Pi Hole & DD-WRT (DNS Traffic Escaping)

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Advanced Networking
Author Message
LunchBoxSteve
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 21

PostPosted: Sun Sep 27, 2020 3:39    Post subject: Pi Hole & DD-WRT (DNS Traffic Escaping) Reply with quote
Can anyone give me a step by step on how to configure DD-WRT with PiHole?

I'm trying to follow along with older threads but it's hard to understand the back/forth and people debugging what they posted along the way and follow what it should be.

I have it setup and running now. I've configured filter rules under access restrictions to not allow any port 53 traffic from any IP address on any interface except for the PiHole address.

The filter is showing lots and lots of counts so I know it's working. I also can't ping domain names in the block list indicating it's working but the problem is that some DNS traffic is still escaping the router.

If I swap out the router with another one (won't mention the name) with the same rules /setup with this PiHole, no traffic escapes so it has to be something with DD-WRT not configured that's allowing it.

Any help would be greatly appreciated. I thought I'd start with verifying I hadn't missed something.
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 7471
Location: Netherlands

PostPosted: Sun Sep 27, 2020 8:40    Post subject: Reply with quote
You missed reading the forum guidelines:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

No mentioning of router model, no build number and posting in the wrong forum Sad

I will transfer this thread to the right forum Smile

_________________
Routers:Netgear R7800, R6400v1, R6400v2, Linksys EA8500, EA6900 (XvortexCFE), E2000 (converted WRT320N), WRT54GS v1.
WireGuard Documents & Guides:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327397
OpenVPN Documents & Guides: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327398
IPSET: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327261
Install guide R6400v2:http://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 4258
Location: UK, London, just across the river..

PostPosted: Sun Sep 27, 2020 10:08    Post subject: Reply with quote
as egc noted above, you've made a vital errors...
have a search, either in the forum or GGl with adding DDWRT at the ggl search...many threads on the Pi-Hole subject this days...same and same again and again...its, not that hard to find.... if you spend some quality time with coffee and reading Wink
step by step guides are somewhere there...
Good Luck

_________________
Atheros
TP-Link WR740Nv1 -----DD-WRT 45993 BS AP,NAT
TP-Link WR740Nv4 -----DD-WRT 44251 BS WAP/Switch
TP-Link WR1043NDv2 ---DD-WRT 46395 BS AP,NAT,AP Isolation,Ad-Block,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---DD-WRT 46166 BS AP,NAT,AD/Block,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---Gargoyle OS 1.12.0 AP,NAT,QoS,Quotas
Qualcomm/IPQ8065
Netgear R7800 -----DD-WRT 46259 BS AP,NAT,AD-Block,AP&Net Isolation,VLAN's,Firewall,Local DNS,DoT
Broadcom
Netgear R7000 -----DD-WRT 46259 BS AP,Wi-Fi OFF,NAT,AD-Block,Firewall,Local DNS,Forced DNS,VLAN's,DoT,VPN
-----------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 by mac913
LunchBoxSteve
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 21

PostPosted: Sun Sep 27, 2020 13:53    Post subject: Reply with quote
No offense but the forums are a mess of information and searching reveals way too many threads on the subject that are hard to follow which is why I asked if someone could give me a step by step or at least point me to one.

As for posting in the right thread, I assume I have it right when I do so but guess I didn't and for that I apologize.

Information on what I'm running this on 2x
Netgear R7000P's running R-43718.

Thanks.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 7471
Location: Netherlands

PostPosted: Sun Sep 27, 2020 15:18    Post subject: Reply with quote
Well I am far from an expert on this subject so can only share what I learned here in the forum regarding this subject.

What I learned is you can use two different approaches to use an external DNS server.
1. Use DNSMasq to set that DNS server on the clients so that the clients directly contact the PiHole as DNSserver.
Set Local DNS from the router itself to the PiHole and block port 53 on OUTPUT chain (so that the router cannot resolve DNS addresses and block port 53 on the FORWARD chain so that clients cannot resolve DNS with their own DNS server.

Of course on the blocked FORWARD chain make an exception for the IP address of the PiHole that should be allowed of course.

2. Redirect all queries to port 53 on the server (you canno tuse Forced DNS redirection as that would also redirect the pihole back to the server).
On the server set static DNS to the Pihole (make sure to enable "Ignore WAN DNS" as as to stop a leak.
Also on the server set local DNS to the Pihole
You can set a block rule for port 53 on the OUTPUT chain to be sure and also the block rule on the FORWARD chain for port 53 but both should not be necessary.

Now there are other possibilities to get DNS like DoH and DoT and also some DNS servers listen on port 5353

You can set block rules for port 5353 and 853 (DoT) on the FORWARD chain to stop this.

