EDIT: Solved! I was using CIDR filtering in AdGuardHome, and set it so the only clients allowed to submit requests were:
10.0.0.0/24 # LAN subnet
10.6.0.0/24 # WireGuard subnet
...Trouble is, dnsmasq uses 127.0.0.1, so that effectively prevented the router itself from being able to make DNS queries, even though its IP was "technically" included.
It worked as soon as I added 127.0.0.1 to the allowed clients list.
Embarrassing.
Installed services
I SSH'd in and confirmed that traceroute, nslookup, ping, all forms of reaching the internet through hostnames fails, though pinging IPs works.
AdGuardHome and Unbound both seem to be doing fine as per init.d, and nothing in my dnsmasq has changed.
Interestingly, resolution works fine for devices on the network. Their DNS settings show the router (as per DNS Director), which means they should be hitting dnsmasq > unbound > adguardhome.
And since I'm using external DNS for the WAN, I'd imagine queries from the router itself should work even if the other devices weren't.
I'm sure a factory reset could fix it, but I'd prefer not to, as I finally got all my DHCP assignments and services just as I like them.
Any thoughts on where to poke next?
10.0.0.0/24 # LAN subnet
10.6.0.0/24 # WireGuard subnet
...Trouble is, dnsmasq uses 127.0.0.1, so that effectively prevented the router itself from being able to make DNS queries, even though its IP was "technically" included.
It worked as soon as I added 127.0.0.1 to the allowed clients list.
Embarrassing.
Installed services
- AdGuardHome
- Unbound
- Device: AX86U (latest firmware)
- WAN DNS: 1.1.1.1 (Cloudflare)
- LAN DNS: Router (via DNS Director)
- IPv6: Off
- Firewall: Off
- VPN: WireGuard Server, default settings (no clients connected)
I SSH'd in and confirmed that traceroute, nslookup, ping, all forms of reaching the internet through hostnames fails, though pinging IPs works.
AdGuardHome and Unbound both seem to be doing fine as per init.d, and nothing in my dnsmasq has changed.
Interestingly, resolution works fine for devices on the network. Their DNS settings show the router (as per DNS Director), which means they should be hitting dnsmasq > unbound > adguardhome.
And since I'm using external DNS for the WAN, I'd imagine queries from the router itself should work even if the other devices weren't.
I'm sure a factory reset could fix it, but I'd prefer not to, as I finally got all my DHCP assignments and services just as I like them.
Any thoughts on where to poke next?
Last edited: