New FWG, question about PiHole setup

Comments

14 comments

  • Avatar
    Andy brown

    https://help.firewalla.com/hc/en-us/articles/360051625034-Guide-How-to-install-Pi-Hole-on-Gold-Beta-

    just follow these instructions, it’s easy and highly recommend.

    1
    Comment actions Permalink
  • Avatar
    Lynk

    Thank you!

    0
    Comment actions Permalink
  • Avatar
    Lynk

    I installed Pihole last night following these instructions provided and when i log in today, it shows an update v5.1.2 available but it's already installed as i see in the yaml file? i also did a pull and no new updates? 

    0
    Comment actions Permalink
  • Avatar
    Andy brown

    Try and change your yaml file to this:

    pihole:
    container_name: pihole
    image: pihole/pihole:latest

    this will pull the latest update.

    Andy

    1
    Comment actions Permalink
  • Avatar
    Lynk

    Thanks Andy, 

    Made the change and waiting on pihole admin page to reflect update. 

    0
    Comment actions Permalink
  • Avatar
    Lynk

    do i need to stop/start the service for it to pull? still shows update available. Confirmed change in yaml file. 

    0
    Comment actions Permalink
  • Avatar
    Lynk

    nvm i just did this and it updated to latest. 

    sudo docker-compose up
    0
    Comment actions Permalink
  • Avatar
    Andy brown

    Yes sorry, should have mentioned that.  If you are used to pihole on RASPi then Pihole -up obviously doesn’t work anymore, as discovered you need to run the docker command.  I just wait until I’ve got the notification at the bottom of my pihole main screen before I run the command.

     

    0
    Comment actions Permalink
  • Avatar
    Lynk

    No worries. With pihole running on the FWG, can i enable DHCP on the pihole docker instance and disable on the FWG? Since it's internal interface, do i need to then point a route for my LAN to the pi IP?

    Do i lose anything by disabling DHCP on FWG?

    0
    Comment actions Permalink
  • Avatar
    Andy brown

    Considering I have a couple of LANs,  Vlans, OpenVPN and WireGuard all from Firewalla, with a dhcp range on each.  I’m not sure you would have the same flexibility if you run dhcp from Pi-hole.  What do you gain from moving it to Pi-hole? 

    0
    Comment actions Permalink
  • Avatar
    Ben Smith

    Hey all,

    I was also running PiHole on a Rasp 3b+ where all my network devices set the DNS to the Pi, PiHole wasn't managing DHCP (that was all done via the router), it just handled DNS filtering and upstream (using DNS-Crypt). Anyway, how does performance look when using a Firewalla Purple to docker run PiHole compared to running it native on a Pi 3b+? My PiHole instance had a gravity well of about 4.8m entries to block, and it runs this perfectly fine with about 30+ network devices.

     

    Many thanks,

    Ben

    0
    Comment actions Permalink
  • Avatar
    Andy brown

    I think you will struggle with RAM if you have 4.8Mil.  Have that on the gold but I’ve increased the RAM to 8GB

    0
    Comment actions Permalink
  • Avatar
    Ben Smith

    Ok that makes sense, I think there's 2Gb RAM in my FW Purple, though I'm pretty sure my Pi3b+ Only had 1Gb RAM (though its running the latest 32Bit RasberryPiOS and PiHole).

    I'm just wondering if its worth keeping the RasPi PiHole and let it continue handling all the DNS filtering and upstream or move it over to a docker container on FW or just ditch it altogether and use the FW for DNS filtering etc.

    It would be good if the FW had better list control, like adding in some of the various block lists out there, sadly the Target List functionality is seems only allows upto 200 entries per list). If I'm seeing this right.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The firewalla already has a list that's pretty large. At the moment it is north 70 million entries; unless you are really passionate about a list (for example log4j type of blocks), you really do not need to import other lists. Firewalla may block lesser (and alarm more if you are using the default mode) but if you tap on + and then "active protect" turn that into strict mode, it will likely to block a lot more. 

    1
    Comment actions Permalink

Please sign in to leave a comment.