[GUIDE-UPDATED] AdGuard Home on DD-WRT

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Goto page Previous  1, 2, 3 ... 12, 13, 14
Author Message
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1958

PostPosted: Mon Feb 26, 2024 21:42    Post subject: Reply with quote
I think there are a few misunderstandings. Explain to us what happens when you un-tick "use DNSMasq for DNS", as advised in the guide. Does it not disable advertising router's IP for DNS to the LAN? Please explain fully, concisely, and show us without a shadow of a doubt what it does, please. K,thanks.
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
Sponsor
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Tue Feb 27, 2024 3:53    Post subject: Reply with quote
guys, the situation is this:

if I use the "use DNSMasq for DNS" option I have many problems, including not entering the AGH GUI, and on many devices, it gives me a network configuration error (dhcp) so I had to deselect it, and everything started working again...
so since I'm not an expert I ask you if you have time, to try to do a test using AGH with DNSmasq and the related configurations.
following this guide everything works apart from the error of option 6, which I then removed from the configurations, everything else is ok.

PS.
sorry for my English...
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3005
Location: Germany

PostPosted: Tue Feb 27, 2024 12:19    Post subject: Reply with quote
If you use dnsmasq as a proxy then there is no individual client sorting in AGH.
AGH only sees the router as a client.

Think carefully about whether you want this.
I won't go to the trouble of describing how to configure it if the configuration is ultimately undesirable.

_________________
Quickstart guides:
use Pi-Hole as simple DNS-Server with DD-WRT
VLAN configuration via GUI - 1 CPU port
VLAN configuration via GUI - 2 CPU ports (R7800, EA8500 etc)

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 23.05.3 - Gateway
Qualcomm IPQ8065 - R7800 - DD-WRT - WAP
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1958

PostPosted: Tue Feb 27, 2024 18:13    Post subject: Reply with quote
Didn't think anyone would answer my question(s), at least not directly.

https://github.com/mirror/dd-wrt/blob/master/src/router/kromo/dd-wrt/index.asp#L222

https://github.com/mirror/dd-wrt/blob/master/src/router/httpd/visuals/dd-wrt.c#L1183

https://github.com/mirror/dd-wrt/blob/master/src/router/services/services/dnsmasq.c#L793

https://github.com/mirror/dd-wrt/blob/master/src/router/libutils/libutils/bcmutils.c#L622

If you untick "use dnsmasq for DNS" per the guide, it will not advertise the router's LAN IP as DNS resolver, hence reasoning for adding no-resolv and dhcp option to additional configs to point to AGH. Leaving it ticked will enable dnsmasq proxy as resolver and circumvent AGH.

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
marcus83
DD-WRT User


Joined: 04 Jan 2024
Posts: 229

PostPosted: Wed Feb 28, 2024 6:56    Post subject: Reply with quote
until someone makes a guide like this with using DNSMasq and AGH, I won't use it, so for now it's fine.

we can end this "dispute" since it is not relevant to the thread.

thanks anyway for the replies.
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Wed Feb 28, 2024 7:54    Post subject: Reply with quote
You can still use AGH and DNSmasq...just use the correct setup...
As it was noted many times..(and one reason for me to abandon the thread)
-there must be some tolerance from AGH side in relation of DHCP and DNS..
-using https for AGH GUI is a must...(i know its an optional, but its a must)
-there is this note of a doubt, as when AGH takes over the router services ...we don't know, what
could be the communication behind...and the robustness of the service...(in terms of DDoS and other attacks) as, more new foreign services are introduced to DDWRT more attack vectors...
I don't see any reason to disable DNSmasq...
-you can stop its cache (so, no caching, no cache poisoning)
-you can disable its other futures like query in strict order, DNSSEC and other options, you can even disable DHCP and rely on upstream DHCP server/forwarder and ect...
-DNSmasq and its DNS encrypted solutions that i used / tested.. all work ok with DNSmasq as a forwarder...and even caching works...!!
The only advantage i see of AGH is QUIC and that is all..to me it doesn't ring the bell..and i don't need a API/GUI for it...if you really need a sophisticated DNS resolving with beautiful graph's and GUI, than Pi hole for DNS is the way...good read and links in the forum thanks to ho1Aetoo...but than again more external stuff around, more fiddling...so, simplicity ...sometimes wins... Laughing

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
blaser
DD-WRT Guru


Joined: 16 Jul 2006
Posts: 525

PostPosted: Tue Mar 05, 2024 18:10    Post subject: Reply with quote
You mentioned on the top to add this line
dhcp-option=6,Router-IP

shouldn't it be:
dhcp-option=br0,6,Router-IP

I keep getting error messages:

Ignoring duplicate dhcp-option 6

_________________
Netgear R9000 main router
RAX80 as AP
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1958

PostPosted: Tue Mar 05, 2024 18:31    Post subject: Reply with quote
Amplifying information regarding contents of resolv.conf, resolv.dnsmasq, and dnsmasq.conf, etc. and configuration screenshots would help us determine the cause of the message.
_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
blaser
DD-WRT Guru


Joined: 16 Jul 2006
Posts: 525

PostPosted: Wed Mar 06, 2024 19:55    Post subject: Reply with quote
after changing it to
dhcp-option=br0,6,192.168.1.1

few problems were solved:
1) no more errors in the messages file.
2) it uses only the Upstream DNS servers configured and not my provider dns in parallel

_________________
Netgear R9000 main router
RAX80 as AP
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3005
Location: Germany

PostPosted: Wed Mar 06, 2024 20:03    Post subject: Reply with quote
Just read what I wrote two pages ago.

It still applies and reducing the entry to just br0 doesn't make it any better.

_________________
Quickstart guides:
use Pi-Hole as simple DNS-Server with DD-WRT
VLAN configuration via GUI - 1 CPU port
VLAN configuration via GUI - 2 CPU ports (R7800, EA8500 etc)

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 23.05.3 - Gateway
Qualcomm IPQ8065 - R7800 - DD-WRT - WAP
blaser
DD-WRT Guru


Joined: 16 Jul 2006
Posts: 525

PostPosted: Fri Mar 08, 2024 17:30    Post subject: Reply with quote
you are correct, I removed that entry completely and it is working good
_________________
Netgear R9000 main router
RAX80 as AP
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Tue Mar 12, 2024 22:10    Post subject: Reply with quote
well.... I just checked my DNScrypt proxy v2 config and it turned out, it does support QUIC.. support has been added not long ago...

but i never had any interest using it....now this is intriguing... Laughing

# Version 2.1.2
- Support for DoH over HTTP/3 (DoH3, HTTP over QUIC) has been added.

current version is Version 2.1.5 Razz ---> I'll have a QUIC look when i can Cool Very Happy

if the QUIC was the holly grall on this thread...

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Goto page Previous  1, 2, 3 ... 12, 13, 14 Display posts from previous:    Page 14 of 14
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum