I ditched my Pi-hole but still block ads with NextDNS
mattsayar.com
mattsayar.com
[1]: https://www.friendlyelec.com/index.php?route=product/product...
Since then, it's trucked along without issue for years. Couldn't use the internet without it at this point.
Having said that, I have a Pi running HomeBridge to make a Pi camera and some non Apple Homekit capable IoT shit work with my phones/iPad, and I'm pretty sure the last few times it's rebooted were due to power outages, and I can't remember the last time I needed to even hit the HomeBridge web interface, never mind ssh into it. I'm a little surprised unscheduled power outages haven't borked the sd card, it's not even configured to do the ramfs overlay thing.
• The free plan supports 300,000 queries/month (all features, unlimited devices, unlimited configurations) and is a great and simple way to test drive it.
• If you like the idea but want more knobs, many people are also happy with competitor Control D. I'd just caution that the two-year-old comparison¹ on their site is just wrong about several claims (including "lower latency") and is not without problems itself². I looked at them and chose NextDNS as a better "set and forget" option that also plays well with Tailscale³.
¹ https://controld.com/blog/control-d-vs-nextdns/ ² https://www.reddit.com/r/ControlD/comments/1irgehp/178ms_lat... ³ https://tailscale.com/kb/1218/nextdns
I couldn’t even reach anyone to cancel my NextDNS subscription, so I did a chargeback - which went through because the card company was also unable to reach anyone there. It seems to be running in zombie mode.
Edit: I totally missed they have a Personal tab at the top that has different pricing. It is still more expensive for their full control plan.
ControlD over NextDNS - one is on zombie mode it seems, the other isnt...
¹ https://github.com/nextdns/nextdns/releases ² https://www.reddit.com/r/ControlD/comments/1irgehp/178ms_lat...
I've been running pi-hole in KVM guest virtual machines for more years than I can remember and never had any problems. I would expect a Raspberry Pi to eventually choke on the demand of providing 24/7 service to a network.
But not everyone has a hypervisor in their basement. Forking over $20/year is definitely better on the budget than buying a server.
But if you already have a server or some reliable hardware in your LAN, there's no good reason to leave anything important up to a Raspberry Pi.
A Pi can run for a very long time if you are careful. I run my dad's phones with one with Raspbx. It has two USB sticks in it. Both are bootable and the live one copies itself to the other monthly. Its unlikely that both sticks will die at the same time - glacial speed RAID 1!
So does any non-trash router.
It’s all just standard *nix software that will work on anything from my SFP module running openwrt, to a reflashed MIPS Ubiquiti router, to my x86 FreeBSD box.
Pi Hole was started specifically as a project targeting the Pi. It wasn't the first to do ad blocking DNS by a long shot, but it did marry a nice web UI to DNS and made it a lot more accessible. Nowadays I think there are much better options like AdGuard that do the same thing, but "running PiHole on a Pi" is a tangible thing to do with the RasPi you got as a gift and is an approachable project for a lot of Linux beginners with real benefits. You can find a million people on YouTube recommending exactly that, and walking you through how to do it step-by-step on a RasPi. Lot of people who are interested in tech but not so skilled probably don't have dedicated servers or know how to set one up, and I expect PiHole on a RasPi gets a lot of momentum from that as something cool and actually useful to do that isn't actually difficult/there are a million tutorials for.
Tl;dr is I agree with you, there are clearly technically superior options. But for a lot of the people you're referring to the alternative is not to run something better on a dedicated server/router, it's to do nothing at all and go back to using the router from your ISP.
I've seen AdGuard recommended a lot recently but from what I can tell this doesn't do the same thing as a DHCP pihole.
Something I'd love to do some day is replace my consumer router with something open source and run an all-in-one solution (ad blocking for all devices on network, DoH, as well as just a generally competent home router for a small apartment). Do you have any recommendations for where to start if I were to go down this road?
More powerful options are projects like PfSense or Opnsense, but those require more expensive hardware and for most uses you probably also need a separate switch. I personally use PfSense and find it relatively easy to use while being extremely powerful, absolutely jam packed with features but an accessible WebUI and clear documentation.
Probably the best all round option are the semi open, prosumer-ish products from companies like Ubiquiti or gl.inet (the latter is even based on OpenWRT, but with a nicer UI... I have one of their routers as a travel router). Ubiquiti's Unifi routers are very easy to use and jam packed with features for a pretty great price, but their platform is not truly open source. Still, gl.inet or Unifi are what I would probably most recommend to someone like you looking to upgrade but feeling overwhelmed by lack of knowledge.
Beware it's fun to tinker and that's how I learnd pretty much everything I know about networking, but breaking the Internet will not endear your new toys to your family. It's good to have a spare in case you mess up so you can keep the bits flowing while you undo your mistake. Anything you choose is going to be an ongoing learning experience if you're starting from no knowledge, but there are lots of high quality tutorials on places like YouTube.
NextDNS just works. Allowlists are pretty easy to implement too for those edge cases.
For me NextDNS is not that usable and is not a finished product because:
a) I need the ability to turn it off temporarily once in a while (even if it’s on a family member’s device)
b) the NextDNS client apps on iOS/iPadOS are abandoned (not updated for years) and the toggle to turn off or on doesn’t reliably work
c) there is hardly any support in the community forums
With the abandoned and flakey client apps, visiting test.nextdns.com would show “unconfigured” or a NextDNS server information randomly. I never know whether it’s really on or not.
Using a VPN profile is recommended through it cannot be easily turned off and on. But even the VPN profile doesn’t work on my Apple TV.
The NextDNS DNS servers around the world seem to work, but the experience on devices is unreliable and poor. If the founders could employ someone to improve the apps and how it works, I’d use it. I had considered a paid subscription a few years ago but didn’t go through because of these experiences.
Update.. as usual I was trying this all day and only after posting this does this work - Here's a bash script https://gist.github.com/willwade/251fa791da27267b5470c75a7b5... - a shortcut for this is way more complicated
That aside, I've had pretty much the same issues with NextDNS that I've had with Pi-hole -- issues that have nothing to do with the infrastructure per se. (The classic example is of an app that doesn't work because domain `X` is being blocked, thus kicking up the usual 15 - 30 minute-long log search and DNS cache-clearing to find and whitelist the domain.)
Note the free plan is great for several devices as long as they’re not Apple. For some reason, 2+ Apple devices blow through the 300,000 query limit really easily. When I used a Pixel 2 I think it averaged 60,000 and fit in the quota with my other devices, and when I switched to iPhone it pushed the total over 300,000. But they’re cheap and definitely worth it.
The pi bit of it is less important than the hole bit of it.
and with things like Tailscale or ZeroTier you can run your pihole at home and use it from anywhere on mobile devices too
I run a couple at home and they've been rock solid in containers on mini-pcs for a long time.
It is the only product I know (short of running dnsmasq standalone) to run a DHCP linked with a DNS and what registers in the DHCP is also registered in the DNS.
For home use I'm currently testing out AdGuard Home as it comes as pre installed with the Flint 2 router. I can't get it to work on my phone so I don't see myself switching away from NextDNS any time soon.
It isn't the pihole software's fault here.