unfortunately no, the router is not able to do that now. However pihole is able to do that, but you have to turn on DHCP for that. I'd rather not turn that on in the pihole. When I get a proper microserver (instead of a raspberry pi), I will turn the DHCP on for pihole and turn DHCP router off.
YESSS!!! that makes total sense. DUH we've both been saying it intercepts ALL DNS traffic. Of course it would still intercept the internal Pihole DNS traffic without exception. That explains my screenshot of pihole because when i make a single DNS request for example youtube. In the log it will...
are you sure about this? Because when I set it to global filter router and reboot all devices it appears to go to DHCP DNS LAN 1/2
Here is log from me changing it via the command you gave me (very useful by the way, wish i would have known about this ages ago)
Chain DNSFILTER (2 references)...
Yes I would say you are correct it is working with DNS Filtering on and global option set to "no filtering"
Maybe you can answer this then because clearly I am confused.
When I select no filtering, a client automatically bypasses the DNS filtering and then either uses the LAN DNS 1/2 provided...
Well I have done what you said. I have changed the LAN DNS server 1 to 37.235.1.174 freeDNS
here is the before
ASUSWRT-Merlin RT-AC68U 384.4-2 Sat Mar 24 17:01:45 UTC 2018
myusername@myrouter:/tmp/home/root# iptables -t nat -L -v -n
Chain PREROUTING (policy ACCEPT 4406 packets, 705K bytes)...
It was the same hardware RT-AC68U. I do upgrade the firmware everytime a new one comes out. Just to give you a general time frame. I bought this router maybe 9 months ago. Set it up within about a month had DNS filtering on. Worked great. However I stopped using DNS filtering after about 2-3...
no worries. It should work as you said, i've had it working 6 or so months ago with another device.
Device 2 is my laptop which I was using for testing to go through the pihole and it works fine. the Nixie clock as you see is set to OpenDNS which in theory should work but I know its not working...
maybe these will also help. Also 192.168.30.5 does not exist on my network, that is ok and i want it like that. I am forwarding a dodgy devices DNS to a DNS server that does not exist so it will just time out and not go anywhere
sorry im being as detailed as possible and i thought thats what you asked for when you said "
What do you have set for DNS Filter's Global Filter mode and any Custom settings?"
which i provided all the customs that I had including the LAN DNS which when DNS Filtering is on and "router" is...
Settings are as follows
DNS Setting - On
Global Filter - Router
Custom 1 - 192.168.20.241
Custom 2 - 1.1.1.1
Custom 3 - 208.67.222.222
LAN DNS 1 192.168.20.241
LAN DNS 2 208.67.222.222
I partially give up on this to be honest. So a few more things I have tried. I am 99% sure DNS filtering is...
oh man i thought i replied to this like 2 days ago... haha but i wrote it in a text file on my computer and never copied it over :P
see below
Correct that is what I understood it to be it affects ALL DNS. Currently there is nothing in custom
Understood. This is currently automatic
Does this...
Small little update.
I fired up wireshark. Did a wifi capture just on my local PC as suspected for some reason the return traffic is not coming in see attached :(
The first one is without DNS Filtering on and working pihole
https://s7.postimg.org/8jq4kz1gb/working.png
The second one is with it...
Ok here are some things from my testing
I have removed all settings of WAN DNS , LAN DNS and turned off DNS Filtering.
With this I have internet and my DNS server is my router. I veified that Pi-hole is not getting any DNS requests
From there I turn on DNS Filtering with Global Filter set to...
Thanks and yes it would go device DNS requst to pi hole (20.251) and pi hole would reach out if it did not have anything cached on the domain. the DNS for the pi hole is Ad Guard DNS. This is working fine for all devices. I can see requests coming in to pi hole every few seconds.
I am currently...