Unbound Makes Pi-hole WAY Better (and more private) | Unbound + Pi-hole Setup Tutorial

Поделиться
HTML-код
  • Опубликовано: 18 сен 2024

Комментарии • 46

  • @QuikTechSolutions
    @QuikTechSolutions Месяц назад +5

    Awesome video Frank. I now have a clearer understanding about what Unbound actually is. Never really fully understood it. But now thanks to you I do! Have a great day.

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад +1

      Thanks, Tony! I'm glad it helped - I've used it for a while (pfSense uses it by default) and I've had nothing but great experiences with it!

  • @vitorbritesvitor903
    @vitorbritesvitor903 Месяц назад +1

    Great video and I've installed and uninstalled pihole and unbound from Casaos a thousand times because it never worked, I always thought that pihole had to have one IP and unbound another IP but no one ever said that. First video that gives a different IP for each one, I'll test it.

  • @TechMeOut5
    @TechMeOut5 Месяц назад

    Excellent video Frank! This is really taking DNS based privacy to the next level.

  • @reyskidude
    @reyskidude Месяц назад +1

    another way to check is to run an online dns leak test... if unbound is working, it should report your own IP address as the DNS

  • @CedroCron
    @CedroCron Месяц назад

    Another great video Frank, thank you!

  • @TazzSmk
    @TazzSmk Месяц назад

    nice!
    I wonder, how would you configure redundant setup with such NAS, plus opnsense/pfsense?
    I think unbound is on by default on opnsense/pfsense itself, so just create another pihole instance on another device and point it there?
    or would it make more sense to configure both pihole instances to point on both unbound instances?

  • @wojtek-33
    @wojtek-33 Месяц назад +1

    Just a couple things not mentioned. If you using pfsense or opnsense, you can just configure Unbound on your router. And you should never run one instance of pihole. Always run two and the second one should be on another device, like a raspberry pi or in an lxc in proxmox. Setting up only one on Synology, if you reboot your synology or a network issue, then your whole network loses internet access.

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад +2

      Agreed - I mentioned the redundancy at the end of the video. The only disclaimer I'd add to the pfSense or OPNsense setup is you need to point Pi-hole to it directly so it's best to modify DHCP to point directly to the DNS servers rather than modifying the pfSense/OPNsense DNS servers.

    • @wojtek-33
      @wojtek-33 Месяц назад

      @@WunderTechTutorials Sorry, my bad, I watched most of the video. Should have stayed to the end :)

    • @petermarin
      @petermarin Месяц назад

      @@WunderTechTutorialsI love the way your explain things. Can you do a video on pfSense/ OPNsense and firewalls?

  • @reyskidude
    @reyskidude Месяц назад

    also, there will be sites or devices that uses hardcoded DNS... you can monitor this by setting up firewall rules on your router (mine's Synology) to deny traffic to Google DNS on port 53 and see the hits pile up over time... to counter this, first setup an allow rule for your pihole/unbound servers to port 53, then setup a deny rule below to all traffic to port 53... at this moment, I see 14% of hits are denied DNS traffic to Google

  • @ronald0122
    @ronald0122 Месяц назад +2

    i need unbound with adguard home. can't make it work

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад

      The process should be the same, but you'd have to modify the upstream DNS server to be the Unbound IP.

  • @kevinhughes9801
    @kevinhughes9801 Месяц назад

    Loved this thanks

  • @bradvosburg4972
    @bradvosburg4972 26 дней назад

    "Error response from daemon: Bind mount failed"😥 my Synology volume is "Volume 1"....so I changed compose file to reflect that. Tried "Volume 1" and Volume1" and the lowercase variants of those. Error suggests it a path problem but don't know how to resolve it.

    • @WunderTechTutorials
      @WunderTechTutorials  25 дней назад

      Bind mount fail would definitely be the volume mount. What is the full path you're using?

  • @solodagci
    @solodagci Месяц назад

    I wish you also did a tutorial on Raspberry Pi (not on docker)

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад +1

      Article and video here: www.wundertech.net/use-unbound-to-enhance-the-privacy-of-pi-hole-on-a-raspberry-pi/

    • @solodagci
      @solodagci Месяц назад

      @@WunderTechTutorials You sir, earned a sub.

