1
General Discussion / Why can't I keep DNS queries from going through my PiHole?
« on: December 26, 2023, 08:56:18 pm »
I've been using PiHole with OPNsense for a long time, but decided to switch to AdGuard home running on the OPNsense box so I can retire the Pi. After trying to make the switch following various guides online, I can't seem to get it to work as everything keeps routing through the PiHole no matter what I do, and I can't figure out why. To try to figure this out, I've removed AdGuard for now and tried to revert everything to using default DNS services without the PiHole by removing all the settings that pointed DNS at the PiHole, but I keep getting new queries in the PiHole query log even after doing so.
OPNsense 23.7.10 at 192.168.0.1
System > Settings > General > DNS servers empty, "Allow DNS server list to be overridden by DHCP/PPP on WAN" unchecked, "Do not use local DNS service as a nameserver for this system" unchecked
3 LAN interfaces: 192.168.0.1/24 [LAN], 192.168.10.1/24 [IoTVLAN], 192.168.20.1/24 [GuestVLAN]
Firewall > Rules > [Interface] > Disabled any rules that related to DNS routing (on all 3 interfaces)
Services > DHCPv4 > [Interface] > DNS servers empty (for all 3 interfaces above)
Services > Unbound DNS > Enabled, port 53, nothing listed under overrides, access lists, blocklists, query forwarding, or DNS over TLS
After making the above changes and restarting OPNsense to renew the DHCP leases, I'm still getting queries in the PiHole query log (coming from devices on all of the above listed VLANS). I'm sure there's some setting that I'm missing in the configuration somewhere, but what is it?
OPNsense 23.7.10 at 192.168.0.1
System > Settings > General > DNS servers empty, "Allow DNS server list to be overridden by DHCP/PPP on WAN" unchecked, "Do not use local DNS service as a nameserver for this system" unchecked
3 LAN interfaces: 192.168.0.1/24 [LAN], 192.168.10.1/24 [IoTVLAN], 192.168.20.1/24 [GuestVLAN]
Firewall > Rules > [Interface] > Disabled any rules that related to DNS routing (on all 3 interfaces)
Services > DHCPv4 > [Interface] > DNS servers empty (for all 3 interfaces above)
Services > Unbound DNS > Enabled, port 53, nothing listed under overrides, access lists, blocklists, query forwarding, or DNS over TLS
After making the above changes and restarting OPNsense to renew the DHCP leases, I'm still getting queries in the PiHole query log (coming from devices on all of the above listed VLANS). I'm sure there's some setting that I'm missing in the configuration somewhere, but what is it?