# Pi-Hole VLAN advice using 05-custom.conf or define VLAN interfaces

**URL:** <https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982>\
**Category:** Community Help\
**Created:** [October 3, 2020, 9:16am UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982 "2020-10-03T09:16:35Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 3, 2020, 9:16am UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/1 "2020-10-03T09:16:35Z")

</div>

Hi,

I have 2 Pi-Hole's running on a Rasperry Pi 4 with unbound as resolver.  
My network consist of 8 VLANS who are using Pi-Hole as their DNS, I have also some rules in my firewall to catch services from using another dns then Pi-Hole, all working fine.  
To see the devices in my Pi-hole statisctics I use a 05.-custom.conf file, who looks like this:  
server=/Kopernikus-Native.lan/10.10.1.1  
server=/Kopernikus-Trusted.lan/10.10.10.1  
server=/Kopernikus-Kids.lan/10.10.20.1  
server=/Kopernikus-IoT.lan/10.10.30.1  
server=/Kopernikus-Surveillance.lan/10.10.40.1  
server=/Kopernikus-Servers.lan/10.10.50.1  
server=/Kopernikus-Guests.lan/10.10.90.1  
server=/Kopernikus-Management.lan/10.10.100.1  
server=/1.10.10.in-addr.arpa/10.10.1.1  
server=/10.10.10.in-addr.arpa/10.10.10.1  
server=/20.10.10.in-addr.arpa/10.10.20.1  
server=/30.10.10.in-addr.arpa/10.10.30.1  
server=/40.10.10.in-addr.arpa/10.10.40.1  
server=/50.10.10.in-addr.arpa/10.10.50.1  
server=/90.10.10.in-addr.arpa/10.10.90.1  
server=/100.10.10.in-addr.arpa/10.10.100.1

Now I saw on some threads some people are defining their VLAN interfaces on the raspberry pi itself.  
Can someone explain the difference (or advantages) to the method I use?

Thx

---

<div class="post-metadata">

**Author:** ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)\
**Post date:** [October 3, 2020, 6:13pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/2 "2020-10-03T18:13:20Z")

</div>

The difference is that you don't have to route the DNS traffic

> [@Secondary VLAN resolving DNS query without PiHole](https://discourse.pi-hole.net/t/secondary-vlan-resolving-dns-query-without-pihole/33260/7):
>
> That's because you are doing it wrong! wink Don't route DNS Traffic from VLAN to VLAN but instead add some VLAN Interfaces to your Pi-Hole Server so it has a simple local connection with every Client in each VLAN wink If you want I can write up a Tutorial for this in English ? In case you speak Dutch or feel like using Google Translate then click here : [https://gathering.tweakers.net/forum/list\_message/57865570#57865570](https://gathering.tweakers.net/forum/list_message/57865570#57865570)

Maybe @nero355 can give additional info?!

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 3, 2020, 7:35pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/3 "2020-10-03T19:35:47Z")

</div>

Vlan's are a switch thing.  
Clients and servers dont need to be aware what vlan's they are in.  
They only need to be aware of the subnets.  
There are some exceptions like hypervisors that apply virtual bridges etc for their guests/VM's that need to be in vlan trunks.  
I could be wrong missing some bits but am sure someone here will correct me 😉

To prevent having to route traffic between the subnets, you could assign all appropriate vlan's to the switch/router port that Pi-hole is connected to.  
And create a bunch of [aliased IP's](https://en.wikipedia.org/wiki/IP_aliasing) for each vlan on one and the same physical connected interface.  
Below how is done for Raspbian/Debian using `dhcpcd5` network manager (without having to translate that Dutch link):

```auto
pi@ph5:~ $ ip -br link show
lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
eth0 UP b8:27:eb:xx:xx:xx <BROADCAST,MULTICAST,UP,LOWER_UP>

```

* * *

```auto
pi@ph5:~ $ ip -br -4 address show
lo UNKNOWN 127.0.0.1/8
eth0 UP 10.0.0.4/24

```

* * *

```auto
pi@ph5:~ $ sudo nano /etc/network/interfaces
# interfaces(5) file used by ifup(8) and ifdown(8)

# Please note that this file is written to be used with dhcpcd
# For static IP, consult /etc/dhcpcd.conf and 'man dhcpcd.conf'

# Include files from /etc/network/interfaces.d:
source-directory /etc/network/interfaces.d

auto eth0.0
iface eth0.0 inet manual

auto eth0.1
iface eth0.1 inet manual

auto eth0.22
iface eth0.22 inet manual

```

* * *

```auto
pi@ph5:~ $ sudo service networking restart
pi@ph5:~ $

```

* * *

```auto
pi@ph5:~ $ ip -br l
lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
eth0 UP b8:27:eb:xx:xx:xx <BROADCAST,MULTICAST,UP,LOWER_UP>
eth0.0@eth0 UP b8:27:eb:xx:xx:xx <BROADCAST,MULTICAST,UP,LOWER_UP>
eth0.1@eth0 UP b8:27:eb:xx:xx:xx <BROADCAST,MULTICAST,UP,LOWER_UP>
eth0.22@eth0 UP b8:27:eb:xx:xx:xx <BROADCAST,MULTICAST,UP,LOWER_UP>

```

* * *

```auto
pi@ph5:~ $ sudo nano /etc/dhcpcd.conf
[..]
interface eth0
  static ip_address=10.0.0.4/24
  static routers=10.0.0.1
  static domain_name_servers=10.0.0.1

interface eth0.0
  static ip_address=10.10.10.10/24

interface eth0.1
  static ip_address=172.16.0.2/24

interface eth0.22
  static ip_address=192.168.0.2/24

```

* * *

```auto
pi@ph5:~ $ sudo service dhcpcd restart
pi@ph5:~ $

```

* * *

```auto
pi@ph5:~ $ ip -br -4 a
lo UNKNOWN 127.0.0.1/8
eth0 UP 10.0.0.4/24
eth0.0@eth0 UP 10.10.10.10/24
eth0.1@eth0 UP 172.16.0.2/24
eth0.22@eth0 UP 192.168.0.2/24

```

```auto
pi@ph5:~ $ ip -br -4 r
default via 10.0.0.1 dev eth0 src 10.0.0.4 metric 202
10.0.0.0/24 dev eth0 proto dhcp scope link src 10.0.0.4 metric 202
10.10.10.0/24 dev eth0.0 proto dhcp scope link src 10.10.10.10 metric 206
172.16.0.0/24 dev eth0.1 proto dhcp scope link src 172.16.0.2 metric 207
192.168.0.0/24 dev eth0.22 proto dhcp scope link src 192.168.0.2 metric 208

```

And make sure Pi-hole is set to "Listen on all interfaces" below:

[http://pi.hole/admin/settings.php?tab=dns](http://pi.hole/admin/settings.php?tab=dns)

EDIT: added routes

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 4, 2020, 10:19am UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/4 "2020-10-04T10:19:52Z")

</div>

@deHakkelaar

Hi,

Thx for the info.

So if I understand correctly:

- Create a new VLAN switch profile for my pihole's leaving them in the server VLAN (where they reside now) and tag all other VLAN networks

- Install VLAN support on the raspberry pi

- Create a vlan file in /etc/network/interfaces.d to define my VLANS --\> I suppose I can skip the VLAN where my pihole is in? Since this is connected to eth0

- Edit /etc/dhcpcd.conf --\> do I need to do this also when not using to Pi-Hole's as DHCP server? I rather let my Ubiquiti USG/controller handle this, if needed what's the use of the static ip adress defined for every VLAN? Also the static IP for eth0 shoudl this be the IP adress of the Pi-Hole, now it gets is IP from my DHCP (static assignement)

- Set Pi-hole to listen to all interfaces

- Now in all VLANS the dns is pointed to the same DNS, do I need to change DNS now for each VLAN to the coresponding static ip set in dhcpcd.conf?

Do I still have to use my 05-custom.conf file? or delete it...

Thx!

--\> I'll gave it a try and all seem to be working except for eth0 as soon as my VLANS are up I can't connect to the pihole admin page or ssh or use DNS on eth0 (however pinging to it works), on the vlans I can go to the static set adress and login to pihole use ssh/dns, after removing vlans from the vlan file and reset networking I am able to access the pihole again on eth0, any idea what could cause this?

