I’ve got a Surf SOHO Mk3, and a Pi-Hole (hosted on a Pi 4), I think I know what I have to do achieve the set up I want, but there seem to be some conflicting solutions in some of the threads on this topic. I might also be trying achieve something that I don’t quite need to do.
I’ve got 3 VLANs, and an untagged LAN, roughly:
Untagged (Machine that can access router)
Vlan1 (Other home machines)
Vlan3 (Pi-Hole), just created.
Layer 2 Isolation is on all of the above (am I right in assuming this does not affect ethernet devices)?
My goal was to leave Inter-Vlan routing off for everything, but still forward DNS requests through the Pi-Hole on the separate Vlan. My current understanding is that this is not possible, and Inter-Vlan routing must be enabled, is that correct?
I currently have it working with Inter-Vlan routing enabled, so the question is more, is it possible to keep it disabled somehow? The answer in Pi-hole with multiple VLANs didn’t seem to work for me, and the answers in Challenges using PiHole suggests the routing must be enabled (which makes sense).
I’ve tried forwarding the DNS requests using the DNS proxy and “DNS Forwarding Setup”, but that didn’t seem to help. It sounds like another alternative might just be to leave the Inter-Vlan routing enables but beef up the firewall rules. I like the idea of keeping the Vlans entirely separated (but the value of this might be a misunderstanding on my part.