# Pi-hole's DHCP service should announce different DNS to clients

**URL:** <https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282>\
**Category:** Help\
**Created:** [January 20, 2019, 10:21am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282 "2019-01-20T10:21:10Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![74cmonty](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/74cmonty/32/6196_2.png) [@74cmonty](https://discourse.pi-hole.net/u/74cmonty)\
**Post date:** [January 20, 2019, 10:21am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/1 "2019-01-20T10:21:10Z")

</div>

#### Please follow the below template, it will help us to help you!

## Expected Behaviour:

Pi-hole's DHCP service must announce different DNS server to clients

## Actual Behaviour:

Pi-hole's DHCP service announce Pi-hole's IP as DNS server to clients

## Debug Token:

llnlt32ffs

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [January 20, 2019, 3:12pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/2 "2019-01-20T15:12:47Z")

</div>

> [@74cmonty](#):
>
> ## Expected Behaviour:
> 
> Pi-hole’s DHCP service must announce different DNS server to clients

This is not the expected behavior. The expected behavior is that Pi-Hole provides itself as DHCP to clients, so they will route DNS through Pi-Hole.

There is a method to use an alternate DNS for individual clients, but this is not the default Pi-Hole behavior.

To do this, Pi-Hole must be the DHCP server. These thread provide guidance.

> [@Secondary DNS Server for DHCP](https://discourse.pi-hole.net/t/secondary-dns-server-for-dhcp/1874/10):
>
> Sure. So the dhcp-option=6,Pi-holeIP,SecondaryDNSIP Woyld look like this: dhcp-option=6,192.168.1.2,8.8.8.8 Assuming pi has 192.168.1.2 ip. Replace with what you have. 8.8.8.8 is the google dns So if you use your pi as dhcp server, it will push those ips as primary and secondary ips.

> [@Things you can do with dnsmasq!](https://discourse.pi-hole.net/t/things-you-can-do-with-dnsmasq/2595):
>
> I came up with some stuff that eases things a little bit with my Pi-Hole life. Some of the ideas here, I gathered from around the internet. I wanted to share my findings. These configs are to be placed in /etc/dnsmasq.d I do realize that these could easily be combined into a single 04-custom.conf, but for the ease of teaching myself things I can do with this,, I like them seperate. Bypass Pihole by MAC Address What this Does: Find the MAC Address of the device that you want to skip pihole, …

---

<div class="post-metadata">

**Author:** ![74cmonty](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/74cmonty/32/6196_2.png) [@74cmonty](https://discourse.pi-hole.net/u/74cmonty)\
**Post date:** [January 21, 2019, 9:59pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/3 "2019-01-21T21:59:33Z")

</div>

Will this work?  
Creating file /etc/dnsmasq.d/05-custom.conf

```auto
# DNS
dhcp-option=6,10.0.0.1 10.0.0.2
# NTP Server
dhcp-option=42,10.0.0.1

```

---

<div class="post-metadata">

**Author:** ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)\
**Post date:** [January 21, 2019, 10:27pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/4 "2019-01-21T22:27:58Z")

</div>

What are you trying to achieve? Redirecting DNS and DHCP to another non-Pi-hole server negates the Pi-hole server. No need to install Pi-hole if that is the only goal?

---

<div class="post-metadata">

**Author:** ![74cmonty](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/74cmonty/32/6196_2.png) [@74cmonty](https://discourse.pi-hole.net/u/74cmonty)\
**Post date:** [January 21, 2019, 10:40pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/5 "2019-01-21T22:40:47Z")

</div>

Actually this is true.  
However I have installed Identity Management System "[FreeIPA](https://www.freeipa.org/page/Main_Page)" that is providing a DNS.

In the config of FreeIPA I have defined a forwarder to Pi-hole.

As DHCP is running on Pi-hole, too I need to provide another DNS than Pi-hole to any DHCP client.

