bypass DNS for one device

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
jauch888888
DD-WRT User


Joined: 23 Apr 2020
Posts: 101

PostPosted: Wed Feb 14, 2024 1:47    Post subject: bypass DNS for one device Reply with quote
Hi,

Is it possible to bypass DNS for a particular device? I'm using dnscript, but on my pixel phone, I would like to use the private dns directly on the phone and not using the ones from dnscrypt proxy, is it possible?
thanks
Sponsor
mwchang
DD-WRT Guru


Joined: 26 Mar 2013
Posts: 1858
Location: Hung Hom, Hong Kong

PostPosted: Fri Feb 16, 2024 10:58    Post subject: Re: bypass DNS for one device Reply with quote
jauch888888 wrote:
Is it possible to bypass DNS for a particular device? I'm using dnscript, but on my pixel phone, I would like to use the private dns directly on the phone and not using the ones from dnscrypt proxy, is it possible?
thanks


pixel phone static ip dns - Google Search
https://www.google.com/search?q=pixel+phone+static+ip+dns

pixel phone static ip - Google Search
https://www.google.com/search?q=pixel+phone+static+ip

_________________
Router: Asus RT-N18U (rev. A1)

Drink, Blink, Stretch! Live long and prosper! May the Force and farces be with you!

Facebook: https://www.facebook.com/changmanwai
Website: https://sites.google.com/site/changmw
SETI@Home profile: http://setiathome.berkeley.edu/view_profile.php?userid=211832
GitHub: https://github.com/changmw/changmw
jauch888888
DD-WRT User


Joined: 23 Apr 2020
Posts: 101

PostPosted: Fri Feb 16, 2024 22:22    Post subject: Re: bypass DNS for one device Reply with quote
mwchang wrote:
jauch888888 wrote:
Is it possible to bypass DNS for a particular device? I'm using dnscript, but on my pixel phone, I would like to use the private dns directly on the phone and not using the ones from dnscrypt proxy, is it possible?
thanks


pixel phone static ip dns - Google Search
https://www.google.com/search?q=pixel+phone+static+ip+dns

pixel phone static ip - Google Search
https://www.google.com/search?q=pixel+phone+static+ip


thank you but I can't just add a private dns on my cell phone like cloudf;are or google. Cause I'm using dnsscripts on my router, so when I add a private dns on my cell, the wifi is disconnected.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12921
Location: Netherlands

PostPosted: Sat Feb 17, 2024 6:59    Post subject: Reply with quote
I do not think that the wifi will be disconnected when you set a private DNS on your phone.
Perhaps you mean that you do not have DNS resolution?

The use of Private DNS on your phone has no relation to what DNS the router is using (SmartDNs, DNSMasq etc).

However the router has settings to block the use of Private DNS, maybe you have this enabled?

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Sun Feb 25, 2024 6:58    Post subject: Reply with quote
Quote:

However the router has settings to block the use of Private DNS, maybe you have this enabled?



Where can I disable this?
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Sun Feb 25, 2024 7:54    Post subject: Reply with quote
enabling of Forced DNS, or Forced Dot option, omit the use of Private DNS, client side...(bsic setup page down at the bottom)
_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Sun Feb 25, 2024 9:40    Post subject: Reply with quote
Alozaros wrote:
enabling of Forced DNS, or Forced Dot option, omit the use of Private DNS, client side...(bsic setup page down at the bottom)


it's already set up, but if I configure a private DNS on my phone it doesn't work 🤔
lexridge
DD-WRT Guru


Joined: 07 Jun 2006
Posts: 1080
Location: WV, USA

PostPosted: Mon Feb 26, 2024 4:18    Post subject: Reply with quote
marcus83 wrote:
Alozaros wrote:
enabling of Forced DNS, or Forced Dot option, omit the use of Private DNS, client side...(bsic setup page down at the bottom)


it's already set up, but if I configure a private DNS on my phone it doesn't work 🤔


What is already set up? I believe the post states those two options must be turned off to allow a private DNS on your phone. Your reply is not at all clear on which position those switches are in.

_________________
Linksys EA8500 (Internet Gateway, AP/VAP) - DD-WRT r53562
Features in use: WDS-AP, Multiple VLANs, Samba, WireGuard, Entware: mqtt, mlocate
Wireless 5ghz only

Netgear R7800 (WDS-AP, WAP, VAP) - DD-WRT r55779
Features in use: multiple VLANs over single trunk port

Linksys EA8500 WDS Station x2 - DD-WRT r55799

Netgear R6400v2 WAP, VAP 2.4ghz only w/VLANs over single trunk port. DD-WRT r55779

OSes: Fedora 38, 9 RPis (2,3,4,5), 20 ESP8266s: Straight from Amiga to Linux in '94, never having owned a Windows PC.

