Hi everyone,
I'm hoping to get some advice on how to properly handle a managed school Chromebook on my home network powered by OPNsense and AdGuard Home.
The issue:
My son was given a school-managed Chromebook. The device appears to be hardcoded/configured via Google Admin policies to strictly use DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT).
- If I try to block or interrupt DoH/DoT traffic on my network, the Chromebook completely loses internet access and refuses to connect. It does not fall back to the local DNS servers assigned via DHCP.
- If I allow DoH/DoT, the Chromebook completely bypasses my local DNS security and filtering (AdGuard Home).
What I've considered/tried so far:
- I have completely disabled IPv6 on my local network (LAN is IPv4-only).
- I know the device's IP and MAC address.
- I could put the Chromebook into a dedicated VLAN to isolate it from the rest of my home network, but that doesn't solve the issue of filtering the traffic originating from the Chromebook itself.
- Dropping standard DoH/DoT IP lists or blocking port 853 / known DoH endpoints causes the device to report "No Internet".
Has anyone successfully dealt with strictly managed ChromeOS devices on OPNsense? Is there a recommended approach (e.g. specific NAT port forwards, blocking specific canary domains, or handling ChromeOS network checks) to force local DNS usage without breaking its internet connectivity?
Thanks in advance for any insights!
Best regards,
Maarten
That is a collision of interest of the purest kind.
You can block DoT/DoH, but obviously, you cannot intercept and modify that traffic, because it is encrypted and protected via certificates. Normally, such an approach would be used in conjunction with a traffic interception of normal, unencrypted DNS traffic to be able to block certain DNS domains. If anyone wants to use your network, he must fall back to standard DNS in such a scenario, i.e. abide by your imposed rules.
If you want to give a device internet access that does not play by those rules, you can, but then you cannot block DoT/DoH, as you have seen.
In that case, I would put that device into a separate VLAN (probably also a separate WLAN), such that it can do whatever it chooses, but has no possibility to access any of your own LAN ressources. Of course, you can allow specific services, like accessing a printer.
Or to put it short: You cannot have the cake and eat it, too.
BTW: If there was a canary domain, you would be able to see a DNS request (and, obviously, it would be via normal DNS).
Since Chromium deliberately chose not to implement a Firefox-style canary domain, there is no DNS-side mechanism to force such a fallback; and if the Chromebook is managed by the school, the DoH-only setting is most likely policy-locked anyway.
If DNS cannot be inspected the next step up is SNI for (most) TLS traffic, which is still unencrypted most of the time (though encrypted SNI is slowly coming too).
Zenarmor might be able to do that style of blocking.
Thanks for the clear explanation! That clarifies why the Chromebook behaves this way.
Since ChromeOS indeed lacks a canary domain mechanism like Firefox and the school policy locks DoH/DoT, forcing local DNS on this device seems virtually impossible without breaking its internet connection.
Maybe I will follow your advice and put the Chromebook into a dedicated, isolated VLAN (with its own SSID) to ensure it has internet access while keeping it completely segregated from my local network devices.
Thanks again for helping me understand the limitations here!
But personally I think that this is such a weird implementation. I cannot monitor or filter what my kid is accessing on my own home network, simply because it's a school-managed Chromebook. It's just such a pain in the *** (pinky)...
The same goes for some corporate devices. I work for government now. The laptops issued for when working away from the office like when working from home, it connects to my home wifi but it automatically connects only to an always-on vpn and local networks aren't routable. No home printing for instance.
The similarity is that they are regulated groups, and their endpoint security must be able to inspect all traffic regardless of location. That is why you can't modify DNS settings on them.
Quote from: cookiemonster on October 05, 2026, 09:59:56 PMThe same goes for some corporate devices.
I told him that more or less already @ https://forum.opnsense.org/index.php?topic=53056.msg275061#msg275061 but he wanted to check if someone happens to know any workarounds in the English part of the forum :)
My last advice would be :
- Buy a second hand/used quality laptop.
They can be pretty cheap!
- Configure it however you want so you are in control and/or can spy on the kiddo...
- Tell the kiddo it's BRAND NEW!
Aaaaand DONE! :)
If the Chromebook is school managed I would trust them to a certain degree to put proper protection in place and just isolate the device from the rest of the network.
What would he do with that second hand laptop? My very educated bet is that the school managed device is 100% mandatory for any school related work.