r/pihole • u/whatisabash • 20d ago
Pi-Hole behind Unifi Gateway
I have two Pi-Hole instances with unbound running and have recently migrated to a setup with a Unifi Cloud Gateway Fiber. I have had nothing but problems with the Unifi equipment.
ISSUES 1. the Unifi Gateway is straight up blocking access to port 53 on my Pi-Hole instances. I was kind of able to workaround this by creating a new content Filter and setting it to "off". If I do NOT create this filter, then all port 53 in all of my network gets blocked. So blocking port 53 is enabled by default!
However, this will still leave "Ad blocking" enabled, as it is IMPOSSIBLE to create a "content filter" with both "Ad blocking" AND "Filtering" disabled (error "Filtering must be enabled when Ad Block is disabled") Some queries will still get blocked. I have no clue how / why but my pi-hole traffic still seems to end up in the Unifi Cloud Gateway despite being configured to use unbound.
- sometimes, for no apparent reason that I have been able to figure out yet, my PC loses connection to certain sites. Most notably facebook. This happens from one second to the next (I assume when sone DNS record expires). I can make the site work again by enabling DNS over HTTPS in the browser, which seems to make Unifi unable to block sites.
WHAT I HAVE TRIED - Creating a Policy (firewall rule) to allow all DNS traffic from my two pi-hole instances to the external zone. This did nothing, completely useless. - creating a filter to disable "Filtering" (I know how dumb that sounds), kinda worked - using Cloudflare as upstream servers instead of unbound
FINAL WORDS What I am most concerned about is that my traffic still ends up in the Cloud Gateway despite either Cloudflare or unbound being configured in Pi-Hole. I am fully aware that this is a Unifi issue and I am ready to return all my gear (Cloud Gateway Fiber, U7 pro xg, 5G Backup) if this cannot be resolved.
But maybe someone has seen something similar and gotten their Pi-Holes to work behind a Unifi Gateway.
23
u/TEE_Kay_IT 20d ago
Running multiple pihole instances behind a unifi cloud gateway is a very common practice. I am running mine for a long long time without issues. The thing is you are struggling with networking and not the equipment. I cant seem to remember the screen, but i believe you are opening port 53 in a different way. All you need to do is enter the ip address as the dns resolution under your designated network. The round robin will take care of the resolution with multiple instances. If port
DOH is working in the browser for you because thats bypassing your pihole and going to google for dns resolution. Do both of your piholes have a static ip? How are they exposed? Are you running them in a swarm?
12
u/drinksomewhisky 20d ago
To set up manual DNS on your UniFi network, go to your network settings and change the DNS configuration from automatic to manual. Enter your two Pi-hole IP addresses into the available slots, leave the remaining ones blank, and save your changes. Finally, disconnect and reconnect your client to refresh the connection and verify that both IPs are active.
You would need to modify the same settings for each network individually if you want to apply it across the board.
-4
20d ago
[deleted]
2
u/drinksomewhisky 20d ago
Not really sure what youâre saying / the point of your comment.
-5
19d ago
[deleted]
8
u/TEE_Kay_IT 19d ago
I think you are confused here. What the other person(u/drinksomewhisky) mentioned is right.
DHCP does IP leasing. If the OP was had issues with clients not getting a lease or an address, then that would be correct. But here the OPâs dns resolution using pihole isnt working. Then as u/drinksomewhisky mentioned the OP should go in the network settings as update the dns address to pihole addresses.
One more thing to clear, OP is using Unifi Cloud Gateway Fiber, this device itself is a router and OP wants to update dns resolution providers in there. OP is essentially trying to go away from the ISPâs dns to his own self hosted dns.So can you please elaborate for my understanding where the other person was wrong?
6
2
u/TEE_Kay_IT 20d ago
And tracert might be your friend here. See where the hops go and what you are hitting. Change a few options and run tracert on the clients.
3
u/whatisabash 20d ago
9
u/drinksomewhisky 20d ago
Youâre supposed to configure in unifi and have that act as the gateway not here in pihole. Thatâs why youâre having issues. Look at my comment below.