Forum member #248
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Mon Feb 26, 2024 6:36    Post subject: Reply with quote
I use adguard-home and these 2 options are mandatory, but I wanted to know how to bypass a DNS to a single device
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3006
Location: Germany

PostPosted: Mon Feb 26, 2024 10:10    Post subject: Reply with quote
Force redirection means that all DNS queries are redirected to the router.

Is it possible to create a redirection rule via iptables with the exception of one ip address.

from my pi-hole sticky

## filter on br0 (usually includes LAN and WLAN)
iptables -t nat -I PREROUTING -i br0 ! -s 192.168.1.110 ! -d $(nvram get lan_ipaddr) -p tcp --dport 53 -j DNAT --to $(nvram get lan_ipaddr):53
iptables -t nat -I PREROUTING -i br0 ! -s 192.168.1.110 ! -d $(nvram get lan_ipaddr) -p udp --dport 53 -j DNAT --to $(nvram get lan_ipaddr):53

192.168.1.110 = IP address of the Pi-Hole = ip address you want to exclude

the redirection must of course be deactivated in the GUI

_________________
Quickstart guides:
use Pi-Hole as simple DNS-Server with DD-WRT
VLAN configuration via GUI - 1 CPU port
VLAN configuration via GUI - 2 CPU ports (R7800, EA8500 etc)

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 23.05.3 - Gateway
Qualcomm IPQ8065 - R7800 - DD-WRT - WAP
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Mon Feb 26, 2024 12:36    Post subject: Reply with quote
@marcus83 as you may guess very likely your phone private DNS is using port 443 HTTPS(DOH)...and those cannot be mitigated...as you see DDWRT has an option to capture and forward/redirect only those on port 53, as well port 853... Embarassed
So, your question is a victim in a lack of knowledge from your side....

To be precise not many users support/have experience with AD-Guard home...so any further advise regarding to this DNS platform need to be addressed to the developer that made the code for it and has a knowledge of its integration...

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Mon Feb 26, 2024 14:48    Post subject: Reply with quote
thanks for the replies, I forwarded my questions to the AGH github discussion.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12921
Location: Netherlands

PostPosted: Mon Feb 26, 2024 15:24    Post subject: Reply with quote
marcus83 wrote:
I use adguard-home and these 2 options are mandatory, but I wanted to know how to bypass a DNS to a single device


The above is simply nonsense Adguard home is a DNS server just like DNSmasg or SmartDNS or ..., none of those DNS servers really 'need' those settings to work.

Your problem is you deviate from default settings without sufficient knowledge.

Another example: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=336004, why do you think the default value of MTU is 1400? Why have you set it at 1500?

You are doing fairly complicated things which is fine of course and we encourage you to do so but my advice is to investigate some time to read up on the subjects Smile

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Mon Feb 26, 2024 15:36    Post subject: Reply with quote
egc wrote:
marcus83 wrote:
I use adguard-home and these 2 options are mandatory, but I wanted to know how to bypass a DNS to a single device


The above is simply nonsense Adguard home is a DNS server just like DNSmasg or SmartDNS or ..., none of those DNS servers really 'need' those settings to work.

Your problem is you deviate from default settings without sufficient knowledge.

Another example: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=336004, why do you think the default value of MTU is 1400? Why have you set it at 1500?

You are doing fairly complicated things which is fine of course and we encourage you to do so but my advice is to investigate some time to read up on the subjects Smile


I solved the MTU problem. but it's not clear, there are those who say one thing and those who say another...
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12921
Location: Netherlands

PostPosted: Mon Feb 26, 2024 15:55    Post subject: Reply with quote
marcus83 wrote:
egc wrote:
marcus83 wrote:
I use adguard-home and these 2 options are mandatory, but I wanted to know how to bypass a DNS to a single device


The above is simply nonsense Adguard home is a DNS server just like DNSmasg or SmartDNS or ..., none of those DNS servers really 'need' those settings to work.

Your problem is you deviate from default settings without sufficient knowledge.

Another example: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=336004, why do you think the default value of MTU is 1400? Why have you set it at 1500?

You are doing fairly complicated things which is fine of course and we encourage you to do so but my advice is to investigate some time to read up on the subjects Smile


I solved the MTU problem. but it's not clear, there are those who say one thing and those who say another...


But if you just use the default settings there was no problem to solve.
Why do you think default settings exist Wink

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum