An extensive tutorial on how to setup a Pi-Hole
crosstalksolutions.com
crosstalksolutions.com
AdGuardHome is far better than PiHole. It's a single Go binary and I think UI is better. It won't break if you upgrade your system. You don't need docker or LAMP stack. Just pull binary and run it. It will even generate systemd service file for you if you need.
It's almost like there's a lot of needless overhead in modern software or something.
I do have proxmox at home already, so spinning up a container for PiHole and pivpn was super easy. But it looks like AGH supports certain features PiHole does not.
Now I'm running AdGuardHome on an EdgeRouter-POE, very slick install via script!
Happy to move on from constantly handholding Pi-Hole. I had to move it from a Raspberry Pi to an Intel NUC earlier, since the raspi SD-card had crapped out.
Yay for efficient programming!
Edit: Also great to see that AGH has secure DNS built in. My Pi-Hole solution required cloudflared [0] for that.
Also, I'm cool with a paid product, but it looks like this one is open source? I know they have paid products, but I can't figure out if it relates to this at all?
I set it and forgot it, until I went to Estes Park, Colorado over the Christmas holidays one year. I travelled with my MacBook just in case anything popped off... and it did. I logged into my MacBook, but quickly realised although I could connect to WiFi as normal, no DNS would resolve (it was pointed to 192.168.1.100 of my home network), and I couldn't connect to anything - including logging in the Self Service app to re-issue sudo access, to change the DNS. I had to walk a new colleague how to handle the scandal over the phone, driving through the mountains... thank goodness for good cell service!
Best way to handle it is to just reconfigure your router to hand out the pihole dns server to all the clients on your network. That way it's automatic when at home, and doesn't override anything when you're away.
You can configure the default DNS for devices when they connect to tailscale. This way, pi hole is opt in for users who want to set up tailscale.
Disclaimer: I haven't tried this myself since I have Mullvad ad blocking setup and I'm lazy
But as others mention tailscale also works
Another hack to consider is running pi-hole in a VM or container on the laptop itself, and have it act as a filtering cache for a more public resolver. Though this imparts an administrative load, you no longer have a single pi-hole so either need to configure it separately or arrange for it to be able to sync with config on your main instance.
Both these arrangements will have trouble if you find yourself on a network that blocks DNS requests to anything other than its local resolvers (though for the pi-hole-on-laptop you can always reconfigure pi-hole to look at the local resolvers if/when needed), so the VPN option is better where available. If you have no static IP at your base of operations, there is always the option of a cheap VPS somewhere to be the VPN endpoint – essentially my first paragraph but your “port knocking” is connecting to the VPN, with pi-hole either on that machine or a machine also connected to the same VPN to get around its lack of fixed public address. Though back to the adversarial local network problem: if the network blocks DNS queries to non-local resolvers it is not unlikely to try block VPNs too.
That way when you're home, you get the pi-hole, but when on the road, you get whatever DNS is given for the network you're connected to.
All machines on your local net now use the pihole as dns as handed out by the router, and when you roam tailscale routes your dns to your pihole.
If you're travelling overseas though, it makes sense to reconfigure tailscale to use NextDNS directly so its faster.
Using NextDNS allows you to use encrypted DNS upstream (supported out the box with AdGuardHome, unlike pi-hole), meaning your ISP can’t as easily snoop on you. Of course, they still may be monitoring the hosts you connect to and the non-encrypted SNI requests, but that’s a lot more effort and most of the major US ISPs don’t do that at scale. DNS snooping does almost as well and is way easier.
Otherwise, as the parent poster realized, moving the device to another network will require manual changes. And then changes again when you get back.
I'm just not able to configure custom upstream in pi-hole (ie Unbound or NetDNS). Probably some firewall rule or anything related to setting of container to work with pihole.
On the trusted VLAN I use Technitium as DNS and DHCP. I don't use any block lists, though, because I had too many complains from other network users. Technitium is mostly just because it's easy to manage DHCP hostnames and other DNS records in the same UI.
Files don't leave my work laptop. If I need to get files into my work laptop (very rarely, usually slack emojis) I email them to my work account or share a Google Drive folder with my work account. These methods are traceable and auditable for my company and, importantly, don't open any of my personal accounts to legal discovery from the company's side as far as I can tell.
