3 ms·
I built my own router with a raspberry pi. I installed pi-hole and use that as a dns resolver. I then use an iptables rule to NAT / forward all dns traffic on p
by aronpye 6y ago
I built my own router with a raspberry pi. I installed pi-hole and use that as a dns resolver. I then use an iptables rule to NAT / forward all dns traffic on port 53 to the pi-hole resolver, similar to how ISPs often intercept dns requests. This prevents IOT devices from bypassing the dns server configured via my DHCP. Letting pi-hole block the requests helps prevent errors from dns request timeouts.
An additional benefit is that you get to log internet traffic and get shocked as you find out what your devices are really up to.
To block ads that are served over whitelisted / not blocked domains I’d need some kind of deep packet inspection. I’m not sure this kind of filtering even exists / would work as a lot of the ad traffic I see is served over https.
- chrisjc 6y agoIs there anything to stop devices from establishing a VPN connection? I imagine that would be the next logical step that device manufactures will go to to combat consumers setting up pi-holes.
- aronpye 6y agoNo, something that uses an encrypted tunnelling protocol like IPsec would hide its communications. You wouldn’t be able to spoof the server either due to IPsec’s authentication capabilities. You could stop the device from initiating a tunnel by blocking the appropriate ports and protocols. Although if I found out a device was going to these lengths and wasn’t open source, I don’t think I’d want it on my network.