Please, don't be so cryptic in your comments. The long quotations of the org post are also a bit annoying, but anyway: As you obviously do not understand the principle, how it works _without_ cisco, lemme explain: (assuming, all traffic from users is routed via squid box) - iptables rules (redirect port 53) make shure, all clients only use _local_dnsmasq for DNS. - Squid also uses only _local_ dnsmasq - local dnsmasq uses upstream DNS _only_ via dnscrpyt_proxy. - dnsmasq-proxy is configured to access one of the dns-crypt-enabled DNS servers. cisco is just one of them. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Force-DNS-queries-over-TCP-tp4678324p4678350.html Sent from the Squid - Users mailing list archive at Nabble.com. _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users