Also, FWIW, I'm assuming this hypothetical software is clever enough to only function in jurisdictions where that would be legal? Spying on your employees home network is a massive no-no here, you'd need some very deep pockets if you wanted to attempt it, because when you are found out you'll be paying a lot of compensation for privacy violations.
I'm not a security professional so take this with a grain of salt but, if I were going to do this I would be listening for things that could conceivably be trying to pop equipment in employee possession. So malicious mDNS advertisements, nmap scans, that kind of thing.
You would have a very difficult time even proving that they did it unless they told you that it happened or if you were the kind of person whom, bordering on certifiable paranoia, kept logs of all of your home internet traffic.
Even then, the only thing you could do would be to sue the company, a very expensive process with no guarantee of success and that would take years to see any small measure of justice. They would only be liable for the damages you suffered as a result of their theoretically justifiable intrusion into your home network unless they tampered with your systems or downloaded files from your other computers, in which case you may have a criminal complaint against your company, but even with the Federal laws (like 18 U.S.C. § 1030 federal computer hacking) you not only have to prove that they accessed your personal computers without your permission but also that they did so with the "intent to cause harm".
If they did this and then fired you because of what they found, then you might have the slimmest of chances with a good lawyer to both federally prosecute the company and also sue for damages, but you first have to keep a flawless and undebatable log of all network activity on your personal network, bring a work computer to your home, join it to your network, and have someone acting in an official capacity from the company (because some rogue I.T. guy poking around doesn't represent the company and would thus be personally liable for the damages, absolving the company of any guilt) use that computer to access your personal network, snoop around, and download your personal files or data AND cause you some verifiable injury for what was found.
To say that is a tall order is such an understatement it's like saying Mar's Mons Olympus is a pretty big pile of dirt.
1. Using tcpdump passively to collect multicast, broadcast, etc with, for example, information such as identity information and in some cases what you're watching on your streaming box. This isn't always encrypted.
2. Using tools to sniff Bluetooth and Wi-Fi information. macOS and Windows includes such tools by default.
Sorry, I am being deliberately vague on purpose.
I know you can accomplish the same thing with Unifi access points and security gateway and of course Ruckus, Cisco, Aruba, etc will as well. I don't know of any residential equipment that will but I haven't used residential Wi-Fi gear for almost a decade.
The setup is:
- traffic on a particular SSID gets tagged with a VLAN at the AP
- That VLAN is tagged on all of the switch ports between the AP and the router
- the router's firewall is configured to block the guest subnet from the other local subnets and allow internet egress
Using NextDNS you are getting the same capability served by a global anycasted network of resolvers and it can work even on your phone while away from home (because the mobile web is even more gross).
The benefits outweigh the downsides, and at least in North America the performance is good.
https://github.com/pi-hole/docker-pi-hole/blob/62ca934d07/ex...
Do they have any “tools” to temporarily allow some blocked content from a device? Or does one have to go to web and adjust the profile?
I don't use Windows at home, but I imagine there is a similar toggle.
Additionally, my Pi-Hole would frequently (at least once a month) require reboots and troubleshooting. That's the last thing I want to do (with family (im)patiently waiting) after working all day.
I have my traffic going to Pi-Hole, which forwards it to a stubby instance, which encrypts it and forwards it to NextDNS. When I'm out then my phone just sends it straight to NextDNS
Laptops basically have a UPS built-in.
Doesn't the Pi 3 expect up to 2.5 amps? I imagine some of that is for powering USB ports, so you could probably get away with 1.5 amps if you're not using them, but even that's a lot for laptop USB. I'd be surprised if any offered more than 1 amp.
However, cheap is not how I would have described it ;-)
I did some research into this as well and I'd gladly consider this as an option but most power banks can't do this. And the ones that do don't tend to advertise it. Every time someone says they found one that can do this, in some forum or whatever, they are no longer available to buy.
Every time I need another containerized app to run I'm up and running in just a few minutes with plenty of headroom left on the small box.
See: https://arstechnica.com/gadgets/2022/11/used-thin-client-pcs...
But I do agree: run pi-hole as vm/dockers on some home server.