Stopping DoH is more difficult, you need a block list with DoH servers and use this to block on the FORWARD chain.
See: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=326658&postdays=0&postorder=asc&start=15

Like I said these are just my thoughts on the subject an probably not complete and/or possibly wrong on details
Regard this as a possible direction how to proceed Very Happy

_________________
Routers:Netgear R7800, R6400v1, R6400v2, Linksys EA8500, EA6900 (XvortexCFE), E2000 (converted WRT320N), WRT54GS v1.
WireGuard Documents & Guides:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327397
OpenVPN Documents & Guides: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327398
IPSET: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327261
Install guide R6400v2:http://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
LunchBoxSteve
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 21

PostPosted: Sun Sep 27, 2020 17:02    Post subject: Reply with quote
Thank you for this... How would I block output and input chains?
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 4258
Location: UK, London, just across the river..

PostPosted: Sun Sep 27, 2020 17:24    Post subject: Reply with quote
LunchBoxSteve wrote:
Thank you for this... How would I block output and input chains?


hmmm...i guess using iptables...


here is what i've found with a(pi-hole)search in the forum:

Use DNSMasq for DNS ticked
DHCP-Authoritative ticked
Recursive dns resolving unticked
Force dns redirection unticked

Dnsmasq advanced settings:

Dnsmasq enabled
local DNS enabled
No DNS Rebind enabled
Query DNS in Strict Order enabled
every thing else disabled in this section

Additional Dnsmasq Options
no-resolv
dhcp-option=6,192.168.49.1
server=192.168.49.1

lets presume your pi-hole has this address...

this suppose to be a DNSmasq way, egc gave you the directions for Iptables way, with bit of search you will find the rest, wiki also available very close the BOARD button Rolling Eyes

i guess learning is all about try n err here...as i don't have PI-Hassole Razz and never tried it, probb never will...its your duty to try n err / learn ... Twisted Evil

_________________
Atheros
TP-Link WR740Nv1 -----DD-WRT 45993 BS AP,NAT
TP-Link WR740Nv4 -----DD-WRT 44251 BS WAP/Switch
TP-Link WR1043NDv2 ---DD-WRT 46395 BS AP,NAT,AP Isolation,Ad-Block,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---DD-WRT 46166 BS AP,NAT,AD/Block,Firewall,Local DNS,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 ---Gargoyle OS 1.12.0 AP,NAT,QoS,Quotas
Qualcomm/IPQ8065
Netgear R7800 -----DD-WRT 46259 BS AP,NAT,AD-Block,AP&Net Isolation,VLAN's,Firewall,Local DNS,DoT
Broadcom
Netgear R7000 -----DD-WRT 46259 BS AP,Wi-Fi OFF,NAT,AD-Block,Firewall,Local DNS,Forced DNS,VLAN's,DoT,VPN
-----------------------------------------------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 by mac913
LunchBoxSteve
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 21

PostPosted: Sun Sep 27, 2020 18:02    Post subject: Reply with quote
What I'm trying to accomplish is blocking the domain names for Windows Update / Telemetry. When I feed this into my PiHole attached to my PFSense box and redirect all my DNS traffic through the PiHole it blocks perfectly on any of our PiHoles that I attach.

When I run the PiHole attached to a DD-WRT router I can get it to block all the domains from the web browser but Windows Updates / Telemetry is still getting through somehow.

We are trying to use it because these forced updates keep breaking stuff on a family members household system and we can't take them off the internet but need to stop the updates until we choose to do them so we had thought a Pihole would work because it's working for me on my setup.

(We just connect via VPN when we want to do updates to tunnel through the rules in the Firewall).
LunchBoxSteve
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 21

PostPosted: Sun Sep 27, 2020 18:09    Post subject: Reply with quote
Alozaros

So I tried this just now and it blocks microsoft.com but not www.microsoft.com in the web browser with these settings.

I have the microsoft.com in the block list as a test domain.

In my PFSense box with the same PiHole settings it blocks everything from microsoft.com with or without the WWW.
LunchBoxSteve
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 21

PostPosted: Sun Sep 27, 2020 18:47    Post subject: Reply with quote
Ok so I have it figured out...

It appears for it to work properly that the domains to be blocked in PiHole need to be added to the Regex section of the Block List and not the Domain section for it to block not only the domain.com but also the www.domain.com

For whatever reason PFSense seems to handle it's DNS requests differently than DD-WRT when pushing them through the PiHole which is what lead me to believe it was DD-WRT leaking DNS traffic.

When in fact it wasn't leaking traffic but handing the DNS traffic to the Pi Hole in different ways and so Pi Hole wasn't blocking it on some requests but was blocking it on other requests.

I should mention I'm using it with DD-WRT configured with Alozaros's mentioned information just above.

Anyway, all resolved now...

Thanks for everyone's help.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum