Best DNS Server for Home lab - Pihole Unbound configuration!

Best DNS Server for Home lab - Pihole Unbound configuration!

VirtualizationHowto

1 год назад

99,693 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@ronm6585
@ronm6585 - 03.03.2023 20:05

Thanks.

Ответить
@ripaire
@ripaire - 03.03.2023 20:27

hi sir but you didn't explain the point of exposing port 53 and how to prevent people from using our dns : i am running ubuntu on oracle cloud and i want to allow just people i know to use my dns but if i open port 53 i will end with unknown people using my dns and i don't want to use vpn as solution or tailscale i want to allow just a specefic devices to use it based on mac address not on ip

Ответить
@lucacamphuisen3093
@lucacamphuisen3093 - 03.03.2023 22:16

I've been using the built-in unbound in opnsense together with blocking lists, works great. I've also got it configured to forward a subdomain (*.k8s.domain.tld) to a selfhosted PowerDNS instance (dns server with api and gui comparable to hosting platform dns management). Configured external-dns on k8s to auto manage those sub-subdomains (e.g. nginx.k8s.domain.tld ) to my k8s services and use the cloudflare dns api to issue the tls certs :D

Ответить
@MacGyver0
@MacGyver0 - 03.03.2023 23:42

DOT and DOH are available for client devices which connects to Unbound.
But how exactly unbound improves privacy?
All requests to root servers are not encrypted, it still will use DNSSEC to ensure that response was not modified, but your ISP (and anyone who can read your traffic) will see what requests Unbound is making.
And yes, each recurse DNS request takes more time (30 times more in comparison with Cloudflare DNS), unbound will cache response, but for short time (15 min?).
So - it is slow and does not add privacy. But in Forwarding Mode to Cloudflare or quad9 (for example) using DOT, you will get really fast DNS and much more privacy.

Ответить
@hotstovejer
@hotstovejer - 04.03.2023 01:19

It's always DNS.

Ответить
@RicardoWagner
@RicardoWagner - 06.03.2023 04:02

Great !. The only thing missing for everyone to get into it is the cron suggested for the reload of the root servers. Thanks

Ответить
@da5fx
@da5fx - 06.03.2023 19:58

Hi
My DNS server is a HA MaaS region I still can use Pihole just as a filter if needed

Ответить
@Nitdawg-zt2dl
@Nitdawg-zt2dl - 07.03.2023 06:27

Will this work for my local and lab name resolution also or will I have to run this and point my windows DNS server to this and itself to resolve both internal and external device?

Ответить
@DevArt59
@DevArt59 - 08.03.2023 17:10

Now do it using containers ! Please

Ответить
@fasttrax
@fasttrax - 17.03.2023 00:32

Seems to be working, but if I type "unbound-control status" I get "Error setting up SSL_CTX client cert". How do I fix that? Thanks for the great video.

Ответить
@ripaire
@ripaire - 22.03.2023 17:14

hi sir tell me how i can enable safesearch through unbound and please share ith us the configuration

Ответить
@MrPDC-jr5yl
@MrPDC-jr5yl - 06.04.2023 20:56

Nice video Brandon, can you share you docker-compose file?!

Ответить
@vincentmartin2528
@vincentmartin2528 - 10.04.2023 17:02

Excellent video on unbound. Could you do the same video for Adguard Home. That would be a great addition I think.

Ответить
@DominikSchmid
@DominikSchmid - 13.04.2023 20:27

I have been trying to run pihole and unbound as docker containers with traefik. So far I was not successful. Could you show how to integrate unbound as a docker container in your setup of traefik and pihole?

Ответить
@Jou685
@Jou685 - 04.07.2023 21:46

How can i use both Pi-hole and nginx-proxy-manager together as one DNS?

Ответить
@JustinGeekNerd
@JustinGeekNerd - 05.07.2023 02:44

why you put sudo when root??

Ответить
@lcbdias
@lcbdias - 03.08.2023 19:20

great video!
for some reason when i check unbound as Upstream DNS Servers it cant no longer resolve local network DNS with SSL certificate (Nginx Proxy Manager/Let's Encrypt).
any ideas on why?

Ответить
@Meowbay
@Meowbay - 08.08.2023 18:01

Why are you using docker containers for everything? It's an extra point of failure, it's less secure, it's out of your control, it's a huge inefficient resources hog compared to just plain Debian minimal server use. All this even on VM, wow, your electricity bill or energy footprint seem to not matter to you do they?

Ответить
@TossACoinToYourWitcher
@TossACoinToYourWitcher - 16.08.2023 08:12

I have found Technitium is much more robust and has DOH and AD blocking and custom blocking built in. The entire thing is administrated in a web page an runs on raspberry pi too.

Ответить
@epictetus8028
@epictetus8028 - 19.08.2023 04:21

Why don't you run a DNS proxy on your Palo Alto?

