Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WireGuard Clients not obeying specified DNS nameservers

    Scheduled Pinned Locked Moved WireGuard
    4 Posts 2 Posters 568 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      tibere86
      last edited by

      I have my Pihole instance identified (10.1.1.10) as the DNS nameserver in my client configs but clients do not use it. What am I missing? Under my WireGuard rule tab, I have made an allow all rule which should allow access to my LAN where my Pihole resides.

      M 1 Reply Last reply Reply Quote 0
      • M Offline
        michmoor LAYER 8 Rebel Alliance @tibere86
        last edited by

        @tibere86 Right off the top of my head, are clients configured for DoH or DoT. If so they are bypassing configured DNS

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        T 1 Reply Last reply Reply Quote 1
        • T Offline
          tibere86 @michmoor
          last edited by

          @michmoor - Hmmm. I'll try adding a port 53 redirect rule followed by DoH/DoT IP block rule and see if that helps.

          M 1 Reply Last reply Reply Quote 0
          • M Offline
            michmoor LAYER 8 Rebel Alliance @tibere86
            last edited by

            @tibere86 that doesnt help if they are using DoH which works over 443. Also DoT works over port 853 which is easier to block.

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.