One thing to consider though is becoming a dns resolver for any random thing on the net. What I did for this was create a bash script that adds the visiting ip to iptables whitelist. Created an impossible-to-guess php page (pi admin uses php so it’s already installed and ready to go) which takes the REMOTE_ADDR and passes it to the bash script to add to iptables. Makes it super easy to allow ip’s when isp changes address or when visiting family/friends and they want to use it.
DNS Amplification Attacks: https://www.us-cert.gov/ncas/alerts/TA13-088A
> A Domain Name Server (DNS) amplification attack is a popular form of distributed denial of service (DDoS) that relies on the use of publically accessible open DNS servers to overwhelm a victim system with DNS response traffic.
DNS queries are much smaller then DNS responses. Making a huge amount of queries uses less bandwidth then uses to respond - making it a prime candidate for DDOS attacks. Look at your logs, no doubt you will see a large number of requests for various hosts. This is your system being used to attack people. Please close the port.
I hesitate to mention this, as it causes heads to explode, but the problem you're describing is nicely solved with port-knocking. Might be easier than setting up the php page, etc. ...
Edit: found this guide https://www.inmotionhosting.com/support/website/ssh/how-to-u...
Looks like I could just create some bookmarks for the ports and open them sequentially.
I think overall this is a much better solution than messing with php/bash - good idea and thanks!
The gist is, on the client configuration:
1. Set DNS server IP against allowed IP in the peer (which is your wireguard server) section.
2. Set DNS entry to the same IP as above for the client interface.
Ref the discussion and the linked blog post (that talks abt Pi-Hole with wireguard): https://news.ycombinator.com/item?id=19544532, https://www.reddit.com/r/WireGuard/comments/bqccdz/split_tun...
DNS = <public-resolver>,<private-reslover>
...wouldn't work?
Edit: per discussion on r/Wireguard, looks like one soln is to run dnsmasq locally on ::53 and forward public queries to the VPN/DNS provider of your choosing and resolve private queries locally.
https://www.reddit.com/r/WireGuard/comments/cmhap6/use_both_...
Android 9 has support for custom private DNS servers so I just point it to my home IP and works great, no adverts when I'm out of the house.