Pi-Hole's blacklist
Overview
Pi-Hole is a very powerful tool that acts as a DNS server with the ability to block advertising and tracking domains. Pi-Hole obtains lists of tracking domains from a configurable blacklist of predefined sources, and then compares DNS queries against them. However, although its main purpose is to work as an ad blocker, the nature of Pi-hole actually allows it to block the domain of any website by manually adding the domain name to a blacklist.
For more information on how Pi-Hole works, visit their official website. This guide explains how to extend the blacklists of Pi-Hole with our cloud filtering in order to benefit from additional malware protection and content filtering features.
Important Prerequisite Before proceeding with this guide, you must register your public IP address. Only registered IP addresses can use the malware protection and content filtering features on their network. You can do this by navigating to your dashboard and accessing the Networks section.
Configuration Methods
The setup process described in this guide can be done either through the web interface or by manually editing the configuration files. You can decide which one to use based on your personal preferences and the type of installation you have done. If you decide to configure via the web interface, follow the first section below. Otherwise, skip to the command line instructions.
Configuration Through Web Interface
A. Access the Web Interface
Log in to your Pi-Hole admin dashboard. From the main panel, go inside the Settings menu and move to the DNS tab.
B. Set Up Upstream DNS Servers
Here you need to enter the IP addresses of the upstream DNS servers you want to set up. These are the servers to which all requests will be automatically forwarded by your Pi-Hole server. Enter our custom IP addresses in the IPv4 Custom fields as follows:
- Custom 1 IPv4: 185.236.104.104
- Custom 2 IPv4: 185.236.105.105
C. Save and Verify
Scroll to the bottom of the page and click the Save button to apply your changes. You should now have your Pi-Hole server properly configured to forward all client requests to our DNS servers.
To start using our blacklists for content filtering and malware protection, you must now configure your specific filtering policies by going to the Protection section of our cloud dashboard.
Switch Configuration File via CLI
If for some reason you do not want to use the web interface or have simply decided not to install it, you can alternatively edit the Pi-Hole configuration files manually by following these simple steps. Please note that if you have already completed the web interface setup above, you do not need to proceed with this section.
A. Locate the Configuration File
The file we are interested in is called setupVars.conf and by default is located inside the /etc/pihole/ folder. Move to that directory and open the file with your preferred text editor:
sudo nano /etc/pihole/setupVars.confThis file is basically a script that takes care of setting numerous variables, which will then be used by Pi-Hole when running its core services.
B. Edit the DNS Variables
The variables we need to change are the ones defining the upstream DNS. If you have not previously configured an upstream DNS server, you might not find these variables in the file. In that case, you can directly add two new variables called PIHOLE_DNS_1 and PIHOLE_DNS_2 to the file. Set their values to our correct IP addresses as shown below. If they already exist, simply update their values:
PIHOLE_DNS_1=185.236.104.104
PIHOLE_DNS_2=185.236.105.105Save and close the file once you are done.
C. Apply Changes and Restart Services
Run the reconfiguration command in your shell to apply the new values:
pihole -rFinally, we need to restart the DNS service to make sure everything is running smoothly. You can use the following command to do this:
sudo service dnsmasq restartWe are done. You should now have your Pi-Hole server properly configured to forward all client requests to our DNS servers. What remains to be done now is to configure your filtering policies by going to the Protection section of our cloud dashboard.