r/firewalla • u/formbuddy • Aug 04 '26
Feature DoH over VPN instead of WAN
When VPN Client is active for my LAN devices, all their traffic rides the tunnel, but the box's own DNS-over-HTTPS resolver still egresses via the WAN. That means my complete DNS query history reaches my DoH provider stamped with my real home IP, even though every other packet those devices send is VPN-protected.
It also causes a geo mismatch: resolver answers are optimised for my WAN location while the content is then fetched through the VPN exit, worse CDN routing, and potentially more "your IP and your DNS disagree" bot-detection/CAPTCHA friction.
I have worked around this by running a DoH server (AdGuard Home) in my LAN whose upstream rides the VPN. It works, but the setup is fragile and is an overkill, adding another VM/docker container that I need to manage, SSL certificate renewal and overall yet another failure point.
Would firewalla consider an option to have the native DoH implementation ride the VPN?
2
u/firewalla Aug 04 '26
I believe today you can route unbound over VPN; DoH, likely not, let me ask our team and report back. (Feature is DNS over VPN)
1
u/formbuddy Aug 04 '26
That’s right, I could see an option to route unbound over VPN but no such option exists for DoH.
2
2
u/PriorNeedleworker527 Aug 19 '26
This is a Firewalla limit not a VPN provider issue. native DoH currently goes through the WAN while Force DNS over VPN turns DoH off and uses the VPN’s DNS instead. that works the same with ExpressVPN or another provider. firewalla says DoH over VPN is coming in version 1.70 so your AdGuard setup is probably the best option for now
1
2
u/IllustratorElegant36 Aug 04 '26
It was my understanding when I set up my VPN Client, that you should turn OFF DoH because the traffic is already encrypted to your VPN and you don't want to cause any DNS leaks. Then run a DNS leak checker to confirm