[Solved] Domain Blocker / DNS Firewall: Status shows red exclamation marks

6 Posts
2 Users
2 Reactions
410 Views
(@misterwick)
Active Member
Joined: 4 Jahren ago
Posts: 9
Topic starter  

Hi,

my eBlocker does not filter ads / trackers. The status in the dashboard shows a red exclamation mark at "Domain Blocker (ads)" and "Domain Blocker (trackers)". On some devices the exclamation mark also appears at "DNS Firewall". The status changes from time to time on the tested devices (Win 10 PC, Android tablet, various Android smartphones with different Android versions), but the status always shows at least one red exclamation mark. I have also cleared the DNS cache in the DNS Firewall. Even after countless attempts, the status does not change to green.

image

This is my setup:

  • Raspberry Pi 3 B V1.2, 1GB, connected directly to the router
  • eBlocker OS 2.6.2 (192.168.0.4 / 255.255.255.0) - Gateway: 192.168.0.1
  • eBlocker runs in expert mode as DHCP-server (range 192.168.0.50 - 192.168.0.250)
  • DNS Firewall: Custom list of external DNS servers
  • no additional filter lists, no VPN, no TOR, no HTTPS, no eBlocker Mobile
  • Router (192.168.0.1 / 255.255.255.0): Vodafone Station (ARRIS, Cable), DHCP disabled, DNS cannot be changed

DNS server custom list

image

client settings (Win 10, actual Firefox, Chrome, Edge, Brave) 

image

tracert

image

nslookup shows this. I would have expected the IP of the eblocker here!?

image

Router

image

DHCP is OFF in Router, but shows ON!?

image

I already checked this post. Any ideas? 

Client OS
Browser
eBlocker hardware
Client OS version
Browser version
eBlockerOS version

   
Random reacted
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

@MisterWick Just disable IPv6 on your client - or even better in your router and it will work: https://eblocker.org/docs/disable-ipv6-for-your-internal-network/

To get your setup straight, please also check out the new Setup Guide we've just released: https://eblocker.org/docs/setup-instructions-start-here-eblocker-beginners/

You might also want to consider deleting the 8.8.8.8 DNS you've "accidentally" added. This is Google, the pest for your privacy. This pretty much kills the eBlocker advantages...

THX!


   
ReplyQuote
(@misterwick)
Active Member
Joined: 4 Jahren ago
Posts: 9
Topic starter  

I have disabled IPv6 on my PC and the status is now green 😀 
Unfortunately it is not possible to disable IPv6 in my router and on my mobile devices 🙁. What can I do? 

The 8.8.8.8 DNS was only for testing because with most DNS servers the reliability is low or medium. Have deleted it now.


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 
Posted by: @misterwick

Unfortunately it is not possible to disable IPv6 in my router and on my mobile devices 🙁. What can I do? 

I'd personally recommend to get a "real" router (that gives you full control - ie. ability to disable IPv6 and DHCP) and leave the providers modem just as "connector" to the internet (disabling WLAN, not plugging in any clients).

So like: Internet<->Providers's DSL/Cable-Modem<->real router<->LAN/WLAN

This also adds another layer of security: Today someone who passes your modem (say a "service technician" of your provider) can easily get access to all your LAN/WLAN devices. Using a router behind the modem (which serves all your devices as LAN/WLAN access point) an attacker only reaches the WAN port of the router and needs much more efforts to bypass the router to get access to your devices. In addition if you live in an area with many other WLANs, you might want to consider buying a router that "out-rules" all others due to higher signal strength, Wifi 6 support etc.

Additionally you can also donate to the IPv6 implementation goal. But even if the goal is reached, a freelancer will take some time to implement it. So this is rather a long term solution...

Nevertheless, any contribution to the eBlocker project is highly appreciated. Please consider donating anyways - also to credit our forum support. 👍 😎 

THX!

PS: IPv6 is also the pest for your privacy. So I'd always recommend to disable IPv6 in your LAN/WLAN even if IPv6 has been implemented in eBlocker.


   
ReplyQuote
(@misterwick)
Active Member
Joined: 4 Jahren ago
Posts: 9
Topic starter  

Thanks for the detailed explanation. I think I will buy an additional "real" router to avoid the problems with IPv6.

I love eBlocker and you are doing a great job! Please keep up the good work 👍

I have just donated to the project.


   
Random reacted
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

@misterwick Thanks, mate! I appreciate supporting you.

BTW: I run a similar setup with a „real“ router as I don‘t trust the provider‘s technicians. I saw live how easily they connected to my Fritzbox from some „service technician tablet“via the Internet - and since then I‘m using a separate router.

One additional hint: If you are based in Germany there is the „freedom of modem choice“ act, so you might even be able to swap out the providers modem completely…

THX!


   
ReplyQuote

Nach oben scrollen