There are many DNS names options. Which one do you use?
.home.lan for me.
I bought a .com for like $10 CAD from Cloudflare that uses a URL not linked to me.
Maybe overly paranoid, but it also makes it easy to get SSL certificates for my lab.
nothing as home does work (meaning plain hostname) works by default on openwrt dns
While this works for most things, you will run into issues with certain software which automatically assume that no TLD means the provided address is incorrect.
Usually adding a slash at the end works if the protocol is http based
According to IETF, you should only use
.intranet
,.internal
,.private
,.corp
,.home
or.lan
for your private network ( RFC 6762 Appendix G ). Using other TLDs might cause issues in the future, especially since new gTLDs seems to show up every few months or so, which can collide with the TLD you use for your local network.The one reserved for residential usage is
home.arpa
.Interesting, so this is the latest recommendation? Which is probably why I haven’t seen it in the wild yet, at least in my circles.
Which means they probably going to
cash outrelease gTLDs for.intranet
,.internal
,.private
,.corp
,.home
and.lan
soon…
@redcalcium
Really? Not .local? Why is it the default on so much?
@zephyr@dpflug @redcalcium @zephyr it is reserved for mDNS.
@sifrmoja
Ah, yep. Now that you say it. Thanks for cluing me in.
@redcalcium @zephyr
A long time ago Microsoft and some teaching sources used .local in example documentation for local domains and it stuck. Like contoso.com was Microsoft’s example company. I was taught to use .local decades ago and it took a very long time to unlearn it.
A problem with the
.lan
TLD (maybe others from this list) is that web browsers do not consider it a TLD when you type it in the address bar, and only show you the option to search for that term in your default search engine. You have to explicitly typehttps://
before it, to have the option to visit the URL.E.g type
example.com
in the address bar -> pressing Enter triggers going tohttps://example.com
. Typeexample.lan
-> pressing Enter triggers a search forexample.lan
using your default search engine.Little known trick–or perhaps everyone knows it and is quietly laughing behind my back–with Chromium browsers and Firefox (and maybe Safari, I’m not sure), you can add a slash to the end of an address and it will bypass the search.
So, for example, my router on the LAN goes by the hostname “pfsense”. I can then type pfsense.lan/ into my address bar and it will bring me to the web UI, no HTTP/s needed.
You can throw a
/
after to force it to recognize as a URL too.
I can vouch for the fact that .local stopped working suddenly in most browsers a year or two ago, I was forced to migrate to .internal
hostname.vlan.local.lan
local.lan is the only fixed part of my fqdn’s
server.home for my part
I use a subdomain of a domain name I own.
i use my external zone name but have an internal view of the zone inside my lan so records point to local ips.
Exactly the same. I’d like to add that my devices still get a .lan TLD from the router.
Do you use NAT reflection to avoid issues with mobile devices caching the external IP address?
yep
Ah that’s a really good point. I will have to Google this so I can learn how it is done in iptables because I’ve only ever done it with pf on OpenBSD.
I’ve never experienced any issues so far, the devices should be flushing the cache on network change in theory.
Same here. I have several domains, one is used for servers and email, 2nd for websites, 3rd for messing around (test setups) and a 4th is almost unused now, but with the demise of twitter and reddit I’m thinking of using that one for the fediverse (it’s my username in national tld).
BTW internal and external dns run on different systems and all private zones are dnssec signed. (Loved the challenge on setting that up correctly)
I use subdomains, i.<external domain>, w.<ext> for wifi, few others for vms and containers.
With wireguard everything just works, and wireguard overhead over wireless is negligible even on wifi6.
I agree on WireGuard. It’s clearly the winner in terms of speed for point to point VPN.
Same, I achieve this with Adguard DNS rewrite.
Split Horizon DNS is the most seamless user experience.
I use .lan for everything the router can resolve names for, and .local for Avahi mDNS 😈
my server is just
server
Idk is that wrong but I made up server name tride so .tride is my local domain
I tend to use .local
That will work fine so long as you don’t need services like Avahi and mDNS.
There actually is a correct awnser: home.arpa
See https://www.ctrl.blog/entry/homenet-domain-name.htmlYou shouldn’t use .local for your manually defined local domain names if you plan to ever use mdns/avahi/bonjour/zeroconf.
I actually use .lan for an internal domain but I guess I could use a real domain with the DNS-01 challenge and have real internal certificates. I had not thought about that until just now.
And
.box
has been registered as a generic TLD now, so you could run into external .box domains.Hopefully AVM gets to register
fritz.box
then, because they’ve been setting up their customers with that as their internal domain for ages…
I just bought an actual domain and use that 😅
As an added bonus, letsencrypt works with no effort.
Same here. Well worth it for $10 a year
I bought domain from joker.com, 10 years for $33
What? How they sell for so long?
I don’t know but they do. I picked the cheapest name I could find and went with it.
Checked and they still do sell domains for 10y but price has gone up.
same. saved my ass already a few times when doing some reverseengineering voodoo. being able to set a valid https cert makes it easier to redirect apps than to bypass forced HTTPS. had to pretend to be a update server for something once and patching the URL was enough via getting a cert quickly (using DNS-01 challenge, no exposed ports ever)