Ответить
@igihara2662
@igihara2662 - 23.08.2023 10:02

Hello there
Would you consider to make a tutorial for a newbies on rpi - docker pihole + unbound?
Have a nice day

Ответить
@KonstantinGontsov
@KonstantinGontsov - 15.09.2023 21:59

I disagree!!! Best DNS Server for Home Lab is Technitium ))))))

Ответить
@TazzSmk
@TazzSmk - 23.09.2023 12:31

I'm watching this again after half year and I wonder if it's possible to completely migrate Unbound (config+caches) to new/different host/VM/CT?
I'm getting about 11 000 cache hits, so it's working pretty well :D

Ответить
@badpickle2347
@badpickle2347 - 17.12.2023 22:11

i can never figure out how to follow this guide. Seem to be missing steps or other prerequisite i'm not aware of. intriguing

Ответить
@OH2023-cj9if
@OH2023-cj9if - 27.12.2023 13:34

NextDNS every day!

Ответить
@Life_Is_A...
@Life_Is_A... - 30.12.2023 00:10

Networking tutorials on YT in a nutshell:
- This is a computer! We must first switch on the computer! Then reach over and touch the mouse!
- I'm going to change the attributes on this API here, then update the libraries for the database, which will allow more data visualization to take place on the next step, where we'll be able add identifiers and self closing tags to optimize the backend of the framework for the web server. This only works for version 1.6.344 of course!

Ответить
@yosoyestoyarto
@yosoyestoyarto - 31.12.2023 14:58

I try, pihole, but the phones at home not resolve local like, home.pc.local

Ответить
@markdevaal4116
@markdevaal4116 - 08.01.2024 13:42

Awesome tutorial. Im using Pi-Hole with Unbound in a Proxmox container and this works perfectly for me.

Ответить
@Liqtor
@Liqtor - 12.01.2024 22:05

PiHole + UnBound + LAN-Cache = Dream setup.

Ответить
@vizerdown
@vizerdown - 27.01.2024 22:51

Are you running pihole container on the unbound server?

Ответить
@BoltGoesPro
@BoltGoesPro - 29.01.2024 06:22

Would be nice to be able to copy and paste the commands from your description .-.

Ответить
@hugosantosRN
@hugosantosRN - 02.02.2024 19:26

AdGuard Home + Unbound here, very satisfied

Ответить
@Luckdragon2000
@Luckdragon2000 - 24.02.2024 13:00

Why would we not want to use IP6 for this?

Ответить
@dimkinlv
@dimkinlv - 25.03.2024 13:58

cant find any hint in pihole docs about cron for unbound. is it not needed anymore ?

Ответить
@Glatze603
@Glatze603 - 28.03.2024 21:32

Hi Brandon, thanks for your inspiration 🙂A video about Technitium DNS (like your article) would be nice.

Ответить
@kevinvanderlei3271
@kevinvanderlei3271 - 01.04.2024 07:04

Fantastic video, Brandon! Thank you for sharing your experience. May I ask you questions in the future?

Ответить
@YannMetalhead
@YannMetalhead - 24.05.2024 02:37

Good video.

Ответить
@Raylightsen
@Raylightsen - 26.05.2024 07:28

I want easy and simple explanations, not these convoluted ultra complex explanations.

Ответить
@FaithMediaChannel
@FaithMediaChannel - 01.06.2024 02:16

Showing this I have been looking at different ways to re-organizing our infrastructure as well as my home lab I have actually have pi installed in the cloud on our own servers as well as smaller versions of it on smaller devices, service quality commercial, but allowing us of the number of traffic that we have on it, I have found a pie is very easy to use and for those who are used to working with Cisco and all the flavors in betweenRoehling recommend putting pie hole on base if you have a lot of endpoint but a small thin server will work just as well and easily handles 200+ devices as well as in points and additional layers of that you can have one device and by pairing with Docker. Again thank

Ответить
@fernandavln38
@fernandavln38 - 24.06.2024 00:00

Good guide.

Ответить
@mondskiez309
@mondskiez309 - 27.06.2024 01:21

There is a docker-compose file to install both in one run.. everything is setup and you simply log into the web admin interfacr..

I got it running for my ansible docker play..

Ответить
@someoneelse5005
@someoneelse5005 - 02.08.2024 00:32

Nice video and good instructions.

Some advice:

Make sure that all the text you are pasting from somewhere can easily be reached, given the video! You can put all this info in description or create a github repository that would contain all the information and files needed, this is egregiously hard to follow.

Ответить
@chuckcrizer
@chuckcrizer - 09.08.2024 14:43

What? No O'Reilly book(s) to wade through? Lamorama.

Ответить
@remomattei
@remomattei - 27.08.2024 20:01

Hi great video. Do you have those config file available? Thanks

Ответить
@praveenmarkandu
@praveenmarkandu - 11.09.2024 09:22

Thanks. This helped me. Would be good if you could put links to the configs you are referring to

Ответить
@Glatze603
@Glatze603 - 19.09.2024 16:01

What DHCP solution do you use and are the clients automatically registered in the DNS after an IP has been assigned via DHCP?

Ответить
@Fureewolf
@Fureewolf - 25.10.2024 18:50

Question: What are to be installed first? Linux OS, Docker, PiHole, then last UnBound? Before I start the setup from this tutorial.

Ответить