Jump to content

PIA and maybe pi-hole problems

paddy-stone
Go to solution Solved by paddy-stone,
7 minutes ago, Eigenvektor said:

Hm, ok so that means PIA shouldn't be blocking you from accessing it in general, just DNS for some reason. Any chance the update reset the DNS leak protection setting (or the update broke the setting)?

 

On your PC, something like "nmap -P0 -p 53 <ip>", where "ip" is the Pi's IP address. Ideally the port should come back as open.

 

Yep, came back as open

 

zenmap_kjidhIc30Y.png.99d2b629b5eaba551f07df458027d5e9.png

 

Well, wouldn't you know it, I just changed the settings from openvpn, to wireguard, and can now the raspberrypi can be the DNS server fine... it's returning DNS queries fine.

I tried safelinking.net again, and still wasn't resolving, so added safelinking.net to the whitelist and is now going through OK.

 

Thanks for the help.. I'm guessing it must have been an openvpn bug then if switching to wireguard fixed the problem with not allowing the pi-holes DNS server.

Anyway, I am happy now, all is as it should eb again :D

Having a weird problem. Just recently on my desktop, if I have PIA set to PIA DNS, it'll connect, but it won't resolve safelinking.net links either on browsers or jdownloader.

And also, if I set PIA's DNS to the pi-hole IP address, then it won't connect - well technically it's "connecting", but doesn't give me any connectivity or IP address. I only can connect if I set a public DNS address, or use PIA DNS.

 

For reference, other devices DNS settings set to pi-hole work fine, and also when not using PIA VPN on my desktop then DNS settings set to pi-hole works fine.

 

Any clue as to what could be wrong? I can't set up the DNS to be on the router, the ISP router has DNS settings disabled, which is why I am now setting up separately on devices themselves since my last router went wonky. Also, I still had this problem with the desktop, even with DNS server set on the router level.

 

Pi-hole is setup on my raspberry pi 4, and also has fail2ban installed.

 

Thanks for any ideas here.

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Ahh, also I guess I could turn off DHCP on the router, and get the pi to be the DHCP server, that would at least allow IOT devices to use the pi-hole. But I'd still have the problem with the desktop.

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Not sure about that particular domain not resolving but changing your DNS to the Pihole will activate the DNS leak protection.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, 2FA said:

Not sure about that particular domain not resolving but changing your DNS to the Pihole will activate the DNS leak protection.

 Yeah, sorry I forgot to mention that I turned off leak protection.

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, paddy-stone said:

Pi-hole is setup on my raspberry pi 4, and also has fail2ban installed.

Why? Unless you've opened ports to the internet, fail2ban isn't really needed. Your Pi-hole shouldn't be reachable from the Internet in any case.

 

By default VPN clients block all traffic that isn't routed through them. There should be an option to make an exception for your local network:
https://www.privateinternetaccess.com/helpdesk/kb/articles/i-cannot-access-devices-on-my-local-network

 

Without that it is probably blocking DNS requests to IPs on your local network (which is where the Pi-hole is, I presume)

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Eigenvektor said:

Why? Unless you've opened ports to the internet, fail2ban isn't really needed. Your Pi-hole shouldn't be reachable from the Internet in any case.

 

By default VPN clients block all traffic that isn't routed through them. There should be an option to make an exception for your local network:
https://www.privateinternetaccess.com/helpdesk/kb/articles/i-cannot-access-devices-on-my-local-network

 

Without that it is probably blocking DNS requests to IPs on your local network (which is where the Pi-hole is, I presume)

Yes, I already have "Allow LAN traffic" selected... I'm not having a problem with anything else to do with PIA, just setting it to pi-holes address, and resolving the safelinking.net domain.... guessing they blocked it on PIA DNS servers now as I never had a problem connecting until a week or 2 ago.

 

Yes I have ports open, because it also runs my VPN server... hence the fail2ban setup.

 

I have had PIA for years now, can access my local network fine etc, including my servers etc from my PC... the only thing I can't do as of around a week or 2 ago, is get the pi-hole to be the DNS server while using PIA.

 

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Oh, yeah forgot again sorry, PIA prog had an update a few days ago, which is when the problem connecting to pi-hole DNS server started IIRC... sorry I forgot to mention it, as it was around the same time that my router flaked out.... and was trying to sort out the 2 problems simultaneously.

@Eigenvektor @2FA

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, paddy-stone said:

Oh, yeah forgot again sorry, PIA prog had an update a few days ago, which is when the problem connecting to pi-hole DNS server started IIRC... sorry I forgot to mention it, as it was around the same time that my router flaked out.... and was trying to sort out the 2 problems simultaneously.

Yeah, sounds like the update might have broken something.

 

In that case I'd probably use something like nmap to see if port 53 on the Pi shows up as open while you're connected with PIA. And also have a look at the logs on the Pi, to see whether e.g. fail2ban is blocking you for some reason (though your internal IP shouldn't change).

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Eigenvektor said:

Yeah, sounds like the update might have broken something.

 

In that case I'd probably use something like nmap to see if port 53 on the Pi shows up as open while you're connected with PIA. And also have a look at the logs on the Pi, to see whether e.g. fail2ban is blocking you for some reason (though your internal IP shouldn't change).

I don't think fail2ban is blocking me, as I can still access the pi using ssh via putty, and no IPs are banned currently when I look up sshd.

 

Is that running nmap on the PC (windows) where I am using PIA, or running nmap on the pi?

 

Thanks for the suggestions.

 

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, paddy-stone said:

I don't think fail2ban is blocking me, as I can still access the pi using ssh via putty, and no IPs are banned currently when I look up sshd.

 

Is that running nmap on the PC (windows) where I am using PIA, or running nmap on the pi?

 

Thanks for the suggestions.

Hm, ok so that means PIA shouldn't be blocking you from accessing it in general, just DNS for some reason. Any chance the update reset the DNS leak protection setting (or the update broke the setting)?

 

On your PC, something like "nmap -P0 -p 53 <ip>", where "ip" is the Pi's IP address. Ideally the port should come back as open. Is there a log for PIA that would show it e.g. that attempt by nmap was being blocked as a leak?

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Eigenvektor said:

Hm, ok so that means PIA shouldn't be blocking you from accessing it in general, just DNS for some reason. Any chance the update reset the DNS leak protection setting (or the update broke the setting)?

 

On your PC, something like "nmap -P0 -p 53 <ip>", where "ip" is the Pi's IP address. Ideally the port should come back as open.

 

Yep, came back as open

 

zenmap_kjidhIc30Y.png.99d2b629b5eaba551f07df458027d5e9.png

 

Well, wouldn't you know it, I just changed the settings from openvpn, to wireguard, and can now the raspberrypi can be the DNS server fine... it's returning DNS queries fine.

I tried safelinking.net again, and still wasn't resolving, so added safelinking.net to the whitelist and is now going through OK.

 

Thanks for the help.. I'm guessing it must have been an openvpn bug then if switching to wireguard fixed the problem with not allowing the pi-holes DNS server.

Anyway, I am happy now, all is as it should eb again :D

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×