FREE DNS SERVICE

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
34,962
Reaction score
11,654
OpenWRT has quite detailed documentation about DNS Hijacking, including blocking DoT providers.
https://openwrt.org/docs/guide-user/firewall/fw3_configurations/intercept_dns#dns_over_https
However, at least I was not able to get it working properly last time I tried it. It is one of the areas I prefer pfSense over OpenWRT. pfSense just works. OpenWRT does not. And it usually comes to my fault in the end as I am not an experienced OpenWRT user (one example is Dual WAN setup). But again I am not an experienced pfSense user either but I just feel pfSense to be much easier than OpenWRT when it comes to more complex topic (like Wireguard and OpenVPN setup, dual WAN setup, and more complex firewall rules).

It seems to me I have to use the static route to sink hole Google DNS (8.8.8.8 and 8.8.4.4) to make it work for OpenWRT, just like what I did for the Asus RT-AX82U.

Current working configurations: I can confirm that Pi-hole is the DNS used by the Realme phone and not Google DNS, Ad blocking test will be 100%.

1) Realme X50 5G Android phone use default "Auto" setting for the Private DNS (DoT) and Mobole Chrome browser Secure DNS (DoH)

2) OpenWRT LAN DHCP DNS set to Pi-hole DNS (192.168.28.254 in my case); I also set the WAN DNS to a cloud instance of Pi-hole (not necessary, probably can use the same local Pi-hole DNS).

3) OpenWRT static route rule to sink hole Google DNS (apparently the above rules do not work well so that I still need this static route rule)

dudwPwM.png
 
Last edited:

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
34,962
Reaction score
11,654


Nice video but not good enough as it does not deal with blocking DoH and DoT.

Read the coments by kc1.
Great explanation!! Thanks a lot! How about SNI-based web filtering on OpenWRT? Because DNS over HTTPS cloud be used to bypass Pi-hole, many smart devices now implement DOH which is impossible for us to block them from phone home. Personally I use AdGuard home and redirect all dns (Port 53)
 

carmelmore

Senior Member
Joined
Apr 21, 2019
Messages
1,118
Reaction score
7
Just tried Adguard dns and Nextdns but it keeps using US server as shown on dnsleaktest so ping is around 200ms.

No issues with Google or Cloudflare dns as it will always use SG server.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
34,962
Reaction score
11,654
Just tried Adguard dns and Nextdns but it keeps using US server as shown on dnsleaktest so ping is around 200ms.
No issues with Google or Cloudflare dns as it will always use SG server.

Try ControlD instead to see if that makes a difference. Based on my testing it is much faster.

That being said it is still better to set up local instance of Pi-Hole or Adguard Home (or pfBlockerNG in case you want to use pfSense)
 

DCmax1104

Member
Joined
Nov 18, 2007
Messages
141
Reaction score
28
Just tried Adguard dns and Nextdns but it keeps using US server as shown on dnsleaktest so ping is around 200ms.

No issues with Google or Cloudflare dns as it will always use SG server.
Which ISP are you using? I had similar problem - my Adguard was connected to their London server.

I emailed Viewqwest and they eventually resolved it and it connected to the SG dns server
 

carmelmore

Senior Member
Joined
Apr 21, 2019
Messages
1,118
Reaction score
7
Which ISP are you using? I had similar problem - my Adguard was connected to their London server.

I emailed Viewqwest and they eventually resolved it and it connected to the SG dns server
Using Singtel. Quad9 and Nextdns also connects to their US server.

What info did you gave Viewqwest in your email for them to solve it? Need to give out your Public IP?
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
34,962
Reaction score
11,654
Using Singtel. Quad9 and Nextdns also connects to their US server.

What info did you gave Viewqwest in your email for them to solve it? Need to give out your Public IP?

For Singtel it is tough to change their routing behaviour but you can try your luck. Viewquest is better in this front.

Or try my suggestion to switch to ControlD if you do not want to go for solutions like local Pi-hole or Adguard Home.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top