HairyA00
Senior Member
Also a great idea!If you have Skynet installed, it has an IoT Blocking setting.
Also a great idea!If you have Skynet installed, it has an IoT Blocking setting.
As far as I am aware, you can have multiple entries in the dnsmasq.conf for the same parameter and it simply uses the last entry.I think i have noticed a speed bump in diversion's DNSMASQ setting section....
View attachment 20036
it mainly concerns bogus-priv and domain-needed functions
When it gets enabled it allows for it to be enabled twice in DNSMASQ.conf, note mine is automatically on in DNSMASQ, but when I use diversion to enable it, it allows for it to make two entries inside DNSMASQ.conf
View attachment 20037
the first place they appear listed is under the expanded-hosts option inside dnsmasq.
View attachment 20038
the second place it is listed is inside the diversion directives under add-hosts list....
Would this cause a problem for DNSMASQ if it is listed twice?
I can see that if you select No inside Diversion, that it should remove those entries from dnsmasq, but I don't think selected Yes should allow the entries to appear twice in the .conf file.
yes I understand DNSMASQ will still function, I want to know is there any performance impact or will it try to run the option "twice" using more system resources, etc etc.As far as I am aware, you can have multiple entries in the dnsmasq.conf for the same parameter and it simply uses the last entry.
[I have 'played' with the dnsmasq.conf file and found this out the hard way when I 'accidentally' set a parameter twice, once at the top of the file and once at the bottom !!! ]
Re: Address 1st-party tracker blocking
This also picked up by SANS NewsBites Vol. 21 Num. 093.
If you follow the link to the uBlock issue it references a 1st Party Tracker Host list that can be imported directly into pihole & Diversion.
https://github.com/uBlockOrigin/uBlock-issues/issues/780#issuecomment-559340435
Regularly updated list is:
https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt
This may be of interest to others.
Import the pixelserv CA into Windows (and all your devices where possible) following the Wiki instructions.View attachment 20058 Hi,
Got this installed. Im not looking to block ads on every single website in the www and seems to work directly connected to my router (going to test remote VPN connection next), Ads were not getting blocked so i updated the host file to the large one, i have a 16gb USB plugged in back, do i need to enable the swap file like it recommended ?..also on the PC that is directly connected to router, i have NOD32 running, it is CONSTANTLY throwing windows out since the Ads have been blocked, i looked closer at one and it referenced pixelserv when i clicked the link, im guessing thats it doing its job ?, what do i do about the constant complaints from NOD32, screenshot below. I keep trying to select 'remember action for this cert' but NOD is saying
"protocol filtering problem, failed to remember cert"
The .conf file is a list of instructions to dnsmasq to configure certain attributes when dnsmasq starts.yes I understand DNSMASQ will still function, I want to know is there any performance impact or will it try to run the option "twice" using more system resources, etc etc.
I have done that, works fine on my android but not on the laptop, well it works, ads are blocked but nod 32 keeps hammering me with those warningsImport the pixelserv CA into Windows (and all your devices where possible) following the Wiki instructions.
https://github.com/kvic-z/pixelserv...ificate#import-pixelserv-ca-on-client-devices
http://192.168.11.1/ca.crt
I have done that, works fine on my android but not on the laptop, well it works, ads are blocked but nod 32 keeps hammering me with those warnings
Post a clear screenshot of the Certification Path tab of the certificate showing if the Pixelserv CA is trusted or untrusted. Maybe you imported into the wrong certificate store in Windows.I have done that, works fine on my android but not on the laptop, well it works, ads are blocked but nod 32 keeps hammering me with those warnings
Maybe the steps in post #4325 might be the go?
This updates installed Entware packages.
Entware version: Entware (armv7sf-k3.2)
Installed from: bin.entware.net
1. show pixelserv-tls info
2. show installed packages
3. update or upgrade pixelserv-tls
4. update list of available packages
5. update and upgrade installed packages
Enter selection [1-5 e=Exit] 3
____________________________________________________
This updates or upgrades pixelserv-tls v2.2.1
1. Update pixelserv-tls, regular Entware version
2. Upgrade pixelserv-tls, regular Entware version
3. Upgrade pixelserv-tls to v2.3.0, Jack Yaz version
Enter your selection [1-3 e=Exit] 3
____________________________________________________
This upgrades pixelserv-tls to v2.3.0, Jack Yaz version.
This version is compliant with the new required
security settings enforced by Apple and other Companies.
See https://github.com/jackyaz/pixelserv-tls/releases/tag/2.3.0
It will install the appropriate version for your
Entware (armv7sf-k3.2) installation.
After successful upgrade, purge and re-generate the
CA certificate in ep , 3, 2.
Continue? [1=Yes e=Exit] 1
____________________________________________________
i Downloading pixelserv-tls
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 629 0 629 0 0 2428 0 --:--:-- --:--:-- --:--:-- 2526
100 26936 100 26936 0 0 34139 0 --:--:-- --:--:-- --:--:-- 34139
i Download successful, installing...
Package pixelserv-tls (2.2.1-1) installed in root is up to date.
Diversion 4.1.6 by thelonelycoder
RT-AC86U (aarch64) FW-384.13 @ 192.168.11.1
1.213M blocked domains by 1 hosts file(s)
649 t 649 w 649 n ads since Nov 29 17:20
____________________________________________________
d Diversion Standard enabled
c communication DivUn stats backup FWun
a ad-blocking to IP 192.168.11.2
l logging dnsmasq.log 32.0K
ep pixelserv-tls 192.168.11.2 v2.2.1
b blocking list Large Thu @ 2:00
el edit lists 0 w 0 b 0 wb
f follow dnsmasq.log
e exit Diversion more options o
____________________________________________________
Done Failed to update pixelserv-tls
What do you want to do?
Post a clear screenshot of the Certification Path tab of the certificate showing if the Pixelserv CA is trusted or untrusted. Maybe you imported into the wrong certificate store in Windows.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!