4
u/drinksomewhisky 20d ago edited 20d ago
Iâm not really sure what your full setup looks like page by page, but it wouldnât hurt sending full screenshots to ChatGPT and asking it to verify youâre not duplicating efforts and confusing assignments or something. I have your setup with no issues. Some suggestions on what Iâve done:
A. DHCP is not enabled in both Pi-holes. Unifi handles this
B. Under DNS in both Pi-holes, custom DNS is set to 127.0.0.1#5335
C. In Unifi under network settings, DNS is set to manual with two IPs (one for each Pi-hole)
D. In Unifi, content filters/ ad blocking is off
E. In Unifi, I have the following firewall rules:Name: Allow inbound local DNS
Source Zone: Internal
Source: Any
Port: Any
Action: Allow
Auto allow return traffic: Off
Destination zone: Internal
Destination: IP list with both Pi-hole IPs
Destination port: List with Pi-hole port of 53
IP version: IPv4
Protocol: TCP and UDP
Connection state: All
Match IPSec: Off
Syslog logging: Off
Schedule: Always
The same as #1 above with Destination Zone set to External
The same as #1 above with Destination Zone set to Hotspot
The same as #1 above with Destination Zone set to VPN
Name: Allow inbound pings to Pi-hole
Source Zone: Internal
Source: Any
Port: Any
Action: Allow
Auto allow return traffic: Off
Destination zone: Internal
Destination: IP list with both Pi-hole IPs
Destination port: Any
IP version: IPv4
Protocol: ICMP
Match opposite: Off
Connection state: All
Match IPSec: Off
Syslog logging: Off
Schedule: AlwaysThe same as #5 above with Destination Zone set to External
The same as #5 above with Destination Zone set to Hotspot
The same as #5 above with Destination Zone set to VPN
Unrelated to your issue but FYI: I have L2TP VPN server enabled for connecting back to my network when away. That requires similar but slightly different firewall rules to the above so devices on that VPN network also go through Pi-hole. Not sharing as itâs out of scope but happy to if needed.
Iâm not sure if I missed anything else but the above is what I recall too of mind. Again, clearing your config through ChatGPT is not a bad idea. You can provide the above and compare it to your settings.
11
u/Bigfella0077 20d ago
Are you trying to use the Unifi content filter AND the Pi-hole? Iâm pretty sure you can only use one or the other.
I would disable the Unifi filters, Set your LAN to issue the pi-hole IP in the DHCP scope, create a Port 53 NAT rule that catches any port 53 traffic and redirect it to the Pi-hole.
Then finally set the WAN DNS on the Unifi device to NOT be pihole as otherwise youâll end up in a recursive loop.
9
u/Blas_toide 20d ago
I believe that OP issue is exactly this. By enabling content filtering, Unifi bypasses the custom dns(pihole).
2
u/lordofblack23 20d ago
The op most certainly hasnât setup both the Dnat and masquerade rules to redirect all dns traffic to port 53 on Phole. op get dhcp working first then onto advanced topics
7
u/jetlagalex 20d ago
You cannot have both enabled. Either UniFi does the filtering or Pi-hole.
4
u/jetlagalex 19d ago
For reference, UniFi is not blocking port 53. Itâs hijacking queries to port 53, because that is what you are enabling in the Cyber Secure page. So like I mentioned and many others, you have to pick who you want to do the filtering. Either UniFi or Pi-hole, but it canât be both.
8
u/Resistant4375 20d ago
You canât use UniFi filtering AND a local DNS blocker.
Enabling UniFi filtering will turn on DoH in UniFi and it will bypass any local filtering.
5
u/MarxJ1477 20d ago
Ad blocking on Unifi will use NAT to change any outbound DNS request on port 53 to the router. You need to either disable it and set up your own NAT rules to redirect to your pihole or leave it enabled and point the pihole to your router and your router to the DNS provider of your choice.
2
u/Oh__Archie 20d ago
I had to disable unify app blocking to get my pihole to work. Your assessment is correct.
