Live data from Hacker News

AdGuard Home: Network-wide ad- and tracker-blocking DNS server

github.com

111–120 of 258 posts

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#111
post #96

With a self-hosted DNS internally, how do you handle fallback? For example if the box with Adguard Home or pihole crashes, can you configure your router or your devices in a way that would instead go to say cloudflare or google DNS?

I dealt with a less-than-ideally reliable pihole by configuring the pihole as the primary DNS, and an external DNS server as the secondary (most devices accept 2 or more IPs for DNS).

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#112
post #20

Earlier quoted context omitted.

I don't get this comment. It is basically the same kind of tool as the Pihole only much easier to install and maintain. (It's a single go binary) Isn't this a popular class of software?

It is not a popular class of software to the masses, it is a popular class of software to a niche audience. I don't share as pessimistic attitude as OP though. I'm pretty sure the audience is in the tens of thousands!

What's funny is that I was once extremely optimistic about the potential for such a device, to the extent of having sold and delivered a few million in product.

Hard experience taught us that churn is just crazy high, no matter how compatible it easy to use you make it. Getting tens of thousands of stars is not the hard part because it's such an easy concept to like. But I would be surprised there are more than let's say ten thousand piholes in active use.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#113
post #96

With a self-hosted DNS internally, how do you handle fallback? For example if the box with Adguard Home or pihole crashes, can you configure your router or your devices in a way that would instead go to say cloudflare or google DNS?

most routers let you set a primary dns server and a secondary. just set the secondary to something like google or cloud flare dns.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#114
post #3

I ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This is…

I setup Pi Hole with tailscale on an inexpensive cloud server. It is configured to serve DNS requests over the tailscale interface. Also added tailscale IP address of the Pi Hole to tailscale DNS override to ensure that all devices on the tailnet use it without any additional reconfiguration. For redundancy, I have multiple DNS servers on my tailnet. Family and friends can use it without worrying about portability and be protected at all times, especially on cell networks.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#115

Earlier quoted context omitted.

I'm curious what issues you ran into with Pi-hole? I was running my instance for years without a single hiccup. I ended up moving to AdGuard Home about a year ago though because I wanted to run it on my OPNSense box. I have an automatic WireGuard VPN set up on my devices to VPN into my home network when I'm not connected to my SSID, so my local DNS still works remotely.

Too many false positives with Pi-Hole. I never felt comfortable putting my partner on the same vlan that it was serving DNS requests for fear that something would break for them when I was out of town, unable to get into the pi-hole and sort out the issue. I also had my banking app stop working one day. Never could get it working. Eventually I just got fed up with having to switch vlans or to mobile data to check my…

Couldn't you just monitor the query log and whitelist domains that were false positives?

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#116

Earlier quoted context omitted.

Except all of these third party VPN and DNS type services are literally NSA honeypots and privacy nightmares. I get that you have to do DNS lookups somewhere, but I'm not going to make it ridiculously trivial for a bad actor to scoop up all that data conveniently in a central location.

Mullvad is an NSA honeypot? Got any sources on that?

Yes, let me just get my tin foil roll, stand up in front of the mirror,…

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#117

Earlier quoted context omitted.

I'm curious what issues you ran into with Pi-hole? I was running my instance for years without a single hiccup. I ended up moving to AdGuard Home about a year ago though because I wanted to run it on my OPNSense box. I have an automatic WireGuard VPN set up on my devices to VPN into my home network when I'm not connected to my SSID, so my local DNS still works remotely.

Is there any config update to the wire guard profile needed to ensure that DNS request traffic is routed through pi-hole?

I use the bare WireGuard app on iOS. I just statically set the DNS server to the AdGuard Home IP (or Pi-hole IP) on my local network in the app.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#118
post #50

Earlier quoted context omitted.

Haven’t used NextDNS but have used PiHole and currently running AdGuard Home. But if you are paying $20/year just for DNS encryption/blocking, you may consider upgrading to Mullvad which gives you DNS Ad blocking but also IP anonymity, tunneling etc.

Except all of these third party VPN and DNS type services are literally NSA honeypots and privacy nightmares. I get that you have to do DNS lookups somewhere, but I'm not going to make it ridiculously trivial for a bad actor to scoop up all that data conveniently in a central location.

>> consider upgrading to Mullvad

> all of these third party VPN and DNS type services are literally NSA honeypots

https://mullvad.net/en/help/privacy-policy

It is up to you to decide what you believe, but Mullvad is a swiss company that does not ask for your personal information for signup and even allows payment in cash. You hurt your own credibility each time you make an unqualified claim without looking into it.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#119
post #3

I ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This is…

I setup Pi Hole with tailscale on an inexpensive cloud server. It is configured to serve DNS requests over the tailscale interface. Also added tailscale IP address of the Pi Hole to tailscale DNS override to ensure that all devices on the tailnet use it without any additional reconfiguration. For redundancy, I have multiple DNS servers on my tailnet. Family and friends can use it without worrying about portability an…

Tried this. Latency of DNS so critical, wasn't loving the self host option. Plus Tailscale wasn't quite reliable enough for all DNS traffic outside the house.

I ended up with Pi-Hole on local network (manual DNS tied to Wifi SSID), NextDNS as default/fallback on other networks.

Re: AdGuard Home: Network-wide ad- and tracker-blocking DNS server

#120
post #96

With a self-hosted DNS internally, how do you handle fallback? For example if the box with Adguard Home or pihole crashes, can you configure your router or your devices in a way that would instead go to say cloudflare or google DNS?

most routers let you set a primary dns server and a secondary. just set the secondary to something like google or cloud flare dns.

I believe this only works if your ad blocking DNS is configured to return 0.0.0.0 for all blocked domains rather than NXDOMAIN, since then services might try using the secondary DNS instead and that would result in nothing getting blocked. Ideally your secondary DNS should be a copy of the primary.
Post reply on HN