Running my own DoH relay and getting Pi-hole protection away from home
scotthelme.co.uk
scotthelme.co.uk
The one thing I need to find a solution for, however... a Raspberry Pi is not quite powerful enough to handle a gigabit connection. I need to look into a more powerful device to replace it with. That would also mean I can add that RPi to my miniature cluster.
To clarify, you're referring pretty much exclusively to the PiVPN part here, correct? I have a 3B doing lots of other things and it's serving Pi-Hole duty as well w/o a hitch.
That said, the Android private dns feature is incredibly simple to use, applies to VPNs, and is the best implementation I've seen.
Currently I use it with NextDns, and this post makes me wonder if a TLS to DNS module for nginx, or some proxy, exists...
One of the things any of these approaches will need is a mechanism to get trustworthy certificates†. But since you're a DNS server I think it likely makes sense to do DNS proof of control (so dns-01 under Let's Encrypt or another ACME service) rather than spin up other services.
† If you don't have this, your resolver clients can't be sure it's you they're talking to, if you don't care about that then you didn't need DNS privacy anyway.
You can get certificates for IP addresses, eg. https://1.1.1.1/
(I have run DoH and DoT in production since 2018, using OpenResty, i.e. nginx plus LuaJIT, with the DoH protocol conversion written by me in Lua, and DoT using basic nginx as described in TFA.)
I wished both were supported at the OS level.
What is it that makes it infeasible to accomplish DIY DNS-based blocking on an OpenWRT router, without the need for an RPi. It makes me wonder if the modified dnsmasq Pi-Hole uses requires more resources that the un-modified version one normally finds on OpenWRT routers.
With respect to what this person is trying to accomplish, third party VPN is OK, but is it really necessary if one has a publicly reachable IP at home. OpenWRT routers often come with Wireguard pre-configured, and if not it can usually be installed no problem.
(Of course you could run OpenWRT on the RPi but is this a popular choice, given the specs of the earlier models.)
For experimenting with DoH at home, I am using dnsdist from PowerDNS.
1. For examlpe, users who prefer to run their own OpenWRT router at home, either in place of or in addition to one provided by an ISP.
Setting up a 30 EUR pi with pi-hole is way easier and probably cheaper than getting another router and configure it for a lot of people.
Otherwise you'll need to set up a firewall rule to redirect all DNS requests.
https://openwrt.org/docs/guide-user/firewall/fw3_configurati...
According to a sibling commenter, that alternative is also possible through Pi-Hole, although it looks like you need to configure a router to rewrite said traffic to point at it. (potentially also requiring the purchase of a $250 piece of additional hardware, at which point, why not just buy a router that supports OpenWRT?)
Yeah I've got a pihole and an openwrt router (Nanopi R4S is amazing bang per buck btw) configured to point to the pihole.
Yet some stuff is leaking past it (mainly iphone) hence my interest in forcing things. I suspect its connected to the fact that ipv6 resolves faster than ipv4 for me somehow but can't quite place what's wrong...because it is catching some ipv6 traffic so its not like the ipv6 pihole is broken broken.
>Otherwise you'll need to set up a firewall rule to redirect all DNS requests.
Yes...the whole chain concept openwrt has going is something I haven't wrapped my head around yet so no rule writing for now
The advantage is the router itself is literally routing all the traffic and thus even hostile clients (e.g. smart tv) that ignore the (dhcp provided) pihole DNS still have to pass their traffic through the router and thus it always has an opportunity to take action on the packets.
As was mentioned in a sibling comment, even with just a pihole and a non-openwrt router you can still configure your network to force all DNS traffic through the pihole but it is more config and more error prone vs the single openwrt router network.
i am sure that this is all possible using some slick openWRT command line/LUA magic/plugins/god knows what, but my time isn't free, and i'm not interested in hacking that all together on the same device that provides internet access.
Are there any other common tricks to use settings profiles instead of apps on iOS?
(I worked on apple MDM products for 4 years)