  • @EddieBogart
    @EddieBogart Месяц назад

    Frank, would it even be more private or secure by adding Stubby to the mix?

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад

      I don't know much about stubby unfortunately, but I'll look into it! Thanks for the suggestion!

  • @lilchinito00
    @lilchinito00 7 дней назад

    @WunderTech So I'm trying to understand this setup but it looks like to me this is installing both pihole and unbound. If I already have pihole installed and working; what am I exactly needing to add to get unbound to work properly with what I have already with Pihole?

    • @WunderTechTutorials
      @WunderTechTutorials  6 дней назад

      That's correct - the second block that has the Unbound information is what ultimately creates the Unbound container, but there may be a few other minor modifications you have to make if you compare the docker compose file in this video to the one you're using.

    • @lilchinito00
      @lilchinito00 6 дней назад

      @@WunderTechTutorials I went ahead and just reinstalled it the way you had it but nslookup isn't working as it keeps failing but when I go into pihole and look at the logs it does show Unbound is catching them with an OK. The replies on the other hand is stating SERVFAIL. Any idea what I could of done wrong?

    • @WunderTechTutorials
      @WunderTechTutorials  6 дней назад

      @@lilchinito00 The only thing I could guess is the nslookup command is using the wrong port or something if the queries are actually going through on Pi-hole.

    • @lilchinito00
      @lilchinito00 5 дней назад

      @@WunderTechTutorials fixed the issue. Seems like Unbound was attempting to resolve queries using IPv6. I had to disable it for it to start working strictly with ipv4. Hopefully its meant to do that but i now no longer get a SERVFAIL. Wanted to mention it here just incase someone else may have this particular issue.

  • @sgabriel5299
    @sgabriel5299 Месяц назад

    Will the NAS still use the .direct QuickConnect connection with unbound and pihole? or will it use synology's relay server?

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад

      If you mean that you'd manually configure the DNS server on the NAS to the bridge interface, it should use it no matter how you connect, but keep in mind that's the NAS only.

  • @mattcero1
    @mattcero1 9 дней назад

    Anyone know how I can get my Pihole time correct? I'm running a stratum 1 time server on the same network Pihole is on. There's nothing in the GUI and my Pihole time seems to be GMT and not local. Thank you.

    • @WunderTechTutorials
      @WunderTechTutorials  8 дней назад +1

      I believe there is a "TZ" parameter you can use in the Docker Compose file.

    • @mattcero1
      @mattcero1 8 дней назад

      @@WunderTechTutorials I figured it out and you simply secure. Shell into the command line and run set up.

  • @drevorazer
    @drevorazer Месяц назад

    Thanks for your video. Does this procedure work with link aggregation on the Synology NAS? I found some problems in the past with pihole and link aggregation.

    • @MN11619
      @MN11619 Месяц назад +1

      I think this will depend on the type on LAG you’re using.
      When using Adaptive Load Balancing I couldn’t get the mac VLAN working. Others have experienced the same online.
      Using IEEE 802.3ad Dynamic Link Aggregation worked fine with a mac VLAN. I think you can only have 1 mac VLAN per interface. I hope that helps

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад +1

      It could certainly be what Nabz commented - are you using Adaptive LB?

    • @drevorazer
      @drevorazer Месяц назад

      I think it is LACP. Not sure if this makes any sense.

  • @kevinoconnor6570
    @kevinoconnor6570 Месяц назад

    When you talk about encrypting DNS queries with Unbound do you mean between Pi-Hole and Unbound? I don't believe that recursive queries are able to be encrypted to the root and authorative DNS servers.

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад +1

      Either DNS-over-TLS (DoT) or DNS-over-HTTPS (DoH). Unbound supports both, but yes, that's why I said "kind of" in the video, because it's not end-to-end encrypted so someone, somewhere will end up getting the request in plain text.

  • @RogierYou
    @RogierYou Месяц назад

    How does this compare with NextDNS ?

  • @FluidITGuy
    @FluidITGuy Месяц назад

    you afraid of twitter now because Elon is scary ?

    • @WunderTechTutorials
      @WunderTechTutorials  Месяц назад

      As ironic as it sounds, I'm not a social media guy so while I have one, I never sign into it.