<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Get all DNS traffic routed through pi-hole and block all other DNS queries]]></title><description><![CDATA[<p dir="auto">I am trying to get all LAN DNS traffic routed through a raspberry pihole. I have both the netgate appliance and pihole sending logs to splunk and I can see that LAN DNS queries are directed to the gateway BUT there are no queries coming from my pihole and all the DNS traffic seems to be going out the WAN interface (challenge #1).</p>
<p dir="auto">I created a FW filter to attempt to block all 'unauthorized' outbound DNS queries but the rule for the WAN doesn't seem to do anything. I would like all DNS queries to only be allowed to the Internet from the pihole (challenge #2). This seems like a straightforward use case and I am probably missing something easy here...any guidance is appreciated, thanks!</p>
]]></description><link>https://forum.netgate.com/topic/147803/get-all-dns-traffic-routed-through-pi-hole-and-block-all-other-dns-queries</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 21:11:35 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/147803.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 01 Nov 2019 11:01:37 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Get all DNS traffic routed through pi-hole and block all other DNS queries on Sat, 02 Nov 2019 11:39:50 GMT]]></title><description><![CDATA[<p dir="auto">Thanks! I followed your second recommendation and just put the resolver in forwarding mode as that seemed the easiest and is working as expected!</p>
]]></description><link>https://forum.netgate.com/post/873777</link><guid isPermaLink="true">https://forum.netgate.com/post/873777</guid><dc:creator><![CDATA[johnny21]]></dc:creator><pubDate>Sat, 02 Nov 2019 11:39:50 GMT</pubDate></item><item><title><![CDATA[Reply to Get all DNS traffic routed through pi-hole and block all other DNS queries on Fri, 01 Nov 2019 14:05:21 GMT]]></title><description><![CDATA[<p dir="auto">Disable DNS Resolver</p>
<p dir="auto">Enable DNS Forwarder</p>
<p dir="auto">Edit <strong>System - General Setup - DNS Server Settings</strong> so that it only has the IP address of your pihole</p>
<p dir="auto">Redirect all LAN-based DNS requests to pfSense:</p>
<p dir="auto">https://doc.pfsense.org/index.php/Redirecting_all_DNS_Requests_to_pfSense</p>
<p dir="auto">You could also keep using DNS Resolver instead of DNS Forwarder, but select the option to run it in forwarding mode.</p>
<p dir="auto">You put firewall rules on the interface that the traffic enters, not exits, so your DNS rules on WAN are useless.</p>
]]></description><link>https://forum.netgate.com/post/873654</link><guid isPermaLink="true">https://forum.netgate.com/post/873654</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Fri, 01 Nov 2019 14:05:21 GMT</pubDate></item></channel></rss>