this post was submitted on 26 Jul 2023
25 points (90.3% liked)

Selfhosted

40040 readers
824 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

Hello, friends.

So I've had my Pi-Hole setup for awhile now and it's great. I'd like to get Wireguard working with it, too, so I could browse the internet without loads of ads and trackers on the go.

However, small issue. All DNS traffic is forcibly routed to my ISP. If you need some details, I made this post on the Pi-Hole userspace.

I'm in America and my ISP is Spectrum. I was wondering if there's a way I could convince technical support to allow me to use a recursive DNS for privacy/security (more-so the second of the two) purposes, or if it is even possible to convince them to do this. I don't know if there's a specific number I should contact, email I should email to, or if I just have to endure the nightmare of getting passed around by customer service one Saturday. Any recommendations would be great.

An interesting note for anyone who's ISP is Spectrum, their DNS service, at least for me, uses OpenDNS with dnsmasq-2.57. That version of dnsmasq is over 10 years old. You see if this is the case for you with

dig CHAOS TXT version.bind @192.33.4.12 +short
dig CHAOS TXT version.bind @198.97.190.53 +short

Or something similar if those IP addresses are different for you. You can see that running those commands were a part of the steps I was asked to take in that Pi-Hole userspace post.

EDIT 1:

For those interested, here's some Github gist I found that shows how to use unbound + stubby for have a recursive DNS + DNS-over-HTTPS. There's also this from the DNS Privacy Project.

EDIT 2:

I seems that initial answer from the Pi-Hole forums was correct. There's probably something that was set in the firmware for the Netgear router that prevents me from setting up my own DNS servers. However, I notice on the router there's a "router mode" option that's on, which I can probably turn off, plug in my Pi to the Netgear device and have the Pi act as my router, thus letting me be able to use it as my DNS server as well. That or just suck it up and buy only a modem, not a router + modem combo.

you are viewing a single comment's thread
view the rest of the comments
[–] duffkiligan@lemmy.world 5 points 1 year ago* (last edited 1 year ago) (1 children)

I think you mean router, since you would most likely not set DNS on a modem (unless it’s a combo) — but yes I would look into getting something better that you have more control over.

Edit: gotta love new Lemmy clients that spam comment replies 🤦‍♂️

[–] AlecStewart1st@lemmy.world 1 points 1 year ago (3 children)

It's a combo. Most are these days, I believe, but I know Spectrum is weird and will give you a router AND modem if you just buy it through them. What device would you recommend? I don't want to buy one just to find out I can't set the Pi-Hole as the DNS server on a new one.

[–] duffkiligan@lemmy.world 2 points 1 year ago (2 children)

I use a Unifi system which is going to be overkill for 99% of people, but as far as Modems only go Arris Surfboards are solid and I’ve never had an issue.

For router you can get whatever is your fancy, mesh system or a big multi antenna whatever.

[–] clegko@lemmy.world 2 points 1 year ago

Moto's DOCSIS modems are pretty damn solid, too. I've had one at my MIL's house doing gigabit for a few years now and haven't had a lick of issue with them.

[–] AlecStewart1st@lemmy.world 1 points 1 year ago (1 children)
[–] duffkiligan@lemmy.world 1 points 1 year ago

That’s still a combo device which I generally would avoid. But basically anything that isn’t provided by the cable company will be better.

[–] RoyalEngineering@lemmy.world 1 points 1 year ago (1 children)

I would recommend putting that modem in Bridge mode and getting something like a TP-Link Omada device. I’ve had them for a while and have been really happy.

[–] AlecStewart1st@lemmy.world 1 points 1 year ago* (last edited 1 year ago)

Seems like I could potentially get around my issue by taking the device out of this "router mode" setting I found and connecting my Pi to it via Ethernet cable and have the Pi be the router for my network.

EDIT: Actually, scratch that. I don't think a Pi would be powerful enough to act as a router. Well, off to by a modem (not a combo) it is!

You just need to tell them you want a modem only, no router.

I'm running an Asus rt68ac with Merlin firmware. Which is nice because I can force all dns through my piholes. Even the hardcoded stuff like the iot devices.