I set my DNS in the WG config as well. I don't bother with having a redirect rule.What do you have set for Private DNS on the phone?
Quote from: CJ on August 16, 2023, 06:17:56 pmI set my DNS in the WG config as well. I don't bother with having a redirect rule.What do you have set for Private DNS on the phone?I did have my main LAN address as the DNS in the wireguard config on the phone. I changed that to the wireguard gateway and it still lets ads through.I have nothing set for private DNS on the phone itself. I assume the wireguard app itself will direct all DNS to what I tell it.I will note that I recently upgraded to 23.1.x (and still on that until 23.7 has another patch or two) and it now has the wireguard kernel implementation and no longer the go version. Did that introduce something different? Figured it'd be a seamless transition.
Quote from: wallaby501 on August 22, 2023, 05:53:19 pmQuote from: CJ on August 16, 2023, 06:17:56 pmI set my DNS in the WG config as well. I don't bother with having a redirect rule.What do you have set for Private DNS on the phone?I did have my main LAN address as the DNS in the wireguard config on the phone. I changed that to the wireguard gateway and it still lets ads through.I have nothing set for private DNS on the phone itself. I assume the wireguard app itself will direct all DNS to what I tell it.I will note that I recently upgraded to 23.1.x (and still on that until 23.7 has another patch or two) and it now has the wireguard kernel implementation and no longer the go version. Did that introduce something different? Figured it'd be a seamless transition.You have Private DNS set to Off or Automatic? You should be using the os-wireguard plugin and not the go implementation, but that shouldn't be causing this.What are you seeing in the unbound reporting? What domains get queried when you start a game? These are game apps, correct?Can you have OPNSense grab a packet capture? I'm wondering if the game is falling back to DoT or DoH after getting failures using the system DNS. A lot of things will either hardcode additional DNS servers and/or use DoT/DoH.