Live data from Hacker News

Setting Up 1.1.1.1 for Families on a Pi-Hole

uglyduck.ca

11–20 of 82 posts

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#12
post #7

any ideas why 1.1.1.2 doesn't support tls?

It does. If you’re having issues, submit a support ticket.

It's not supported.

https://community.cloudflare.com/t/community-tip-best-practi...

> Does 1.1.1.1 for Families support DNS over TLS?

No. But our team is working on it.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#13

I’d urge everyone to run a dns bench tool at home. Cloudflare isn’t always the right choice and for some ISPs with routing issues it can sometimes be a bad choice.

I'd like use self-hosted dnscrypt-proxy, point pi-hole's upstream to it.

Then dnscrypt-proxy will choose the servers that has lowest RTT and meet your requirement ( if DNSSEC, no log, family filter available) for you.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#14
post #12

Earlier quoted context omitted.

It does. If you’re having issues, submit a support ticket.

It's not supported. https://community.cloudflare.com/t/community-tip-best-practi... > Does 1.1.1.1 for Families support DNS over TLS? No. But our team is working on it.

For those playing at home you can specify tls://security.cloudflare-dns.com instead

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#15
post #13

I’d urge everyone to run a dns bench tool at home. Cloudflare isn’t always the right choice and for some ISPs with routing issues it can sometimes be a bad choice.

I'd like use self-hosted dnscrypt-proxy, point pi-hole's upstream to it. Then dnscrypt-proxy will choose the servers that has lowest RTT and meet your requirement ( if DNSSEC, no log, family filter available) for you.

I even use it with blocklist and allowlist. No need for Pi-Hole, if you don't mind editing the lists directly.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#17

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

Control or monitor?

I'm pretty sure I don't want my kids around 4chan and/or kiwifarm till they're much older .....

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#18

why? arent we already using pi-hole for blocking all the stuff? that said, i have a query about a simple way to force all dns in a local network to pass through pi-hole. i only have access to the iSP router and pi-hole and cannot use third party router

Your router must support outbound NAT in order to force all connections on a specified port to a specified host. If your router doesn't have that feature, there's no way to do it.

What would that feature be listed as on the back of the box/spec sheet?

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#19
post #18

Earlier quoted context omitted.

Your router must support outbound NAT in order to force all connections on a specified port to a specified host. If your router doesn't have that feature, there's no way to do it.

What would that feature be listed as on the back of the box/spec sheet?

It's extremely unlikely that any consumer router would support it.

If you really want to force clients on your LAN to always use a specified DNS server you're looking at a more enterprise-y router solution, probably something running pfSense or OPNsense.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#20

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

The DNS approach helps more for malware than it does for adult content and the like.

Twitter, Reddit, Tumblr, Google/Bing image search etc all have adult content easily within reach and DNS can't do anything about that.

It doesn't make sense on a technical level so it doesn't even matter if it makes sense on a philosophical level.

Post reply on HN