blocked (by FRITZBOX DoT)

Hi all,
I'm using openwrt in the latest version with update.
The internet works fine.
But some websites are blocked.
For example,
The settings in the firewall are default.
What can I do?

PING ( 1472(1500) bytes of data.
Von ( icmp_seq=1 Frag needed and DF set (mtu = 1492)
ping: lokaler Fehler: Nachricht zu lang, MTU=1492

PING ( 1462(1490) bytes of data.
1470 Bytes von ( icmp_seq=1 ttl=59 Zeit=17.9 ms

PING ( 1452(1480) bytes of data.
1460 Bytes von ( icmp_seq=1 ttl=59 Zeit=17.8 ms Status

Is down right now?###

### It's just you. is up.

The whole point of pinging is to find which size gets a reply, when the +1 is dropped. In your case 1472 doesn't work and 1462 works, so try 1468. If it works go up one byte, if it doesn't go down one byte.

Just to be clear, the required MTU size should be documented by your ISP, so 'guessing' and approximating the correct setting shouldn't be necessary. MSS clamping also needs to be enabled (it is by default).


I found the cause. I turned on the FRITZBOX DoT.
When I turn off DoT, everything works normally.
Thank you and greetings


DoT is "encrypted DNS" and uses a different DNS than the one provided by the ISP (because the DNS provider must support encryption), if you can't reach sites with DoT on and you still want to use that feature, you probably need to change the DNS in the DoT options to a different provider.


In fact, DoT usually works well enough, while DNSSEC is known to have performance and other issues.

