4 ms·
I've been considering setting up pihole on my home server for a while but I've always been worried that it would break a website for a non-technical family memb
by DFXLuna 8y ago
I've been considering setting up pihole on my home server for a while but I've always been worried that it would break a website for a non-technical family member while I wasn't there to fix it. How has your experience with website breakage been?
Also, how has your experience with wire guard been? I've been using my vpn's default client on all my individual devices out of convenience but after looking at the wire guard website I can see the appeal.
- Fnoord 8y agoMy partner sometimes has a website which breaks, especially when she's shopping online. Which you could consider a Good Thing. For me, the website which breaks is AliExpress. Specifically, the pictures don't load. Quad9 by default also blocks porn websites. For me, that's intentional, but YMMV. My experience with WireGuard has been fantastic. The configuration is straightforward (way less complex than OpenVPN), wg-quick(8) is ace, the macOS and Android UIs work very well. The performance is great (both throughput and latency, even of the userspace ports). You only need very minimal, basic knowledge about networking and public key cryptography. I got some minor complaints. For example the VPN is gone on Android when the app gets updated, and there's no official Windows client (though I don't use Windows right now). The EdgeOS port is sometimes out-of-date but its made by a 3rd party. And, compared to ZeroTier (where I was coming from) I miss out on a nice website configuration, but I get back a CLI one.
- vvanders 8y agoThe only site I've seen break was Burrow ironically enough, couldn't get through the checkout flow which is pretty darn stupid for a purchased product. Our solution is simple, we've got two SSIDs, one w/ PH, one without. They route to separate VLANs and each VLAN uses a different gateway+DHCP with pihole or standard DNS. Fixing a website that doesn't work is simple as hopping over on another SSID. We're using UniFi gear for the wifi, they support 4 SSIDs(8 if you split 2.4/5Ghz) per access point and USG made it trivial to setup multiple gateways(now on pfSense but that's a whole nother discussion).
- michaelmrose 8y agoRegarding the web, browser based blocking still makes more sense. If I have 2 tabs one which works with adblock and one which does not I can simply click an icon to enable ads on the one. Changing networks seems like a pain in the neck.
- vvanders 8y agoOn the flip side I've got 4 different devices across 3 operating systems, but putting it at the DNS layer it just works. FWIW I've been running pihole for almost a year, aside from the issue with Burrow and some social media redirect links used to track(that I want to block) I've not had any other false positives.
- michaelmrose 8y agoFirefox + ublock origin works on mac/windows/linux/android/bsd/some more unusual OS On almost any machine you could have save for ios.
- vvanders 8y agoYeah, and as much as I love Firefox, the android implementation just isn't up to the level to where I can use it as a daily driver. I've got nothing against browser blockers, I just prefer something that works in a unified way as a network policy.
- eropple 8y agoWhat's not up to par for you? Before I went back to iOS (where I use 1Blocker as a content blocker for Safari), Firefox for Android plus uBlock Origin did pretty well for me.
- dfxm12 8y agoI think pihole makes it reasonably easy to disable for some amount of time or until you switch it back on. I know "reasonable" has different meanings to different people though. For example, I don't think changing networks is a pain in the neck. It's just 3 clicks on my android phone or 2 on Windows 10. This is compared to 3 clicks to turn off a browser based ad blocker.