this post was submitted on 04 Feb 2024
47 points (98.0% liked)

Selfhosted

40394 readers
608 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I have an asus router with a pi-hole on the network.

I was doing some work on my server and noticed that when pi-hole was down, I couldn't access the internet. I was looking for some ideas online how to deal with this, but they said to have a second pihole on the network in case one is offline. Is that the only way to do it? Is there any way to have the network go back to normal if the pihole is offline?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] -2 points 9 months ago (1 children)

If you're router has a failover DNS option, usually listed as DNS 2, I would set something like quad 9 as your backup DNS. Address is 9.9.9.9.

If you don't want to do that, then having a second instance of pihole running as the secondary DNS is pretty much your only good option

[–] AndiTails 7 points 9 months ago (2 children)

That's not how the two entries for DNS works. Devices will use both rather randomly, and therefore some requests will not be filtered.

The best way is to run two instances for redundancy.

[–] [email protected] -3 points 9 months ago (1 children)

Can you send me some more information on this because this is the first I've ever heard that it would not automatically pick the fastest closest and most responsive DNS system available.

No remote DNS server will ever be as fast as one that is local

[–] [email protected] 7 points 9 months ago

I tried this. Put a DNS override for Google.com for one but not the other Adguard instance. Then did a DNS lookup and the answer (ip) changed randomly form the correct one to the one I used for the override. I'm assuming the same goes for the scenario with the l public DNS as well. In any case, the response delay should be similar, since the local pi hole instance has to contact the upstream DNS server anyway.

[–] [email protected] -5 points 9 months ago (2 children)

Yeah, looks like you don't know what you're talking about.

The second ipv4 DNS address is for redundancy and every network connected system will use the first one as long as it responds.

It's perfectly fine to have a single pihole and use something like quad9 as a failover in the unlikely event that your pihole goes down unexpectedly.

[–] EncryptKeeper 6 points 9 months ago* (last edited 9 months ago) (1 children)

Actually they do know what they’re talking about. Configuring DHCP with multiple DNS servers isn’t for failover, it’s for redundancy. The result is ultimately operating system dependent, but modern Windows operating systems will query all configured DNS servers in parallel and will accept the first answer it receives. So if you configure your Pihole as one DNS server and a public DNS server as a second, a lot of your traffic will just bypass your Pihole ad filtering entirely.

[–] [email protected] -4 points 9 months ago (3 children)

Proof?

I read 15 different sites about DNS and not a one of them claimed anything like this. They universally all stated that your network attached devices would use the 1st one unless it didn't respond and only use the 2nd one if the 1st one did not.

So once again, I ask "Can you send me some more information on this" and not just claim it without any backup information?

I apologize if I am coming off rude, just my BS meter is getting close to the red zone and I would really appreciate some reliable evidence.

[–] EncryptKeeper 7 points 9 months ago

The best proof would be to just try it yourself and see what happens. Load up Wireshark, make a query, and look at your traffic. Because the problem is there isn’t a single technical article I can point you to that details exactly how DNS resolution works on every device running any given operating system. “Network attached devices” could be anything and so you can’t be certain exactly how each device will operate.

I’ll give you that in the case of Windows devices specifically, Microsoft isn’t good at keeping documentation up to date, and on older version of windows it used to work the way you describe. It would send the request to your first DNS server, wait one second for a response, and only if it didn’t get one would it move on to your next one. However in Windows 10 today if I edit my configuration so that I use a local DNS server located at 192.168.69.210 as my “Preferred” DNS server and 1.1.1.1 as my “Alternate” DNS server look what happens:

It sends the same request out to both without waiting and the response from Cloudflare actually comes in before the one from my local DNS server. So if this were a request for a blocked domain, the client would accept the response from Cloudflare because it was received first and so the request wouldn’t be blocked.

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago)

If what you said was true, my secondary Pi-hole wouldn’t have to respond to any queries. But it in fact gets quite a lot of them. As the other poster has said, it is about 80/20 for 1st and 2nd pihole. Sometimes the ratios are different, depending on the time of day (don’t ask me why….).

[–] [email protected] 1 points 9 months ago* (last edited 9 months ago)

On the left is the DNS server that DHCP sets first. On the right is one it sets second.

This is a mixed machine network (Windows, MacOS, iOS, Android etc).

My clients will mostly pick option number one, but as you can see it's not a guarantee at all.

EDIT. Since lemmy doesn't show kbin images attached to comments https://media.kbin.pieho.me/81/1e/811e8f6bf8aa5e8ea9219ff52d1e61aec8624107ffd11f2a13631d0a1ac29abc.jpg

[–] AndiTails 2 points 9 months ago (1 children)

Run two and check the logs. You'll see about 20% of your requests will log on the second instance. So currently, that's 20% of your DNS requests not being filtered.

You'll also find some devices just latch on the the second and never use the first - again, in your scenario, these are not being filtered.

[–] [email protected] 2 points 9 months ago

I can back this up with experience.

I'm actively running two piholes for years now. About 2/3rds of my traffic does go to the primary and some seem to 'lock on' to using just one, but most devices will swap between the two at their leisure.