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 4, 2020, 6:42pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/5 "2020-10-04T18:42:54Z")

</div>

Not sure if you need that `vlan` package and `8021q` driver.  
As said before:

> [@deHakkelaar](#):
>
> Vlan's are a switch thing.  
> Clients and servers dont need to be aware what vlan's they are in.  
> They only need to be aware of the subnets.

```auto
pi@ph5:~ $ apt show vlan
[..]
Description: ifupdown integration for vlan configuration
 This package contains integration scripts for configuring vlan
 interfaces via ifupdown (/etc/network/interfaces).
 For further details see vlan-interfaces(5) man page in this package.
 .
 Please note that these integration scripts only supports a limited
 set of interface naming schemes, which means you might be better
 off with writing your own ifupdown hooks using ip(route2)
 directly in /etc/network/interfaces rather than using this package.
 .
 It currently also ships a wrapper script for backwards compatibility
 called vconfig, that replaces the old deprecated vconfig program
 with translations to ip(route2) commands.
 This compatibility shim might be dropped in future releases, please
 use ip(route2) commands directly.
 .
 Your kernel needs vlan support for this to work, see "modinfo 8021q".

```

* * *

```auto
pi@ph5:~ $ apt-file list vlan
vlan: /etc/network/if-post-down.d/vlan
vlan: /etc/network/if-pre-up.d/vlan
vlan: /etc/network/if-up.d/ip
vlan: /sbin/vconfig
vlan: /usr/share/doc/vlan/NEWS.Debian.gz
vlan: /usr/share/doc/vlan/TODO
vlan: /usr/share/doc/vlan/changelog.gz
vlan: /usr/share/doc/vlan/copyright
vlan: /usr/share/man/man5/vlan-interfaces.5.gz
vlan: /usr/share/man/man8/vconfig.8.gz

```

You can create those aliased IP's without above.  
Maybe @nero355 can elaborate why that `vlan` package and `8021q` driver is necessary ?

> [@Kopernikus](#):
>
> Edit /etc/dhcpcd.conf --\> do I need to do this also when not using to Pi-Hole's as DHCP server?

Assigning a static IP through `dhcpcd.conf` may sound confusing as if it were to get IP details via DHCP but this is not the case.  
The `static ip_address=` directive will assign a static IP without DHCP dependency:

```auto
pi@ph5:~ $ apt show dhcpcd5
[..]
Description: DHCPv4, IPv6RA and DHCPv6 client with IPv4LL support
 dhcpcd is a one stop network management daemon which includes
  * RFC compliant DHCPv4 and DHCPv6 clients
  * DHCPv6 Prefix Delegation support
  * IPv4LL (aka ZeroConf) support
  * ARP address conflict resolution
  * Link carrier detection
  * Wireless SSID profiles
  * ARP ping profiles

N: There is 1 additional record. Please use the '-a' switch to see it

```

> [@Kopernikus](#):
>
> Now in all VLANS the dns is pointed to the same DNS, do I need to change DNS now for each VLAN to the coresponding static ip set in dhcpcd.conf?

Yes.

> [@Kopernikus](#):
>
> Do I still have to use my 05-custom.conf file? or delete it...

Yes that file is suited for storing your own customizations.

> [@Kopernikus](#):
>
> , any idea what could cause this?

Human error 😉  
Can you post content of the `dhcpcd.conf` and `interfaces.d-->vlan` file ?

`sudo grep -v '^\s*#\|^\s*$' -R /etc/network/interfaces*`

`sudo grep -v '^\s*#\|^\s*$' /etc/dhcpcd.conf`

And post output for below when cant connect to `eth0` IP (`ssh` into one of the other IP's) ?

`ip -4 a s eth0`

`ip -4 r`

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 5:44am UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/6 "2020-10-05T05:44:59Z")

</div>

@deHakkelaar

Hi,

Activated config and did SSH to VLAN10 10.10.10.41 (since eth0 on 10.10.50.41 doesn't work)

Content of dhcpcd.conf:

hostname  
clientid  
persistent  
option rapid\_commit  
option domain\_name\_servers, domain\_name, domain\_search, host\_name  
option classless\_static\_routes  
option interface\_mtu  
require dhcp\_server\_identifier  
slaac private  
interface eth0  
static ip\_address=10.10.50.41/24  
static routers=10.10.50.1  
static domain\_name\_servers=127.0.0.1  
interface eth0.10  
static ip\_address=10.10.10.41/24  
interface eth0.20  
static ip\_address=10.10.20.41/24  
interface eth0.30  
static ip\_address=10.10.30.41/24  
interface eth0.90  
static ip\_address=10.10.90.41/24

Content of vlan:

