{"id":15715697,"url":"https://github.com/trinib/adguard-wireguard-unbound-dnscrypt","last_synced_at":"2025-04-12T23:43:01.773Z","repository":{"id":37758509,"uuid":"352102683","full_name":"trinib/AdGuard-WireGuard-Unbound-DNScrypt","owner":"trinib","description":"Linux ultimate self-hosted network security guide ║ Linux 终极自托管网络安全指南 ║ Guía definitiva de seguridad de red autohospedada de Linux ║ लिनक्स परम स्व-होस्टेड नेटवर्क सुरक्षा गाइड ║ Окончательное руководство по безопасности собственной сети Linux","archived":false,"fork":false,"pushed_at":"2024-02-22T01:54:34.000Z","size":25556,"stargazers_count":807,"open_issues_count":9,"forks_count":65,"subscribers_count":17,"default_branch":"main","last_synced_at":"2025-04-12T23:42:41.324Z","etag":null,"topics":["adblocker","adguard-home","anonymized-dns","cloudflare","dns-over-https","dns-over-tls","dnscrypt-proxy","guide","knot-resolver","network-security","nextdns","oblivious-dns-over-https","openvpn","quad9","ssl-certificates","stubby","tutorial","unbound","vpn","wireguard"],"latest_commit_sha":null,"homepage":"","language":"YAML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/trinib.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2021-03-27T15:07:21.000Z","updated_at":"2025-04-12T18:03:57.000Z","dependencies_parsed_at":"2024-03-17T00:06:50.503Z","dependency_job_id":null,"html_url":"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trinib%2FAdGuard-WireGuard-Unbound-DNScrypt","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trinib%2FAdGuard-WireGuard-Unbound-DNScrypt/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trinib%2FAdGuard-WireGuard-Unbound-DNScrypt/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/trinib%2FAdGuard-WireGuard-Unbound-DNScrypt/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/trinib","download_url":"https://codeload.github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248647256,"owners_count":21139081,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["adblocker","adguard-home","anonymized-dns","cloudflare","dns-over-https","dns-over-tls","dnscrypt-proxy","guide","knot-resolver","network-security","nextdns","oblivious-dns-over-https","openvpn","quad9","ssl-certificates","stubby","tutorial","unbound","vpn","wireguard"],"created_at":"2024-10-03T21:42:28.795Z","updated_at":"2025-04-12T23:43:01.753Z","avatar_url":"https://github.com/trinib.png","language":"YAML","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://img.shields.io/badge/License-MIT-blue.svg\"\u003e\n \u003cimg src=\"https://badges.frapsoft.com/os/v3/open-source.svg?v=103\"\u003e\n \u003cimg src=\"https://img.shields.io/badge/badges-awesome-green.svg\"\u003e\n \u003cimg src=\"https://img.shields.io/badge/Stay-Safe-red?logo=data:image/svg%2bxml;base64,PHN2ZyBpZD0iTGF5ZXJfMSIgZW5hYmxlLWJhY2tncm91bmQ9Im5ldyAwIDAgNTEwIDUxMCIgaGVpZ2h0PSI1MTIiIHZpZXdCb3g9IjAgMCA1MTAgNTEwIiB3aWR0aD0iNTEyIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjxnPjxnPjxwYXRoIGQ9Im0xNzQuNjEgMzAwYy0yMC41OCAwLTQwLjU2IDYuOTUtNTYuNjkgMTkuNzJsLTExMC4wOSA4NS43OTd2MTA0LjQ4M2g1My41MjlsNzYuNDcxLTY1aDEyNi44MnYtMTQ1eiIgZmlsbD0iI2ZmZGRjZSIvPjwvZz48cGF0aCBkPSJtNTAyLjE3IDI4NC43MmMwIDguOTUtMy42IDE3Ljg5LTEwLjc4IDI0LjQ2bC0xNDguNTYgMTM1LjgyaC03OC4xOHYtODVoNjguMThsMTE0LjM0LTEwMC4yMWMxMi44Mi0xMS4yMyAzMi4wNi0xMC45MiA0NC41LjczIDcgNi41NSAxMC41IDE1LjM4IDEwLjUgMjQuMnoiIGZpbGw9IiNmZmNjYmQiLz48cGF0aCBkPSJtMzMyLjgzIDM0OS42M3YxMC4zN2gtNjguMTh2LTYwaDE4LjU1YzI3LjQxIDAgNDkuNjMgMjIuMjIgNDkuNjMgNDkuNjN6IiBmaWxsPSIjZmZjY2JkIi8+PHBhdGggZD0ibTM5OS44IDc3LjN2OC4wMWMwIDIwLjY1LTguMDQgNDAuMDctMjIuNjQgNTQuNjdsLTExMi41MSAxMTIuNTF2LTIyNi42NmwzLjE4LTMuMTljMTQuNi0xNC42IDM0LjAyLTIyLjY0IDU0LjY3LTIyLjY0IDQyLjYyIDAgNzcuMyAzNC42OCA3Ny4zIDc3LjN6IiBmaWxsPSIjZDAwMDUwIi8+PHBhdGggZD0ibTI2NC42NSAyNS44M3YyMjYuNjZsLTExMi41MS0xMTIuNTFjLTE0LjYtMTQuNi0yMi42NC0zNC4wMi0yMi42NC01NC42N3YtOC4wMWMwLTQyLjYyIDM0LjY4LTc3LjMgNzcuMy03Ny4zIDIwLjY1IDAgNDAuMDYgOC4wNCA1NC42NiAyMi42NHoiIGZpbGw9IiNmZjRhNGEiLz48cGF0aCBkPSJtMjEyLjgzIDM2MC4xMnYzMGg1MS44MnYtMzB6IiBmaWxsPSIjZmZjY2JkIi8+PHBhdGggZD0ibTI2NC42NSAzNjAuMTJ2MzBoMzYuMTRsMzIuMDQtMzB6IiBmaWxsPSIjZmZiZGE5Ii8+PC9nPjwvc3ZnPg==\"\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"https://raw.githubusercontent.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/main/assets/images/awcu.gif\" width= \"700\"\u003e\n\n\u003c/p\u003e\n \u003cp align=\"center\"\u003e\n     \u003ca href=\"https://img.shields.io/github/stars/trinib/AdGuard-WireGuard-Unbound-Cloudflare?color=FFD700\u0026style=for-the-badge\" alt=\"GitHub Repo stars\"\u003e\n         \u003cimg src=\"https://img.shields.io/github/stars/trinib/AdGuard-WireGuard-Unbound-Cloudflare?color=FFD700\u0026style=for-the-badge\"\u003e\u003c/a\u003e\n     \u003ca href=\"https://img.shields.io/github/forks/trinib/AdGuard-WireGuard-Unbound-Cloudflare?color=00a671\u0026style=for-the-badge\" alt=\"GitHub forks\"\u003e\n         \u003cimg src=\"https://img.shields.io/github/forks/trinib/AdGuard-WireGuard-Unbound-Cloudflare?color=00a671\u0026style=for-the-badge\"\u003e\u003c/a\u003e\n     \u003ca href=\"https://img.shields.io/github/watchers/trinib/AdGuard-WireGuard-Unbound-Cloudflare?color=9700b2\u0026style=for-the-badge\" alt=\"GitHub watchers\"\u003e\n         \u003cimg src=\"https://img.shields.io/github/watchers/trinib/AdGuard-WireGuard-Unbound-Cloudflare?color=9700b2\u0026style=for-the-badge\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cdiv align=\"center\"\u003e\nTranslate Site | Traducir sitio  | 翻译网站 | Traduire le site | Перевести сайт | अनुवाद साइट\n\u003cbr\u003e\u003ca href=\"https://chrome.google.com/webstore/detail/google-translate/aapbdbdomjkkjkaonfhkkikfgjllcleb?hl=en\"\u003e\u003cimg src=\"https://www.vectorlogo.zone/logos/google_chrome/google_chrome-icon.svg\" width=20px height=20px\u003e\u003c/a\u003e\u0026nbsp;\u003ca href=\"https://addons.mozilla.org/en-US/firefox/addon/traduzir-paginas-web/\"\u003e\u003cimg src=\"https://www.vectorlogo.zone/logos/firefox/firefox-icon.svg\" width=20px height=20px\u003e\u003c/a\u003e \u003ca href=\"https://addons.opera.com/en/extensions/details/translator/\"\u003e\u003cimg src=\"https://www.vectorlogo.zone/logos/opera/opera-icon.svg\" width=20px height=20px\u003e\u003c/a\u003e\u003c/div\u003e \n\n\u003ch1 align=\"center\"\u003eSoftwares\u003c/h1\u003e\n\n\u003cdiv align=\"center\"\u003e \n \n_\u003ca href=\"https://adguard.com/en/adguard-home/overview.html\"\u003e\u003cb\u003eAdGuard Home\u003c/b\u003e\u003c/a\u003e or \u003ca href=\"https://pi-hole.net/\"\u003e\u003cb\u003ePi-hole\u003c/b\u003e\u003c/a\u003e_\u003c/br\u003eBlock banners, pop-ups and video advertisements network-wide\n\n _\u003ca href=\"https://www.wireguard.com/\"\u003e\u003cb\u003eWireGuard\u003c/b\u003e\u003c/a\u003e