Asus Merlin firmware handles this nicely.
Asus Merlin firmware handles this nicely.
Works great.
I have a RaspPi working wonders but I suspect some devices have hardcoded connections which bypass the DNS request. Is there a simple way to forward to that RaspPi for correct “gate keeping”?
I had issues with just DNAT following some ui forum posts, and I think it's because I'm using switch0 as the interface, with devices across LAN ports on my EdgeRouter. The SNAT masquerade was the key to getting the replies from the pi-hole routed properly.
I was previously using my EdgeRouter as the DHCP DNS server, and using DNS Forwarding on switch0 w/ dnsmasq to forward queries to the pi-hole. With a large cache, this avoided a couple hops for every DNS query on my network. However, this meant that I couldn't see which IP was making the query in the pi-hole query logs, so I've flipped it so that the pi-hole is the DHCP DNS server, and the pi-hole queries the EdgeRouter, which then forwards the requests to public DNS w/ caching. I then assigned every device a '.local' domain in the pi-hole Local DNS tab, which lets pi-hole displays a friendly name for each query in the log.
For completeness sake, here's everything I needed on the EdgeRouter. The EdgeRouter was setup with no VLANs, and with all LAN ports switched w/ a single subnet (switch0 interface exists in the dashboard).
EdgeRouter:
* In the bottom left "System" pop up drawer, set "System domain-name" to "local" (or whatever domain of your choice, like "lan" or "home").
* Services > DHCP Server > [Your DHCP Server] > View Details: Set DNS1 to your pi-hole IP (make sure it's statically mapped!), set Domain to "local"
* Firewall/NAT > NAT: Follow above guide
* Services > DNS: Enable DNS Forwarding for switch0, set appropriate cache size
* Config Tree > service > dns > forwarding: set name server to public DNS server of your choicse
Pi-hole:
* Settings > DNS: Disable all external DNS servers, set custom upstream DNS server to the EdgeRouter
* Local DNS > DNS Records: Look at your EdgeRouter DHCP lease list, give everything you care about a static IP assignment, and then give them ".local" DNS records in pi-hole. SSH-ing in and editing `/etc/pihole/custom.list` may be faster, as pi-hole seems to bring services down and then back up for each entry added via the web UI.
Eventually, yes, device/software manufacturers will start using encrypted solutions, but until then, ya do what ya can do. Maybe the blocking solutions will evolve and adapt as well.