what you want.

Regardless, as long as I don't see the diagnostic outputs, I can't tell you why OpenDNS doesn't work for you.

mworthen1
Level 1
Level 1

First command:

Server: resolver1.opendns.com

Address: 208.67.222.222

Non-authoritative answer:

debug.opendns.com  text = "server m11.sea"

debug.opendns.com  text = "flags 20 0 70 79508000000000000000"

debug.opendns.com  text = "originid 0"

debug.opendns.com  text = "actype 0"

debug.opendns.com  text = "source 96.18.171.89:64557"

 

Second command:

Server: google-public-dns-a.google.com

Address: 8.8.8.8

Non-authoritative answer:

which.opendns.com  text = "I am not an OpenDNS resolver."

 

Third command:

Server: google-public-dns-a.google.com

Address: 8.8.8.8

Non-authoritative answer:

Name: whoami.akamai.net

Address: 74.125.80.77

 

Thank you.

 

rotblitz
Level 6
Level 6

For sure, you do not use OpenDNS!  It seems you wanna make fools of us. ;-)

Server: google-public-dns-a.google.com
Address: 8.8.8.8

"I am not an OpenDNS resolver."

You have Google DNS configured on your computer.  Change this to obtain the DNS server addresses automatically via DHCP.

If you configured things correctly, you could use OpenDNS, their data center in Seattle.

If you want to use OpenDNS Home, you had to configure the OpenDNS resolver addresses on the router and to create a network at https://dashboard.opendns.com/settings/ with your IP address 96.18.171.89 registered, and keeping LPC on the router disabled.  Also run an Updater.

If you want to use Netgear LPC, enable this on the router, do not configure OpenDNS resolver addresses on the router, delete any network at https://dashboard.opendns.com/settings/ and do not run an Updater.
Your LPC dashboard is only at https://netgear.opendns.com/

Do not use OpenDNS Home and Netgear LPC at the same time.  These services are incompatible!

mworthen1
Level 1
Level 1

Thank you.  I was trying to set it up on the router so that any device connected to the network is automatically filtered (read, teenagers).

I'll follow these instructions, probably tomorrow as I have no availability tonight.

Thank you.

rotblitz
Level 6
Level 6

Yes, configuring on the router is fine to cover all connected devices, but only if these devices are configured to obtain the DNS server network settings automatically via DHCP from the router, or if you configure the router's IP address as DNS server on the devices.  If you overwrite this by configuring a different DNS service like Google DNS on the end user devices, then this will take priority, or DNS is generally broken, i.e. looking like no internet connection at all, depending on what service you will be using.

If you want to prevent users from changing their network settings to use another DNS service:

  • Regular (non-admin) users cannot change these network settings on computers (Windows, Mac OSX, Linux).  And iOS devices can be restricted from dedicated changes like this.
  • For OpenDNS Home: Configure an outbound firewall rule to block port 53 (TCP+UDP) passthrough, or to redirect all DNS traffic (port 53) to OpenDNS.  (The latter is likely not possible with your router model.)
  • For Netgear LPC: LPC blocks use of alternative DNS services by itself.  No additional measure should be needed.

mworthen1
Level 1
Level 1

Forgive my ignorance, but how do I configure the outbound firewall rule?  When I'm in the Netgear Genie, it says I have an R6400 router.

Thank you.

rotblitz
Level 6
Level 6

Does your question indicate that you want to go for OpenDNS Home?  Fine.

Also, did you expect to find Netgear router experts in the OpenDNS forum?  Too optimistic!  I would have to look for the related user manual and work through it to find out if setting up firewall rules is documented and how - or even not.

Did you expect me to do this work for your?  I will do it, no doubt, if you take over my tasks for the time being.  This requires to forgive even more ignorance, because my tasks appear to be much more complex and difficult than firewall rules on a Netgear router.  Or do you prefer to contact the Netgear router nerds at https://community.netgear.com/t5/WiFi-Routers/ct-p/home-wifi-routers maybe?

mworthen1
Level 1
Level 1

Sorry, I hadn't thought that through.  I'll check the router group.