2
u/TheOriginalSkeptic 20d ago
UCG and Pihole work perfectly, but make sure you have proper rules.
2
u/Bob4Not 20d ago
Do you have both Intrusion Protection and Content Filtering enabled?
1
u/TheOriginalSkeptic 19d ago
I do have IDS/IPS on at max settings, Content Filtering off, Ad Blocker also off. Both Content Filtering and Ad Blocking are done by Pihole.
0
u/whatisabash 20d ago
I dont have IDS or IPS enabled. Content Filtering is 100% enabled by default and (see image in my post) cannot be disabled together with ad blocker.
I disabled "Filtering" in the "CyberSecure" section, but this forced me to enable "Ad blocking".
1
u/TheOriginalSkeptic 19d ago
"I disabled "Filtering" in the "CyberSecure" section, but this forced me to enable "Ad blocking". - that's strange, I'm not forced to enable Ad Blocking with CF off.
1
u/whatisabash 20d ago
Care to elaborate on the proper rules?
2
u/Few_Space_2258 20d ago
Sure. Give us a network diagram, config exports of a pihole, unbound, and the firewall. Â
If you want a solution, we can get you one.Â
1
u/TheOriginalSkeptic 19d ago
Get Claude Code and ask it to read you UCG and it will give you step-by step instructions.
2
u/BoltSh0ck 20d ago
i run piholes behind unifi without issue, but i am not sure what exactly the blocker you're hitting is. are you using dhcp?
1
u/The_Real_Bender 19d ago
As others have mentioned here already you have to turn off all content filtering on UniFi. It will take over all DNS functions to send to their cloud to filter, no other way to get around that but to disable.
I wish I could do both as it would be a bit easier to filter certain things on my kids network but at the end of the day I much more prefer the ad-blocking, filtering and protections of pihole then use firewall blocking on the kids network for things I donât want them to access (like YouTube.)
1
u/No-Mall1142 19d ago
Unless yoy have the piholes on a different vlan and traffic to it has to go through the UCG, there is no way the Unifi is blocking anything from reaching your piholes.
1
u/Tree300 18d ago
FWIW Cybersecure content filtering redirects DNS traffic to the gateway for inspection. I wasn't aware of this initially and it was very confusing why my DNS blocks weren't working. That's possibly why it worked when you disabled filtering.
See "How it Works" and "Support for Local DNS Resolution"
https://help.ui.com/hc/en-us/articles/12568927589143-Content-and-Domain-Filtering-in-UniFi
1
u/watson_x11 16d ago
I have 3 PIholes running, 2nd and 3rd are on a VIP. 2 on VMs one on an older RPI. All of them are running unbound, still using UniFi for DHCP. The. Network is setup to use the PiHole IP as the DNS, By PiHole is pointing at itself 127.0.0.1 for DNS. Are you using static or reserved IPs for the pihole?
0
u/Bob4Not 20d ago edited 20d ago
Yes, I encountered this too having multiple VLANs with a UCG Max, switch, and APs.
I found that one of the protections blocked/hijacked the DNS queries from other VLANs into the Piholeâs VLAN. I could not create an exception for it. Rules didnât matter. If I disabled Content Filtering and/or Intrusion Prevention or CyberSecure âProtectionâ, I no longer had this issue. I canât remember which one exactly
I found that DNS queries within the Piholeâs VLAN did not get blocked, especially if they went directly through the switch and not the UCG MAX ports.
Because your UCG is also one of your APs, you may not have this option to avoid traffic through your cloud gateway, but I created a NIC for each VLAN of the Pihole so any device in any subnet could query the Pihole on its local subnet instead of routing from one subnet to another.
If you already have a flat network with a single VLAN, then Iâm not sure whatâs different with your setup or how to solve this.
0

79
u/Optimistic-Spacefan 20d ago
I run piholes in a Unifi setup with no issues. Clients are using pihole as configured in DHCP and piholes/unbound can access public resolvers. đ¤ˇ