There is no need for cisco stuff. dnscrypt-proxy+dnsmasq, for example, to be used + one of the many open dnscrypt servers form this list: https://github.com/jedisct1/dnscrypt-proxy/blob/master/dnscrypt-resolvers.csv In principle, run dnsmasq on your squid box, and use dnscrypt-proxy to connect dnsmasq to upstream open dnscrypt-enabled dns-server fom list above. Make sure, squid uses this local dnsmasq as dns server. Finally, use iptables to redirect all dns-requsts from clients to your dnsmasq. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Force-DNS-queries-over-TCP-tp4678324p4678343.html Sent from the Squid - Users mailing list archive at Nabble.com. _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users