Draytek
Overview
If you have not yet registered for the service, you can do so by visiting our registration page. Connect to the control panel by entering the IP address of the Draytek device in the address bar of any browser. Then, log in by entering your administrative credentials.
Configure Dynamic DNS Service
To configure the Dynamic DNS service, open the Applications menu and then click on Dynamic DNS. Check the Enable Dynamic DNS Account option and fill in the various fields exactly as follows:
- Service Provider: Choose Customized or User-Defined.
- Provider Host: Enter https://ddns.fsflt.com.
- Service API: Type /nic/update?.
- Auth Type: Choose basic.
- Connection Type: Select Https.
- Server Response: Leave this field completely blank.
- Login Name: Enter the specific username assigned to your dynamic network inside our dashboard. Do not use your main registration email.
- Password: Enter the specific password assigned to your dynamic network.
- Determine Real WAN IP: Select WAN IP.
Finally, click OK to make the changes active.
Enable the DHCP Server
At this point, you can enable the DHCP Server so that it automatically assigns network parameters, including our filtered DNS, to the various internal devices.
Open the LAN menu and click on General Setup. Click on the Details Page button for your LAN and enable the Enable Server item to activate the DHCP service. Then configure it as follows:
- Start IP Address: Enter the first private IP in your local range.
- IP Pool Counts: Set the number of IPs to be handled by the DHCP service.
- Gateway IP Address: Enter the IP address of your gateway, which is usually the local IP of your router.
- Lease Time: Leave the default value of 86400 or enter your desired duration.
- Primary IP Address: Enter 185.236.104.104.
- Secondary IP Address: Type 185.236.105.105.
Alternatively, the DNS settings of the various devices within the network can be changed manually one by one.
Optional: Deny DNS Changes by Users
It is possible to increase security by denying users the ability to browse unfiltered by manually changing the DNS on their local devices.
Open the Firewall menu and click on Filter Setup. At this point, you need to create rules to allow traffic on port 53 for the DNS Service on both TCP and UDP protocols only to our specific cloud IPs.
Click on the first available number under the Set column, and then on the 1 button under the Filter Rule column to create a new rule. Enable it by selecting Check to enable the Filter Rule and configure it as follows:
Rule A: Allow Primary DNS
- Direction: Choose LAN/RT/VPN to WAN.
- Source IP: Leave Any.
- Destination IP: Click Edit, select Single Address and enter 185.236.104.104.
- Service Type: Click Edit, choose User defined with TCP and UDP protocol, and enter the value 53 in the Source and Destination Port fields. Click OK to save.
- Filter: Choose Pass Immediately from the drop-down menu.
Click OK to save and apply the changes.
Rule B: Allow Secondary DNS
Now we need to create another rule exactly similar to the previous one, except for the IP address of the Destination IP field, which should be 185.236.105.105.
Rule C: Block All Other DNS
Finally, it is necessary to create a drop rule to block all DNS traffic directed to external IPs other than our own. Proceed as follows:
- Direction: Choose LAN/RT/VPN to WAN.
- Source IP: Leave Any.
- Destination IP: Leave Any.
- Service Type: Click Edit, choose User defined with TCP and UDP protocol, and enter the value 53 in the Source and Destination Port fields. Click OK to save.
- Filter: Choose Block Immediately.
Finally, click OK to create the rule.