(SOLVED) DNS Rebind protection enabled error (lost GUI - Vigor 2960)


Recommended Posts

I had a router hardware failure and so had to instal a new one. Now when i try to log into unraid by ip address it redirects to https but fails.

 

I guess it's to do with lets encrypt built into unraid as i can connect to everything else. I tried clearing out my web browser cache, but will i need to reboot the server?

Edited by Ockingshay
solved
Link to comment

First go to   Settings   >>>  Identification     

 

Click on the 'Help' icon.  Now look for the "Use SSL/TLS:" parameter and read the help text to see if any of that applies to the router/software that you have.  

 

IF that doesn't help, you can read through this thread particularity around the post that it points to.  

 

       https://forums.unraid.net/topic/61265-what-router-are-you-running/?page=3&tab=comments#comment-637221

 

 

EDIT:  You can also use google to find if anyone has solved your problem on Unraid if you include   unraid   and your router name and model number as search parameters.  

Edited by Frank1940
Link to comment

thank you for your reply. 

 

I had to reboot the server into GUI mode so that i could turn off "use SSL/TLS"

I can now connect to the webgui on a network computer's browser

I then deleted the certificates on my flash drive under /ssl/certs/

I then set "use SSL/TLS" to "auto"

I then attempted to provision a new certificate where upon i receive the "DNS rebinding enabled" error message.

I have tried to google Vigor 2960 <--- my new router/3900 (or it would seem as they share the same webgui and all their documents reference 3900) disable dns rebinding but it doesn't give me anything helpful.

 

Does anyone have any experience with these routers 2900/3900 and would know how to disable the dns rebinding protection? This is also going to affect my plex server.

 

many thanks

Link to comment

The Vigor seems to a industrial strength router and it quite expensive.  So I assume that, in most cases, it would be administered by an IT professional.  (I am not one!)  I would be checking to see if they have a user's group and forum where you can ask about allowing DNS rebinding to a specific site.  I know that the Ubiquiti group has a lot of very knowledgeable people willing to help out.  

 

You might also consider changing your DNS provider as one source of DNS rebinding protection could be your ISP DNS server.   Make sure that you are running the firmware on your router as evidently your Vigor had a security issue with this.  

 

You might also change the subject of this thread to better identify what info you need.  You can do this by editing your first post.  

 

When you find a solution, be sure to update this thread to reflect what it is.  

Link to comment

The certificate created fine when i was using my Asus 87 router, so i don't believe that my ISP (plusnet) is providing any DNS rebinding protection. The DNS servers are to to automatically acquire from my ISP (same as my old router)

 

I have raised a ticket with draytek technical support, so hopefully they should be able to assist.

 

incidentally my son is not able to connect the companion app to red dead redemption 2 since moving to this new router. That connects and authenticates to rockstar's servers on app and ps4 and they can see each other but the handshake fails. Could be related...

 

i'll let you know what draytek say.

Link to comment

Ok, for the sake of completion and sharing the solution for others with draytek routers (Vigor3900, Vigor2960 and Vigor300B), this is what you have to do. Draytek call it LAN DNS and they have an article here that describes the process: https://www.draytek.com/en/faq/faq-connectivity/connectivity.lan/how-to-use-lan-dns-on-vigor3900/

 

Specifically for unraid you will need to use "Type - IP", where ip equals the local address of your server (in my case 192.168.0.5) and "Domain - xxxxxxxxxxxxxxxxx.unraid.net" where xxx is the string that unraid tries to provision. (unraid will give you this is the error message)

Edited by Ockingshay
slight tweak
Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.