/etc/network/interfaces:source-directory /etc/network/interfaces.d  
/etc/network/interfaces.d/vlans:auto eth0.10  
/etc/network/interfaces.d/vlans:iface eth0.10 inet manual  
/etc/network/interfaces.d/vlans:vlan-raw-device eth0  
/etc/network/interfaces.d/vlans:auto eth0.20  
/etc/network/interfaces.d/vlans:iface eth0.20 inet manual  
/etc/network/interfaces.d/vlans:vlan-raw-device eth0  
/etc/network/interfaces.d/vlans:auto eth0.30  
/etc/network/interfaces.d/vlans:iface eth0.30 inet manual  
/etc/network/interfaces.d/vlans:vlan-raw-device eth0  
/etc/network/interfaces.d/vlans:auto eth0.90  
/etc/network/interfaces.d/vlans:iface eth0.90 inet manual  
/etc/network/interfaces.d/vlans:vlan-raw-device eth0

ip -4 a s eth0:

2: eth0: \<BROADCAST,MULTICAST,UP,LOWER\_UP\> mtu 1500 qdisc mq state UP group defa ult qlen 1000  
inet 10.10.50.41/24 brd 10.10.50.255 scope global noprefixroute eth0  
valid\_lft forever preferred\_lft forever

ip -4 r:

default via 10.10.50.1 dev eth0 src 10.10.50.41 metric 202  
10.10.10.0/24 dev eth0.10 proto dhcp scope link src 10.10.10.41 metric 204  
10.10.20.0/24 dev eth0.20 proto dhcp scope link src 10.10.20.41 metric 205  
10.10.30.0/24 dev eth0.30 proto dhcp scope link src 10.10.30.41 metric 206  
10.10.50.0/24 dev eth0 proto dhcp scope link src 10.10.50.41 metric 202  
10.10.90.0/24 dev eth0.90 proto dhcp scope link src 10.10.90.41 metric 207

Hope you can see some error 🙂

Thx!

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 10:04am UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/7 "2020-10-05T10:04:19Z")

</div>

Got it working! 🙂

Somehow it was the vlan package that caused the problem.  
So I removed the vlan package and disabled the kernel module from starting.  
Reboot and I can acess pihole on eth0 and all other vlans.

Next test change DNS in controller/USG to the appropiate VLAN dns and see if all is working.

---

<div class="post-metadata">

**Author:** ![no1jam](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/no1jam/32/24476_2.png) [@no1jam](https://discourse.pi-hole.net/u/no1jam)\
**Post date:** [October 5, 2020, 12:09pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/8 "2020-10-05T12:09:31Z")

</div>

Good tips here. I just enabled a couple firewall rules to allow traffic from one vlan to the other for my pihole specific IP's. but maybe I will test this out in the future!

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 4:15pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/9 "2020-10-05T16:15:56Z")

</div>

> [@Kopernikus](#):
>
> interface eth0  
> static ip\_address=10.10.50.41/24  
> static routers=10.10.50.1  
> static domain\_name\_servers=127.0.0.1

I prefer to have another external DNS server(s) configured for processes running on the Pi-hole host.  
Sometimes, like for example when tinkering, the `pihole-FTL` daemon could stop replying to DNS lookups on the `127.0.0.1` IP and your dead in the water without DNS.

To compliment your setup, I would also configure a firewall either local or on the router/switch to block certain ports for particular vlan's.  
For the non trusted vlan's, I would block SSH (22TCP) and the web GUI access (80TCP) to Pi-hole.

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 4:19pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/10 "2020-10-05T16:19:18Z")

</div>

> [@no1jam](#):
>
> I just enabled a couple firewall rules to allow traffic from one vlan to the other for my pihole specific IP's.

Doing it your way means the router is using valuable resources to NAT traffic from one vlan to another.  
More load and more memory used for the routing tables etc.  
Letting the switch engine do all the work, like described in this thread, is less resource heavy for your router/switch.  
And you wont have to reboot the router every now and than because the NAT tables are all messed up again.

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 5:40pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/11 "2020-10-05T17:40:14Z")

</div>

@deHakkelaar

Screamed to fast that it was working ☹ 🤐  
Came home all was locked up, had to revert everything.  
But maybe I'm closer to a solution, what happened was the following: I made a VPN connection to my OpenVPN AS who's is running a docker container on my Synology NAS. I disable the VLAN service on the raspberry pi's, and then did a ping to the eth0 interface and all was working without realising the only reason that is was resolving was because of the VPN connection. when I was back home I couldn't reach the pihole on their eth0 interface, as soon as I dissabled them again all was working fine.

So what would be the problem here?

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 5:43pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/12 "2020-10-05T17:43:57Z")

</div>

`sudo grep -i 'interface=\|bind-' -R /etc/dnsmasq.*`

?