---

<div class="post-metadata">

**Author:** ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)\
**Post date:** [January 21, 2019, 10:59pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/6 "2019-01-21T22:59:36Z")

</div>

Are your IPA DNS servers hidden masters (auth only and only for your zone) or do they fully recurse? If they recurse and answer all queries for the clients you may find that just using Pi-hole as is and then point Pi-hole to use the IPA's BIND as the upstream works as well and gives you back the dashboard.

---

<div class="post-metadata">

**Author:** ![74cmonty](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/74cmonty/32/6196_2.png) [@74cmonty](https://discourse.pi-hole.net/u/74cmonty)\
**Post date:** [January 21, 2019, 11:24pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/7 "2019-01-21T23:24:32Z")

</div>

I'm not sure if I understand you correctly.  
My current understanding of the setup is this:

1. Client sends DNS request to IPA
2. Server checks if the request is served for local domain
3. If request is for any other domain IPA forwards the request to Pi-hole
4. Pi-hole serves the request if no blacklist rule applies

Where's my mistake / misunderstanding?

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [January 21, 2019, 11:54pm UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/8 "2019-01-21T23:54:38Z")

</div>

If this is the way you have it set up and it works, why do you need Pi-Hole to offer different DNS to clients? The only client that Pi-Hole would see in this setup is IPA. The remaining clients would have IPA for their DNS server.

---

<div class="post-metadata">

**Author:** ![74cmonty](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/74cmonty/32/6196_2.png) [@74cmonty](https://discourse.pi-hole.net/u/74cmonty)\
**Post date:** [January 22, 2019, 12:08am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/9 "2019-01-22T00:08:43Z")

</div>

Well, in this setup the DHCP server should provide the DNS IP of IPA to the Clients.  
However, I'm not sure if this is the best solution.  
Do you have other recommendation?

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [January 22, 2019, 12:21am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/10 "2019-01-22T00:21:59Z")

</div>

Got it. I misunderstood the traffic flow and forgot that Pi-Hole is your DHCP server.

What happens when you use Pi-Hole as the primary DNS and have it use IPA as the upstream server (the reverse of how you have it now)?

---

<div class="post-metadata">

**Author:** ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)\
**Post date:** [January 22, 2019, 1:02am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/11 "2019-01-22T01:02:24Z")

</div>

The big question is how is bind configured. Is it only allowed to answer responses for your local domain and to not answer internet accessible domains/pass non-local domains to bind's upstream. Or is it configured to answer all queries (local from internal database/files and recursively look up non-local domains?)

If bind only knows how to answer local domain queries then your current configuration is what you will have to do, but you will lose the dashboard as all queries to Pi-hole will come from only the bind server's IP address. If bind recurses then you can have it set as the upstream to Pi-hole. You gain back the dashboard and Pi-hole sees queries from the client IP address.

---

<div class="post-metadata">

**Author:** ![74cmonty](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/74cmonty/32/6196_2.png) [@74cmonty](https://discourse.pi-hole.net/u/74cmonty)\
**Post date:** [January 22, 2019, 7:10am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/13 "2019-01-22T07:10:11Z")

</div>

Well, you adress exactly the questions that I was asking myself, too.  
Based on the discussion in another thread regarding "cloudflared configuration" I come to the conclusion that it makes sense to configure `FreeIPA` as DNS upstream server.  
In my understanding of `FreeIPA` this should be possible by using the feature "forward". Hereby any request that cannot be served by internal DNS, means any external domain, would be served by the forward IP address (representing a public DNS server).

What I don't know up to now is if FreeIPA's DNS is working as a recursive DNS server as pointed out by DanSchaper.

---

<div class="post-metadata">

**Author:** ![system](https://discourse.pi-hole.net/uploads/default/original/3X/7/c/7c8792f649eeb921c5d2b4c41564ffa873d9a2b8.png) [@system](https://discourse.pi-hole.net/u/system)\
**Post date:** [February 12, 2019, 7:10am UTC](https://discourse.pi-hole.net/t/pi-holes-dhcp-service-should-announce-different-dns-to-clients/16282/14 "2019-02-12T07:10:20Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
