What's new

Diversion Diversion blocking less than 2%

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Daniel LaRusso

Occasional Visitor
Diversion seems to be blocking less and less for me recently. At last check, it was blocking less than 2% of ads. I'm running the latest Merlin firmware (384.19) and Diversion is updated to the current version (v4.1.12). IP pool starting address doesn't include pixelserv-tls address and I'm using the "Medium" blocking list with no custom lists. I'm using an Asus RT-AC86U, running ExpressVPN client manually configured at the router level. I've followed the protocol for running a VPN client and Diversion (DNS config set to "exclusive" and policy rules off/force internet traffic through tunnel: yes). Other settings are as follows:

DHCP Server > DNS and WINS Server Setting > DNS Server 1 > blank > DNS Server 2 > blank
Advertise router's IP in addition to user-specified DNS > yes
DNS Filter > Enable DNS-based filtering > on > Global filter mode > router

Doesn anyone have any tips or suggestions?
 

Attachments

  • Screen Shot 2020-12-16 at 10.37.33 AM.png
    Screen Shot 2020-12-16 at 10.37.33 AM.png
    241.3 KB · Views: 246
  • Screen Shot 2020-12-16 at 10.49.03 AM.png
    Screen Shot 2020-12-16 at 10.49.03 AM.png
    105.1 KB · Views: 249
Maybe this can help

I've read that and don't use policy rules. "Diversion will work over the VPN tunnel when “Accept DNS configuration” is set to “Exclusive” and Policy Rules are disabled by setting 'Redirect Internet Traffic' to 'All'."

I have DNS config set to "Exclusive" and policy rules are disabled, with all internet traffic forced through the tunnel.
 
Accept DNS configuration : disable
Diversion working. Use stubby (DOT), dnscrypt...
but if you redirect all traffic to vpn you can also use unbound. you only need to use the "bind disable" command here. the dns ip address and the external ip address are the same.
 
Accept DNS configuration : disable
Diversion working. Use stubby (DOT), dnscrypt...
but if you redirect all traffic to vpn you can also use unbound. you only need to use the "bind disable" command here. the dns ip address and the external ip address are the same.

So the best way when using a VPN and ad blocking is to use unbound?
 
As previously mentioned you need to set
Accept DNS configuration : disable
to have your VPN traffic use Diversion. When you set Exclusive you were telling your VPN traffic to only use the DNS provide by the VPN server and not Diversion.

1608248035519.png
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top