Skip to content
DnsLister Forum

Where domain hunters compare notes

AdGuard Home + HaGeZi dns blocklists (and more) on GL routers – PSA

We seem to have a recurring theme about AdGuard Home, reasonable blocklists and crashes on GL routers, so I'm attempting to consolidate a few key tips to be aware of for those getting to know the routers.:

—–

1) Which HaGeZI blocklists should I run? – Here's the word from u/hagezi himself:

https://preview.redd.it/xl106hxwvmnh1.png?width=660&format=png&auto=webp&s=9393277ffe6225aab16b72f47d08d0c454e053f9

Source: https://www.reddit.com/r/GlInet/comments/1v0nzmu/comment/oyjjb7e/

—–

2) How much memory does it use? Why does my router randomly crash? – Again, well said by the same man:

https://preview.redd.it/zhc60gotwmnh1.png?width=616&format=png&auto=webp&s=ab86af9472861d96681f4cbd15e7bdea2ab24c52

Source: https://www.reddit.com/r/GlInet/comments/1vf1383/comment/p1lwz5q/

Why? During blocklist updates AGH briefly holds two copies of the filter data: it downloads the new list into memory, parses it, then atomically swaps it with the old one. The ruleset stays on the router until the swap completes. This can cause memory (RAM) usage to spike 3-4x during an update and easily crash a router. Rule sets like HaGeZI's Threat Intelligence have 2M+ records and require a *minimum* of 2GB free RAM to run safely – your router does not have this kind of RAM.

—–

3) What are my options if I want more filtering without killing my router?

There are many public DNS servers these days that will provide default levels of filtering. Eg:

* Cloudflare: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/
* Quad9: https://quad9.net/service/service-addresses-and-features/

You could chose these instead of running ADH on the router by adding them under "NETWORK > DNS", but you don't have to – when you can have both. You can have local ADH has your primary DNS filter and a cloud DNS as the 2nd.

For both, you use one of the above filtering DNS as your ADH "Upstream DNS". This is under the ADH setting page: Admin Panel > APPLICATIONS > AdGuard Home > Settings Page > (new tab) > Settings > DNS Settings (e.g.. http://192.168.8.1:3000).

In there you can see many different DNS providers you can use as your ADH upstream provider(s): https://adguard-dns.io/kb/general/dns-providers/

What this gains you is the ability to still have all your personal custom ADH block rules and query monitoring on the local router, but offload the heavy lifting to the upstream commercial DNS provider. This way, any queries coming from your router's LAN client devices get filtered by your custom ADH rules first, then passed to the upstream DNS for final malware/family filtering. Any queries that get caught by either set of filters get blackholed and do not resolve (blocked).

——

4) What else?

Another cool DNS option offered by GL routers is Control-D (https://controld.com/) or NextDNS (https://nextdns.io/). Both of these are available under NETWORK > DNS setting (on more recent firmware), and each provides a different way to create a personalized account with custom DNS filtering in the cloud. We'll leave this for user exploration…

——

Enjoy your ad-free (or ruining your 13 yr old's browsing habits) weekend!

Source: r/GlInet · by /u/RemoteToHome-io

Leave a Reply

Your email address will not be published. Required fields are marked *