Ted Lemon wrote:
that would be low fidelity. i need to run clients whose internet
experience will not be influenced by middleboxes.

I'm having trouble figuring out where a middlebox would be here that
would reduce fidelity. Isn't the point of what you're doing to
completely bypass any middleboxes that are in the way?

I think the diagram looks like this:

LAPTOP<----link a---->DNS-over-https-proxy<---link b--->Full Service
Resolver<---internet--->Authoritative servers

Where is the middlebox that's going to reduce fidelity?

you've cut too much context. my answer was to "just truncate". your followup is about "which middlebox."

P Vixie