or \u003ca href=\"https://openvpn.net/\"\u003e\u003cb\u003eOpenVPN\u003c/b\u003e\u003c/a\u003e_\u003c/br\u003eA VPN server accessible from public networks (IPv4 \u0026 IPv6)\n\n_\u003ca href=\"https://www.nlnetlabs.nl/projects/unbound/about/\"\u003e\u003cb\u003eUnbound\u003c/b\u003e\u003c/a\u003e or \u003ca href=\"https://www.knot-resolver.cz/\"\u003e\u003cb\u003eKnot\u003c/b\u003e\u003c/a\u003e_\u003c/br\u003eA validating, recursive, caching DNS resolvers (DoT)\n\n_\u003ca href=\"https://dnsprivacy.org/dns_privacy_daemon_-_stubby/about_stubby/\"\u003e\u003cb\u003eStubby\u003c/b\u003e\u003c/a\u003e_\u003c/br\u003eDNS queries are sent to resolvers over an encrypted TLS connection providing increased privacy\n\n _\u003ca href=\"https://github.com/cloudflare/cloudflared\"\u003e\u003cb\u003eCloudflared Tunnel\u003c/b\u003e\u003c/a\u003e_\u003c/br\u003eA tunneling daemon that proxies traffic from a DNS network to your origins(DoH)\n\n_\u003ca href=\"https://dnscrypt.info/\"\u003e\u003cb\u003eDNScrypt\u003c/b\u003e\u003c/a\u003e_\u003c/br\u003eModern encrypted DNS protocols such as DNSCrypt v2, DNS-over-HTTPS, Anonymized DNSCrypt and oDoH (Oblivious DoH)\n \n#\n\u003c/div\u003e \n\u003cp align=\"right\"\u003e\n\u003ci\u003eAll software are free, open-source and\u0026nbsp;self-hosted\u0026nbsp;\u003c/i\u003e\u003c/br\u003e\u003ca href=\"https://github.com/trinib/Adguard-Wireguard-Unbound-Cloudflare/wiki/About\"\u003e\u003cb\u003eABOUT\u003c/b\u003e\u003c/a\u003e | \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/discussions/17\"\u003e\u003cb\u003eFAQ\u003c/b\u003e\u003c/a\u003e | \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki\"\u003e\u003cb\u003eWIKI\u003c/b\u003e\u003c/a\u003e | \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/discussions\"\u003e\u003cb\u003eDISCUSS\u003c/b\u003e\u003c/a\u003e\n\n\u003ch3 align=\"left\"\u003eDNS query time\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Objects/Hourglass%20Done.webp\" alt=\"Hourglass Done\" width=\"25\" height=\"25\" /\u003e\u003c/h3\u003e\nQuery speed results(Ethernet LAN) using \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Install-Dig-\u0026-WSL\"\u003eBIND9 dig\u003c/a\u003e tool:\n\n - AdGuard default DNS resolvers - `60-70 msec`\n - Public Cloudflare/Quad9/Google DNS Resolvers - `50-70 msec`\n - Self-hosted setup - `5-10 msec`\n\u003e [!NOTE]\n\u003e  Originally `0 msec` or same as ISP DNS speed but multiple blocklist with _excessive_ URLs slow down low-end devices affecting DNS query. This result was from a 1GB | 1.4GH ARM architecture. Blocklists used \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/blob/beb05c3a4b74a675dc88c43bcea41b08d00a04f3/bulkurls.py#L20\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e.\n\u003cdetails\u003e\u003csummary\u003ePreview\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Objects/Clapper%20Board.webp\" alt=\"Clapper Board\" width=\"25\" height=\"25\" /\u003e\u003c/summary\u003e\n\u003cp\u003e\n\nAdGuard default \u003cb\u003e\u003ci\u003evs\u003c/i\u003e\u003c/b\u003e Self-hosted:\n\nhttps://user-images.githubusercontent.com/18756975/150230438-b767e86f-4e18-4791-b5fe-0813615a37a3.mp4\n\nPublic Cloudflare/Quad9/Google:\u003c/br\u003e\n\u003ci\u003e(same results if addresses are added manually in the system's network DNS option