I assumed being ARM, pi was supposed to draw lower power. Looks like not the case.
Found another study confirming the same.
https://uni.hi.is/helmut/2021/06/07/power-consumption-of-ras...
Hardest part for me in the set up was that ad guard should query my router for local domain, because that one keeps track of which dhcp IP address is owned by which host. (This way I can always use host names on my internal network even for devices that get an address via dhcp. Very convenient if you play with Pi Zero and other toys)
1. Incredibly fast and easy to install compared to pi-hole
2. It's easier to update because you don't have to ssh into the raspberry, you can just update the thing through the user interface.
3. From time to time, it happened that the pi-hole hanged up, dns resolution did not work and I needed to reboot the thing to make it work again. I am not sure how widespread this is but I've seen many other users complain about this particular issue (even though it's a once-per-month thing).
(4. Better APIs)
For an in-depth comparison between the two you can take a look at the AGH GitHub Page[0]
[0]: https://github.com/AdguardTeam/AdGuardHome#comparison-pi-hol...
This has the advantage of working on any kind of device that allows you to manually specify a DNS server IP address, without having to install or maintain software.
For example, AdGuard maintains public DNS server IP Address options that: filter nothing, filter out ads and trackers, or filter out ads, trackers and adult content.
I'm OK with paying for services that the family uses and get returns out of them, such as the YouTube Premium. So, I'm not fighting tooth-n-nail to avoid ads where I can just buy it out.
I have seen and have even tried browsing the Internet without these basic tools (AdBlockers), and I'm stunned how the world had evolved into and how are people are on the Internet without these basic safeguards.
The only problem I have is with a few government/banks/insurance website that I have to strip out and go in naked to get things done.
Agreed. As long as there is an option to avoid it, I am ok with paying for it ( Hulu adfree tier comes to mind ).
<< not so much as trying to avoid being tracked entirely.
Agreed. That might be overkill for the benefit it provides.
<< I want to revamp and setup a better infrastructure
I keep talking about it with my friends, but I can't find enough motivation ( and there is always an excuse not to ).
World is ruled by money. Advertising is big. Anything that ruin this business will never be advertised publicly. Just imagine huge posters or ads in TV in prime time for pi-hole or AdGuard. That would be paradox not just for advertisers but also for product that is mean to work against advertising.
If also recommend browser based blockers for desktop and mobile, uBlock Origin bring the best in my opinion and couple that with others as required.
Find and use a few different upstream, privacy conscious and providers. I'm not convinced of the efficacy of paid VPNs, but by all means obtain and use one under your own control for when you're out and about on "hostile" (read; not home) networks.
I had nextdns, moved to pihole but the maintenance was frustrating- and I couldn’t use it outside of my home network (without more work with setup).
So went back to nextdns - I have set up different profiles depending on who is using it (so my wife is on a light version, no logging whereas my 9 year old son is on a lockdown down version with logging).
It just makes things simpler and is very reasonably priced
Maintenance? What maintenance?
I set up my PiHole a couple years ago and haven't touched it since.
Granted, I didn't set mine up on a Pi, I set it up on my EC2 box in AWS. That way, I could have ad blocking on my phone without needing to expose my home network.
Then the SD card died. Instead of digging it out to fix it I tried NextDNS and found it works as good or better while also being less work. Well worth $20 to me.
NextDNS' unlimited queries for its paid plan is also a large reason why I picked it over AdGuard with its 10m queries/mo limit. Even if I'll likely never hit that limit, I don't even want to worry about it.
# nx domain for disabling firefox DoH, so we can still get adblocking
# https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet
local-zone: "use-application-dns.net" always_nxdomainBut what if your IP changes? NextDNS provides a URL you can call manually to resync your IP address. I recycled my PiHole with a cron job to just call it every minute.
I feel like I wouldn't just default to opening HN and reddit all the time on my phone if I knew it was bandwidth capped to dial-up speeds. But if there was something critical there, I would still have access.
The "only for certain devices" part would probably mean putting those devices in a VLAN and only shaping that VLAN's uplink.
A router like pfsense should be able to do all of that.
But I am far from a network engineer, so don't quote me...
Not necessarily...if you're not using ESNI, then the traffic shaper could sniff the server name from the client hello message, then use the TCP sequence numbers to track the individual TCP connection.
