# \[SOLVED\] Pi-hole on Amazon EC2 not filtering ads

**URL:** <https://discourse.pi-hole.net/t/solved-pi-hole-on-amazon-ec2-not-filtering-ads/11111>\
**Category:** Help\
**Created:** [July 24, 2018, 7:18am UTC](https://discourse.pi-hole.net/t/solved-pi-hole-on-amazon-ec2-not-filtering-ads/11111 "2018-07-24T07:18:33Z")\
**Posts on this page:** 1\
**Showing post:** 19

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [July 26, 2018, 5:58am UTC](https://discourse.pi-hole.net/t/solved-pi-hole-on-amazon-ec2-not-filtering-ads/11111/19 "2018-07-26T05:58:42Z")

</div>

Good job!

```
pi@noads:~ $ host pi.hole 52.214.17.59
;; connection timed out; no servers could be reached

```

> [@Egidio](#):
>
> I just found out that my Vodafone router had an option enabled called Safe DNS which prevent usage of custom DNS servers.

Yeah I suspected something like this happening so wanted to make sure with the dig version, it really was dnsmasq answering and not some safety mechanism on the router like rebind protection:

> [@Why won't Pi-hole work with DNS rebind protection enabled?](https://discourse.pi-hole.net/t/why-wont-pi-hole-work-with-dns-rebind-protection-enabled/3142):
>
> What is DNS rebind protection? If your router has an option called DNS rebind protection enabled, you may run into issues when trying to use Pi-hole as your DNS server. The reasons for this are quite technical, but to summarize what this option does in one sentence: DNS rebind protection does not allow DNS queries to be answered with a local IP address. Why does this interfere with Pi-hole? DNS rebind is meant to be a [countermeasure to an attack on your network](http://www.techrepublic.com/blog/it-security/public-ip-dns-rebinding-another-reason-not-to-use-default-passwords/). So in many cases, it's actu…

> [@Egidio](#):
>
> and on the Pi-hole server
> 
> nameserver 127.0.0.1  
> nameserver 172.31.0.2

This means processes/scripts/tasks/programs running on this VM that depend on DNS resolution will sometimes query Pi-hole's own DNS service on the loopback interface 127.0.0.1, and sometimes they will query the other DNS 172.31.0.2.  
Nothing wrong whit that but prefered is to have all DNS queries run through 127.0.0.1.

Tip: if you default the router settings @ home, and only configure the upstream DNS resolver for the router (often called WAN DNS or something) to be that of the Pi-hole IP address (no secondary DNS!), the clients, through DHCP, will be configured to use the router for DNS resolution.  
And in turn, the router will forward queries to Pi-hole to have them answered.  
That way you have your router caching DNS queries on your local network resulting in less traffic to the (slower) internet.

Ps. if you fiddle with DHCP settings, always make sure the client DHCP leases get renewed.  
Disconnect & reconnect network on the clients or reboot them.

---

_[View the full topic](https://discourse.pi-hole.net/t/solved-pi-hole-on-amazon-ec2-not-filtering-ads/11111)._