fields)\u003c/i\u003e\n\nhttps://user-images.githubusercontent.com/18756975/150319049-3d8acdc9-624f-4b60-8ee2-b80227522252.mp4\n\n\u003c/p\u003e\n \u003c/details\u003e\n \n#\n# Table of contents\n \n - [Requirements](#requirements)\n - [Install Raspberry Pi OS](#install-raspberry-pi-os-) \u003cimg src=\"https://www.vectorlogo.zone/logos/raspberrypi/raspberrypi-icon.svg\" width=20px height=20px\u003e\n   - [Access Pi OS with SSH](#access-pi-os-with-ssh)\n - [Install AdGuard Home](#install-adguard-home-) \u003cimg src=\"https://www.vectorlogo.zone/logos/adguard/adguard-icon.svg\" width=20px height=20px\u003e\n   - [Setup devices to work with Adguard](#setup-devices-to-work-with-adguard)\n   - [Updating Adguard](#updating-adguard)\n   - [Setting up AdGuard blocklist](#setting-up-adguard-blocklist)\n     - [Add/Remove multiple URLs](#addremove-multiple-urls)\n   - [Uninstall AdGuard](#uninstall-adguard)\n   - [Install SSL certificate](#install-ssl-certificate)\u003cimg src=\"https://www.vectorlogo.zone/logos/letsencrypt/letsencrypt-icon.svg\" width=20px height=20px\u003e\u003cimg src=\"https://avatars.githubusercontent.com/u/27781978?s=280\u0026v=4\" width=20px height=20px\u003e\n   - [Install Pi-hole](#install-pi-hole-as-an-alternativeclick-here) \u003cimg src=\"https://upload.wikimedia.org/wikipedia/en/1/15/Pi-hole_vector_logo.svg\" width=21px height=21px\u003e\n - [Install Unbound](#install-unbound-) \u003cimg src=\"https://www.vectorlogo.zone/logos/nlnetlabsnl_unbound/nlnetlabsnl_unbound-icon.svg\" width=20px height=20px\u003e\n - [Install Knot](#install-knot-resolver-as-an-alternativeclick-here) \u003cimg src=\"https://www.vectorlogo.zone/logos/knot-resolvercz/knot-resolvercz-icon.svg\" width=20px height=20px\u003e\n - [Setup DNS security](#setup-dns-security-)\n   - [Configure DoH/oDoH](#configure-dohodoh)\n     - [Cloudflared tunnel](#cloudflared-tunnelclick-here) \u003cimg src=\"https://www.vectorlogo.zone/logos/cloudflare/cloudflare-icon.svg\" width=20px height=20px\u003e\n     - [DNScrypt proxy](#dnscrypt-proxyclick-here) \u003cimg src=\"https://i.imgur.com/lEHVsn3.png\" width=20px height=20px\u003e\n   - [Configure DoT on Unbound](#configure-dot-on-unbound)\n     - [Configure Stubby and Unbound](#configure-stubby-and-unbound) \u003cimg src=\"https://getdnsapi.net/static/logo.svg\" width=50px height=20px\u003e\n   - [Configure AdGuard with (DoH/DoT/oDoH)](#configure-adguard-with-dohdotodoh)\n     - [Monitor query logs](#use-tail-command-to-monitor-logs-in-realtime)\n - [Install WireGuard](#install-wireguard-) \u003cimg src=\"https://www.vectorlogo.zone/logos/wireguard/wireguard-icon.svg\" width=20px height=20px\u003e\n   - [Connecting VPN to Android/iOS Phone](#connecting-vpn-to-androidios-phone)\n   - [Connecting VPN to Windows](#connecting-vpn-to-windows)\n   - [Configure WireGuard with adblocking \u0026 DNS security](#configure-wireguard-with-adblocking--dns-security)\n   - [Install OpenVPN](#install-openvpn-as-an-alternativeclick-here)\u003c/a\u003e \u003cimg src=\"https://i.imgur.com/Agstbe5.png\" width=20px height=20px\u003e\n     - [Limit traffic](#limit-traffic)\n     - [Disable all IPv6](#disable-all-ipv6)\n   - [Test Vpn](#test-vpn) \u003cimg src=\"https://i.imgur.com/6Yf8Zra.png\" width=20px height=20px\u003e\n - [Extras](#extras)\n - [Repository Resources](#repository-resources)\n\n#\n# Requirements\n \nThis tutorial is installed on a Raspberry Pi with Debian OS. Other Linux \u003ca href=\"https://distrowatch.com/dwres.php?resource=popularity\"\u003eoperating system\u003c/a\u003e\u003ci\u003e(𝟹𝟸/𝟼𝟺bit)\u003c/i\u003e, \u003ca href=\"https://en.wikipedia.org/wiki/Category:Single-board_computers\"\u003ehardware\u003c/a\u003e or \u003ca href=\"https://github.com/dalisoft/awesome-hosting#vps\"\u003eVPS service\u003c/a\u003e can be used.