Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block internet access for client operating system's DNS over HTTPS

    Scheduled Pinned Locked Moved DHCP and DNS
    22 Posts 5 Posters 612 Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U Online
      Uglybrian
      last edited by

      I think you are on the right track with your With your DoH list on your firewall.
      Here are two list i use.

      https://raw.githubusercontent.com/crypt0rr/public-doh-servers/refs/heads/main/ipv4.list

      https://raw.githubusercontent.com/crypt0rr/public-doh-servers/refs/heads/main/ipv6.list

      Here is how i have mine set up. go to firewall/aliases/ URLs click add. In properties change the URL type to tables. Add your list.

      2025-11-03_07-06.png

      your update frequency will be stock at 128 days i set mine to 33. Save and then make your firewall rule.

      2025-11-03_07-12.png

      There are more DoH list on github that are more aggressive.

      1 Reply Last reply Reply Quote 0
      • R Offline
        richardsago
        last edited by

        Thank you @Gertjan for the reply. I will next try to solve the "Unbound python mode" for the next school break.

        Thank you @SteveITS for the reply. I was not sure about dns flushing and browser cache issues so what I did was to restart the client PC each time I tested a DoH setting change in the operating system, and pressing shift + [refresh] multiple times on the browser when I typed a URL. The client computer is using pfSense for DNS, DHCP, and internet connection. In case I misunderstood the question this is the services status on the pfSense dashboard:
        80c37773-52df-44ee-a0c9-b32a4dc8f59e-image.png

        Thank you @Uglybrian for the suggestion. I have replaced my manual list with your auto-populated list.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.