Best firewall solution for gaming sites

Started by mnhim001, December 11, 2025, 05:42:35 PM

Previous topic - Next topic
I have 3 kids at home that are gamers and streamers.  I have setup OPNsense and enabled Unbound DNS using the AdGuard List.  This caused all their gaming sites to no longer work.  I added a bunch of sites to the Allowlist Domains.

My question is, is this the best solution? or is there another solution? I was thinking of installing AdGuard Home plugin, but not sure if its just going to give me the same results.

What I am looking for is an ongoing Allow list that I don't have to come back up update manually. 

By using a mechanism that "always" blocks known ad distributing sites, you will automatically trigger blocks on sites that rely on such ads. The only way of having the best of both worlds is to use ad-blocking mechanisms that fake the ads being displayed. Such mechanisms are available for many browsers, think of uBlock Origin.

A prominent example of a site that does not tolerate ad-blocking is Youtube.

On devices where those tools are not available, you can still use DNS-based ad blockers, e.g. by identifying your smartphones and using AdGuard DNS rules only for those devices.
Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, ZTE F6005

1100 down / 800 up, Bufferbloat A+

Quote from: meyergru on December 11, 2025, 05:54:27 PMBy using a mechanism that "always" blocks known ad distributing sites, you will automatically trigger blocks on sites that rely on such ads.


That's not always true. Many sites that test for adblockers use a separate dns entry for the test for if there is an ad blocker. It it tests 'positive' then the site throws up all over the user. If you block the dns that is only testing, the site is generally blind to the ad blocker. It's tedious to find the one or ones testing for if there is an ad blocker. But worth it if you can block ads on the site.

Adguard Home and Pihole are tailor made for this kind of granular control. And, fortunately, Adguard Home is an OPNsense option.

Agree Ublock Origin is great. PC ad blocking can do more than only dns blocking, such as it is with Adguard Home or Pihole.

You are theoretically correct, alas, it suffices to have "some" sites checking with the same DNS entries that the ads use and making those fail.

And by using a PC blocker, the use can always selectively disable the blocker for sites that do not work and that he needs to work (even with ads) - this granular control is what you miss by using a DNS blocker on your firewall.

On Youtube, not only are no ads showing up on the page - the videos are not interrupted by ads, either.
Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, ZTE F6005

1100 down / 800 up, Bufferbloat A+