EDIT: ps. whats a "OpenVPN AS" ?

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 5:49pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/13 "2020-10-05T17:49:00Z")

</div>

Hi,

Did:  
sudo grep -i 'interface=|bind-' -R /etc/dnsmasq.\*

But still can't reach on eth0  
To test tried it also from other vlan's and also the native lan (eth1), same result, also disabled firewall to test but doensn't work, question remain why did it work through the VPN

OpenVPN Access Server+ ([https://github.com/linuxserver/docker-openvpn-as](https://github.com/linuxserver/docker-openvpn-as))

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 5:57pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/14 "2020-10-05T17:57:21Z")

</div>

I meant I wanted to see the output for that `grep` command ?  
If no output, thats a good thing.

I cant make up which device is dialing into that Docker VPN server ?  
If its the Pi-hole host, test without being connected to VPN first.  
VPN servers will force their own DNS server IP's onto the clients.

To test DNS resolution, you can use the `nslookup` tool on a **client** (Windows/Linux/MacOS) as well as on the Pi-hole host itself eg:

`nslookup pi.hole`

`nslookup pi.hole 10.10.50.41`

`nslookup pi.hole 10.10.90.41`

`nslookup pi.hole 8.8.8.8`

`nslookup pi-hole.net 10.10.50.41`

EDIT: ow ps. make sure DNS queries dont get looped back to Pi-hole.  
A typical loop that users create is to configure their router to be the upstream DNS server for Pi-hole.  
And the loop is closed when the router upstream WAN/Internet DNS setting points to the Pi-hole IP.  
The "Conditional forwarding" setting in Pi-hole can also create a DNS loop.

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 6:11pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/15 "2020-10-05T18:11:28Z")

</div>

Hi,

No output from the grep command.  
It was a Windows pc (at my work) who was connecting to it, from there I have access to all my VLANS, it are the Pi-Hole dns servers who are pushed.  
If I do the nslookup test on my pc all seem to resolve fine.  
Also ping to it responds (IP & hostname).  
But it won't let me access the admin page, also SSH and DNS not working.  
When I remove the aliases all is working fine again.

Router is set to cloudflare DNS, but I have DNS redirtection and maqquerade rules in my json file for devices who have hard coded DNS. Conditional forwarding is disabled... however is my 05-custom.conf not doing the same?

Did also tracert to the pihole ip and all goes like it should first out of the trusted vlan gateway and then to the pihole.

It'l like something blocked the ports, but why only when the aliases are activated.

Btw, as upstream for my pihole's I use Unbound

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 6:19pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/16 "2020-10-05T18:19:29Z")

</div>

Are you sure no DNS loop exists (like described in previous posting of mine) that can lockup the `pihole-FTL` daemon ?  
Usually you get "`time-out`" messages when doing a `nslookup` (without VPN).  
And load on the Pi-hole host is unusually high:

`uptime`

And check the logs live if `pihole-FTL` gets flooded:

`pihole -t`

Do some more `nslookup` checks to pinpoint!

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 6:20pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/17 "2020-10-05T18:20:44Z")

</div>

All nslookups give me instant aswer without delay, same for tracert all below 1ms  
Could it have something to do with Unbound?

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 6:23pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/18 "2020-10-05T18:23:27Z")

</div>

So it seems currently all is working as intended ?  
But after a while it grinds to a halt ?  
Thats what happens if you have a DNS loop.  
But yeah `unbound` can have issues too:

`journalctl -u unbound`

---

<div class="post-metadata">

**Author:** ![Kopernikus](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/7feea3/32.png) [@Kopernikus](https://discourse.pi-hole.net/u/Kopernikus)\
**Post date:** [October 5, 2020, 6:25pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/19 "2020-10-05T18:25:52Z")

</div>

No DNS lookups work but can't access the admin interface or connect through ssh on eth0.  
Just checked the pihole-FTL live all seems fine.  
It's like there a firewall rule who's not allow to connect.

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [October 5, 2020, 6:29pm UTC](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982/20 "2020-10-05T18:29:04Z")

</div>

Check local firewall on Pi-hole.  
Below is permissive allowing all:

```auto
pi@ph5:~ $ sudo iptables -nL
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

```

EDIT: one more:

`sudo netstat -nltup`

[Next page](https://discourse.pi-hole.net/t/pi-hole-vlan-advice-using-05-custom-conf-or-define-vlan-interfaces/38982.md?page=2)
