› UKTH forums › 🛜 Wireless Routers & Modems › 💬 ASUS & Wireless › ASUS 87U with Pi-Hole DNS issues
- This topic has 22 replies, 2 voices, and was last updated 1 year, 9 months ago by
UK Sentinel.
-
AuthorPosts
-
July 24, 2023 at 7:59 am #26039
Hi, I’m new to this group and I am hoping that someone can resolve my problem. I have an Asus 87U behind my main router running a VPN client. This works great allowing me to send clients through the VPN or via WAN. I recently introduced a Raspberry Pi 4B model for ad blocking and have added this to my setup by setting it as LAN DNS in my ASUS router. All works okay except for my WAN clients are getting a UK IP but are using the DNS of the VPN which i didnt want. I have set WAN dns as Quad9 but they don’t seem to use that. I have also changed VPN client to strict, relaxed or exclusive but no joy. I have tried changing lots of different settings but it makes no difference. My WAN clients should be using Quad 9 as set on my main and ASUS router, so not sure what is occurring.
You need to login in order to vote
July 24, 2023 at 1:59 pm #26044Hi, is your ASUS 87U running stock firmware of ASUSWRT-Merlin ?
Edit: Apoligies, I just checked, did you realise the RT-AC87U is no longer supported by ASUS for firmware releases.
What is main router ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
July 25, 2023 at 6:54 am #26051Hi,
Yes, I am running Merlin firmware at 384.13_10 which is quite old but as you said it is not supported any longer. I may have to update my router to a newer model. Just thought I would be able to get this to work. I know the latest firmware has a tab for director.
You need to login in order to vote
July 25, 2023 at 7:44 am #26052DNS can be tricky.
on the 87U is VPN > Accept DNS Configuration set to ‘DISABLED’ as this then should just ignore DNS pushed by remote VPN server ? (if you older ASUSWRT-Merlin firmware version supports this option).
Just going through the basics, On your ASUS Router (VPN Server) is WAN DNS set to Quad9 and the LAN DNS to the Pi’s IP Address
i.e.
- Advanced Settings > WAN > WAN DNS Setting > ‘DNS set to Quad9’
- Advanced Settings > LAN > DHCP Server > ‘DNS set to Pi’s IP Address’
What DNS IP does the VPN clients end up using and are you using the guests wifi ?
I am thinking out loud but assume issue with rouge DNS has happened since introduction of Pi’s. maybe a idea to move the Pi’s to the ASUS’s DMZ.
This may make the architecture simpler especially and you main router (upstream) should still provide a proper firewall type service.
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
July 25, 2023 at 6:45 pm #26056Hi,
I’ve changed the accept DNS to disabled but it made no difference. I do have Wan DNS set to Quad9 on Asus router and the main router. Lan on Asus is set to Pi-hole and it is blocking ads.
My VPN is set to Luxembourg and when I do a DNS leak test on a WAN client it is using the DNS of VPN which is also Luxembourg.
Aside from this I am running Unbound with Pi-hole but that hasn’t caused any issues that I know of.
You need to login in order to vote
July 25, 2023 at 6:53 pm #26059Interesting, was there the VPN / DNS issue before you installed the Pi-hole ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
July 25, 2023 at 7:11 pm #26060July 25, 2023 at 7:14 pm #26061If I remove the Pi-hole from the situation, then the wan clients start using Quad9. Ummm must be something in the Pi-hole setup.
You need to login in order to vote
July 25, 2023 at 7:17 pm #26062Are you able to try the Pi-hole in a DMZ, just for testing purposes ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
July 25, 2023 at 7:24 pm #26063July 25, 2023 at 7:26 pm #26064July 25, 2023 at 9:10 pm #26065give the router and vpn clients a reboot and see if that does anything
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
July 25, 2023 at 10:14 pm #26069No difference after reboot. Not sure why it’s forcing wan clients to use dns of vpn. Tried loads of different settings but to no avail.
You need to login in order to vote
July 26, 2023 at 6:04 am #26070It is odd, are you using the guest wifi ?
Alas not familiar with Pi-Hole configuration but maybe is the Pi-Hole also offering DHCP service for LAN clients on same IP subnet ?
In a completely sane world, madness is the only freedom (J.G.Ballard).
You need to login in order to vote
July 26, 2023 at 7:12 am #26071 -
AuthorPosts
- You must be logged in to reply to this topic.