OPNsense Forum

English Forums => General Discussion => Topic started by: MaartenVT on October 05, 2026, 11:29:45 AM

Title: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: MaartenVT on October 05, 2026, 11:29:45 AM
Hi everyone,

I'm hoping to get some advice on how to properly handle a managed school Chromebook on my home network powered by OPNsense and AdGuard Home.

The issue:
My son was given a school-managed Chromebook. The device appears to be hardcoded/configured via Google Admin policies to strictly use DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT).


What I've considered/tried so far:


Has anyone successfully dealt with strictly managed ChromeOS devices on OPNsense? Is there a recommended approach (e.g. specific NAT port forwards, blocking specific canary domains, or handling ChromeOS network checks) to force local DNS usage without breaking its internet connectivity?

Thanks in advance for any insights!

Best regards,

Maarten
Title: Re: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: meyergru on October 05, 2026, 11:49:51 AM
That is a collision of interest of the purest kind.

You can block DoT/DoH, but obviously, you cannot intercept and modify that traffic, because it is encrypted and protected via certificates. Normally, such an approach would be used in conjunction with a traffic interception of normal, unencrypted DNS traffic to be able to block certain DNS domains. If anyone wants to use your network, he must fall back to standard DNS in such a scenario, i.e. abide by your imposed rules.

If you want to give a device internet access that does not play by those rules, you can, but then you cannot block DoT/DoH, as you have seen.
In that case, I would put that device into a separate VLAN (probably also a separate WLAN), such that it can do whatever it chooses, but has no possibility to access any of your own LAN ressources. Of course, you can allow specific services, like accessing a printer.

Or to put it short: You cannot have the cake and eat it, too.

BTW: If there was a canary domain, you would be able to see a DNS request (and, obviously, it would be via normal DNS).

Since Chromium deliberately chose not to implement a Firefox-style canary domain, there is no DNS-side mechanism to force such a fallback; and if the Chromebook is managed by the school, the DoH-only setting is most likely policy-locked anyway.

Title: Re: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: Monviech (Cedrik) on October 05, 2026, 12:45:02 PM
If DNS cannot be inspected the next step up is SNI for (most) TLS traffic, which is still unencrypted most of the time (though encrypted SNI is slowly coming too).

Zenarmor might be able to do that style of blocking.
Title: Re: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: MaartenVT on October 05, 2026, 01:47:03 PM
Thanks for the clear explanation! That clarifies why the Chromebook behaves this way.

Since ChromeOS indeed lacks a canary domain mechanism like Firefox and the school policy locks DoH/DoT, forcing local DNS on this device seems virtually impossible without breaking its internet connection.

Maybe I will follow your advice and put the Chromebook into a dedicated, isolated VLAN (with its own SSID) to ensure it has internet access while keeping it completely segregated from my local network devices.

Thanks again for helping me understand the limitations here!

But personally I think that this is such a weird implementation. I cannot monitor or filter what my kid is accessing on my own home network, simply because it's a school-managed Chromebook. It's just such a pain in the *** (pinky)...
Title: Re: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: cookiemonster on October 05, 2026, 09:59:56 PM
The same goes for some corporate devices. I work for government now. The laptops issued for when working away from the office like when working from home, it connects to my home wifi but it automatically connects only to an always-on vpn and local networks aren't routable. No home printing for instance.
The similarity is that they are regulated groups, and their endpoint security must be able to inspect all traffic regardless of location. That is why you can't modify DNS settings on them.
Title: Re: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: nero355 on October 05, 2026, 10:11:04 PM
Quote from: cookiemonster on October 05, 2026, 09:59:56 PMThe same goes for some corporate devices.
I told him that more or less already @ https://forum.opnsense.org/index.php?topic=53056.msg275061#msg275061 but he wanted to check if someone happens to know any workarounds in the English part of the forum :)

My last advice would be :
- Buy a second hand/used quality laptop.
They can be pretty cheap!
- Configure it however you want so you are in control and/or can spy on the kiddo...
- Tell the kiddo it's BRAND NEW!

Aaaaand DONE! :)
Title: Re: School Chromebook bypasses local DNS (DoH/DoT) – how to force local DNS on OPNse
Post by: Patrick M. Hausen on October 05, 2026, 10:17:14 PM
If the Chromebook is school managed I would trust them to a certain degree to put proper protection in place and just isolate the device from the rest of the network.

What would he do with that second hand laptop? My very educated bet is that the school managed device is 100% mandatory for any school related work.