Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense router and Adguard Home ( DNS based ad block server) mini box

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 1.4k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Antibiotic
      last edited by Antibiotic

      Could you please suggest more reliable and convenient way to connect of this two for avoid lagging or latency increasing. How should better? or will work well in both situations. Adguard Home server will act as local DNS server for whole home network.

      1. pfSense (have 4th LAN and 1 WAN) router + switch + Adguard Home box ( DNS based ad block server) on this switch and other home network on this switch.
      2. pfSense (have 4th LAN and 1 WAN) router + Adguard Home box ( DNS based ad block server) in pfSense addtional LAN + switch to pfSense other LAN and other home network on this switch.

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      1 Reply Last reply Reply Quote 0
      • stephenw10S Online
        stephenw10 Netgate Administrator
        last edited by

        Unlikely to make any measurable difference.

        But setup #2 avoids any possibility of an asymmetric route if DNS requests are redirected to the adguard device.

        Steve

        A 2 Replies Last reply Reply Quote 0
        • A Offline
          Antibiotic @stephenw10
          last edited by

          @stephenw10 So, setup # 2 More preferable, is it correct? Just I'm in doubt because like understand AdguardHome in pfSense LAN will have different subnet from switch or for DNS server settings this is can be ignoring?

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          1 Reply Last reply Reply Quote 0
          • stephenw10S Online
            stephenw10 Netgate Administrator
            last edited by

            Yes, I would choose #2. You can have DNS servers in a different subnet, that's no problem.

            A 2 Replies Last reply Reply Quote 0
            • A Offline
              Antibiotic @stephenw10
              last edited by

              @stephenw10 Ok, thanks for assistance))))

              pfSense plus 24.11 on Topton mini PC
              CPU: Intel N100
              NIC: Intel i-226v 4 pcs
              RAM : 16 GB DDR5
              Disk: 128 GB NVMe
              Brgds, Archi

              1 Reply Last reply Reply Quote 0
              • A Offline
                Antibiotic @stephenw10
                last edited by Antibiotic

                @stephenw10 But with this connections type for traffic shaping wizard should choose multi wan wizard or dedicated wizard than?Have intel i226-v cards on all ethernets.

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • stephenw10S Online
                  stephenw10 Netgate Administrator
                  last edited by

                  You don't need shaping to/from the DNS server itself so you would only select the LAN to add shaper queues to if you need them.

                  A 1 Reply Last reply Reply Quote 0
                  • A Offline
                    Antibiotic @stephenw10
                    last edited by

                    @stephenw10 Well noted

                    pfSense plus 24.11 on Topton mini PC
                    CPU: Intel N100
                    NIC: Intel i-226v 4 pcs
                    RAM : 16 GB DDR5
                    Disk: 128 GB NVMe
                    Brgds, Archi

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      Antibiotic @stephenw10
                      last edited by

                      @stephenw10 In case of use pfBlockerNG on pfSense and AduardHome on separate box like a DNS server could be any conflicts or duplicate functions? Any profit or negative?

                      pfSense plus 24.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      provelsP 1 Reply Last reply Reply Quote 0
                      • stephenw10S Online
                        stephenw10 Netgate Administrator
                        last edited by

                        pfBlocker can load and block IP lists and also url/domian lists via DNS-BL. If you are filtering DNS with an external box I would not also use DNS-BL in pfBlocker. But DNS filtering does not block IP list in the firewall so that could still be done using pfBlocker.
                        Personally I would just use pfBlocker for both.

                        1 Reply Last reply Reply Quote 0
                        • provelsP Online
                          provels @Antibiotic
                          last edited by provels

                          @Antibiotic
                          I've used pfBlocker for years but I recently brought up Pi-Hole running on a tiny VM (1 proc, 1 GB, on my Windows server) for fun. The Pi forwards only to PFSense's Resolver, still running pfBlocker, and pfSense's DHCP issues the Pi as the only DNS to the local net. Works great! And I run all these lists on the Pi using only 30% of the memory. Plus, I can copy/paste this entire list into the interface at once, update, and done. Also, rate limits chatty hosts like my TV (like 1000+ hits/minute!). And the interface is a real treat and very intuitive. pfB can do much more (IP, country blocks) but the Pi interface is so darn pretty!

