-all *arr apps in docker containers using docker compose -tailscale has friendly tailnet name -…magicdns enabled -…global nameservers have mullvad public dns in them

not very confident here, can I just follow this guide (link: https://tailscale.com/kb/1114/pi-hole/) and it works or do I need to change some settings? I notice it tells me to add a custom DNS but mullvad is already in there? how does it know which to use or in which order?

  • Petter1@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    11 months ago

    I would install AdGuard as docker container and set the IP with which this Container is reachable as Nameserver (DNS) in tailscail

    You can most likely leave the DNS server of mullvad as second priority so you have a backup if your AdGuard container is not reachable

    But im just a noob with a sysadmin friend, lol

    • danA
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      11 months ago

      You can most likely leave the DNS server of mullvad as second priority so you have a backup if your AdGuard container is not reachable

      That’s not really how DNS works. If you have two DNS servers configured, the OS will usually do either one of two things:

      1. Balance the requests between them; or
      2. Send the request to both servers and use the one that replied faster

      If you mix Mullvad and AdGuardHome DNS servers, you’ll very likely end up with a mix of both being used. The DNS servers configured on your clients should either be all AdGuardHome or all Mullvad so that you don’t confuse yourself (“why are some ads blocked but not others??”) :)

      If you want to continue using Mullvad’s DNS servers, that’s fine, but you’d set them as upstream servers in AdGuardHome, and then configure all devices to use the AdGuardHome DNS. Ideally use their DNS servers using DNS-over-HTTPS or DNS-over-TLS: https://mullvad.net/en/help/dns-over-https-and-dns-over-tls

      • Petter1@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        11 months ago

        😮really, that would be really not intuitive design, have to check this on my OpnSense, in that case

        But generally, ads are always blocked, tho.

        Edit: See pic for how tailscale describes it:

        I understand it so, that your DHCP (your tailscale and for me OpnSense) will give the complete DNS list to devices, and those decide how to handle DNS lookups and may prefer mullvard prior AdGuard and thus will show ads. If that happen, you have to disable mulvards DNS server by removing it from the list.

        • danA
          link
          fedilink
          English
          arrow-up
          3
          ·
          11 months ago

          You got it. :)

          I’d recommend running two AdGuard Home servers on two different devices, and keeping them in sync with AdGuardHome-Sync. That’s useful because if you ever have to reboot one of them, the internet won’t break.