Not a chance.
There is a possibility that the TCP sequence numbers between the two connections overlap, but it's so unlikely as to be negligible.
I'm just spitballing. My bona fides are nothing more than memories of reading about the upside-down-ternet and fiddling with primitive QoS features on elderly routers, but I'm sure this is the right post on the right forum to get a real solution.
But you're spot on regarding effort/learning.
Are you buying 10GBASE-T equipment or something?
2 APs - $200
8 port switch - $150
That's less than I'd spend personally.
If the Pi isn't the gateway (which it likely isn't) that's not going to be trivial. Even if it was, fiddling with iptables isn't exactly easy. How are you going to identify devices? MAC? DHCP reservations? Static IPs? That's not a trivial project.
How are you going to identify devices? MAC? DHCP reservations? Static IPs?
Yes.
That's not a trivial project.
I do this stuff all the time, it's not rocket surgery.
I have many hardwired devices, they may not.
I need two APs as I live in an older house and I get crappy reception in my basement. I also want a guest and IoT network so I chose to use VLANs to segregate, which requires switching and APs that can do that.
Yes, if you do this all the time (I do too) it's not that hard. But it's certainly not a beginner project.
This is the only European based vendor I'm aware of, aside PCEngines, whose hardware is excellent but not comparable wrt performance for heavy use. I'm sure there are cheaper similar solutions, especially from far east; also some interesting offers from the US and UK although shipping and import fees make them a lot less appealing (for us in the EU).
HN looks like it would do well back in the 14.4 dial-up days. Hell, it would probably be okay using an I/O port on an arduino at 9600baud
1. By using NetGuard and port forwarding DNS.
2. One can then enjoy reading about myriad security issues that rely on remote DNS, such as the recent DNS rebinding-dependent exploit against Tailscale.
- Not that many people run Piholes so the return on investment isn't good.
- More complicated integrations with webmasters.
[a secret 4th thing] - I think the people who build these systems want to have this escape hatch for themselves.
Also browser extensions are far and away the most popular ad blocking method so if it doesn't block them there's no reason to bother.
1. ad blockers are still so niche that it's not worth it to them
2. static IP addresses are dead-simple to block in a router or (probably? not a browser coder) in a browser plugin
3. static IP addresses aren't a real great cloud pattern, they're hard to scale out to meet demand
Ex A: https://blog.cloudflare.com/twilio-segment-sdk-powered-by-cl...
Ex B: https://developers.cloudflare.com/fundamentals/get-started/r...
E.g. I setup my router as a linux box that has Adblock DNS software package. Extend said package to write all resolved IPs such that its firewall checks the list before allowing traffic?
How else are people solving these rouge systems that ignore the network settings?
Both options are great, and OpenBSD/unbound has been running just as easily. Here is a recent HN thread on this: https://news.ycombinator.com/item?id=33122419
I’ve been using pihole for a really long time, but lately have run into an issue around blocking YouTube. I have wildcard blacklisted YouTube.com and www.YouTube.com, but it doesn’t work. It’s not just me, I found a thread online of others discussing this.
I’m using Firefox, so it’s not Chrome bypassing DNS check.
Does anyone know what the hell is going on?
A GUI is not really useful IMHO. And at scale, dnscrypt-proxy's logs can go to ES/Kibana if really needed.
added VPN provider
This make pi-hole useless. I would prefer to let DNS2 empty.
Also pihole won't catch DoH queries, that could be set in browsers or other apps.
The smartest thing I did was buy a $60 used chromebook, convert it into an LXD "server" and run pi-hole there. better performance.
I sold my five pi's on Ebay months ago for around a grand.
Have not figured out the smart tv yet.
Can you ask this piece of garbage, for-profit guide maker to not block countries from accessing his supposed "guides?"
I bet this scumbag did that intentionally.
No hate for the PiHole here; it served me well and it really gives lots of kids a nice project and it's totally turnkey protection. Mad props to the PiHole guys and gals for proving this is viable and this is a good thing for privacy and safety.
Does anyone know if using a pi-hole triggers ad-blockers popups on websites, and if yes, is it easy to deal with (either activate ads for specific websites, etc)?