                          https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADhosts.txt
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Spam/hosts
                          https://v.firebog.net/hosts/static/w3kbl.txt
                          https://adaway.org/hosts.txt
                          https://v.firebog.net/hosts/AdguardDNS.txt
                          https://v.firebog.net/hosts/Admiral.txt
                          https://raw.githubusercontent.com/anudeepND/blacklist/master/adservers.txt
                          https://v.firebog.net/hosts/Easylist.txt
                          https://pgl.yoyo.org/adservers/serverlist.php?hostformat=hosts&showintro=0&mimetype=plaintext
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/UncheckyAds/hosts
                          https://raw.githubusercontent.com/bigdargon/hostsVN/master/hosts
                          https://v.firebog.net/hosts/Easyprivacy.txt
                          https://v.firebog.net/hosts/Prigent-Ads.txt
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.2o7Net/hosts
                          https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt
                          https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt
                          https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt
                          https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
                          https://v.firebog.net/hosts/Prigent-Crypto.txt
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Risk/hosts
                          https://bitbucket.org/ethanr/dns-blacklists/raw/8575c9f96e5b4a1308f2f12394abd86d0927a4a0/bad_lists/Mandiant_APT1_Report_Appendix_D.txt
                          https://phishing.army/download/phishing_army_blocklist_extended.txt
                          https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
                          https://v.firebog.net/hosts/RPiList-Malware.txt
                          https://v.firebog.net/hosts/RPiList-Phishing.txt
                          https://raw.githubusercontent.com/Spam404/lists/master/main-blacklist.txt
                          https://raw.githubusercontent.com/AssoEchap/stalkerware-indicators/master/generated/hosts
                          https://urlhaus.abuse.ch/downloads/hostfile/
                          https://zerodot1.gitlab.io/CoinBlockerLists/hosts_browser

                          https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADhosts.txt
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Spam/hosts
                          https://v.firebog.net/hosts/static/w3kbl.txt
                          https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt
                          https://someonewhocares.org/hosts/zero/hosts
                          https://raw.githubusercontent.com/VeleSila/yhosts/master/hosts
                          https://winhelp2002.mvps.org/hosts.txt
                          https://v.firebog.net/hosts/neohostsbasic.txt
                          https://raw.githubusercontent.com/RooneyMcNibNug/pihole-stuff/master/SNAFU.txt
                          https://paulgb.github.io/BarbBlock/blacklists/hosts-file.txt

                          https://adaway.org/hosts.txt
                          https://v.firebog.net/hosts/AdguardDNS.txt
                          https://v.firebog.net/hosts/Admiral.txt
                          https://raw.githubusercontent.com/anudeepND/blacklist/master/adservers.txt
                          https://v.firebog.net/hosts/Easylist.txt
                          https://pgl.yoyo.org/adservers/serverlist.php?hostformat=hosts&showintro=0&mimetype=plaintext
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/UncheckyAds/hosts
                          https://raw.githubusercontent.com/bigdargon/hostsVN/master/hosts
                          https://raw.githubusercontent.com/jdlingyu/ad-wars/master/hosts

                          https://v.firebog.net/hosts/Easyprivacy.txt
                          https://v.firebog.net/hosts/Prigent-Ads.txt
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.2o7Net/hosts
                          https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt
                          https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt
                          https://www.github.developerdan.com/hosts/lists/ads-and-tracking-extended.txt
                          https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/android-tracking.txt
                          https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/SmartTV.txt
                          https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/AmazonFireTV.txt
                          https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-blocklist.txt

                          https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt
                          https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
                          https://v.firebog.net/hosts/Prigent-Crypto.txt
                          https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Risk/hosts
                          https://bitbucket.org/ethanr/dns-blacklists/raw/8575c9f96e5b4a1308f2f12394abd86d0927a4a0/bad_lists/Mandiant_APT1_Report_Appendix_D.txt
                          https://phishing.army/download/phishing_army_blocklist_extended.txt
                          https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
                          https://v.firebog.net/hosts/RPiList-Malware.txt
                          https://v.firebog.net/hosts/RPiList-Phishing.txt
                          https://raw.githubusercontent.com/Spam404/lists/master/main-blacklist.txt
                          https://raw.githubusercontent.com/AssoEchap/stalkerware-indicators/master/generated/hosts
                          https://urlhaus.abuse.ch/downloads/hostfile/
                          https://malware-filter.gitlab.io/malware-filter/phishing-filter-hosts.txt
                          https://v.firebog.net/hosts/Prigent-Malware.txt

                          https://zerodot1.gitlab.io/CoinBlockerLists/hosts_browser

                          https://raw.githubusercontent.com/chadmayfield/my-pihole-blocklists/master/lists/pi_blocklist_porn_top1m.list
                          https://v.firebog.net/hosts/Prigent-Adult.txt

                          Got the list suggestions from here. I use the first 3.

                          Peder

                          MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                          BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                          1 Reply Last reply Reply Quote 1
                          • A Offline
                            Antibiotic
                            last edited by

                            Ok, thanks to all for answering

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.