\u003c/br\u003e_(Raspberry Pi OS is most simple and recommended for Pi. For more experience users, \u003ca href=\"https://dietpi.com/\"\u003eDietPi\u003c/a\u003e OS is also recommended)_\n\n   - A Raspberry Pi 3 or 4 version\n   - A router that supports port forwarding(most can)\n   - MicroSD USB card reader\n   - MicroSD card (8GB or bigger, at least Class 4)\n   - Ethernet cable\n   - (Optional if using monitor) MicroHDMI-(RPi 4) or HDMI-(RPi 3)\n\n#\n\u003ch1 align=\"center\"\u003e\u003cb\u003e\u003ci\u003eInstall Raspberry Pi OS\u003c/b\u003e\u003c/i\u003e \u003c/h1\u003e\n\nRaspberry Pi OS comes in desktop and lite versions(use lite for \u003ca href=\"https://www.google.com/search?q=What+is+a+headless+operating+system%3F\u0026client=firefox-b-d\u0026sxsrf=APq-WBvlqMZasn_klYxS5HZmhKQlduKYuQ%3A1650123816301\u0026ei=KORaYtz7EYOdwbkP74G16AE\u0026ved=0ahUKEwjcr5-f9pj3AhWDTjABHe9ADR0Q4dUDCA0\u0026uact=5\u0026oq=What+is+a+headless+operating+system%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyCAghEBYQHRAeOgcIABBHELADSgQIQRgASgQIRhgAUMEBWMEBYNAEaAFwAXgAgAFqiAFqkgEDMC4xmAEAoAECoAEByAEIwAEB\u0026sclient=gws-wiz\"\u003eheadless\u003c/a\u003e mode). It can be accessed with a monitor/keyboard/mouse or connect via \u003ca href=\"https://www.google.com/search?q=What+is+SSH+in+Linux%3F\u0026client=firefox-b-d\u0026sxsrf=APq-WBsiHvek7g0OrBHWDbEy-x7m-B6O3Q%3A1650481751310\u0026ei=V1pgYoHNEs-uwbkPtI25mAI\u0026ved=0ahUKEwjB1PrTq6P3AhVPVzABHbRGDiMQ4dUDCA0\u0026uact=5\u0026oq=What+is+SSH+in+Linux%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyBggAEBYQHjIGCAAQFhAeMgYIABAWEB4yBggAEBYQHjIGCAAQFhAeMgYIABAWEB4yBggAEBYQHjIGCAAQFhAeMgYIABAWEB4yBggAEBYQHjoHCCMQsAMQJzoHCAAQRxCwAzoHCAAQsAMQQzoKCAAQ5AIQsAMYAToPCC4Q1AIQyAMQsAMQQxgCSgQIQRgASgQIRhgBUM8IWM8IYJAMaAFwAXgAgAFxiAFxkgEDMC4xmAEAoAECoAEByAERwAEB2gEGCAEQARgJ2gEGCAIQARgI\u0026sclient=gws-wiz\"\u003essh\u003c/a\u003e from a terminal.\u003cbr\u003eRaspberry Pi OS \u003cb\u003ecannot\u003c/b\u003e be setup through the \u003ca href=\"https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/#Headless%20setup\"\u003ewizard\u003c/a\u003e anymore, the \u003ca href=\"https://www.raspberrypi.com/news/raspberry-pi-imager-imaging-utility/\"\u003eImager\u003c/a\u003e utility is needed to preconfigure an image user account.\n\n * Install Raspberry Pi Imager: https://www.raspberrypi.com/software/\n\n- Open Pi Imager tool and choose OS, go to advanced settings and configure user details. Then choose storage and write.\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/S6pDPZv.png\"\u003e\u003c/p\u003e\n \n\u003ci\u003ePlace SD card into the Raspberry Pi, plug in Ethernet cable and boot up\u003c/i\u003e\n\n## Access Pi OS with SSH\n\n * Wait for a minute for Pi's first boot up\n\n * Open browser and login router's admin panel(default \u003ca href=\"https://www.google.com/search?q=what+is+gateway+ip+address\u0026client=firefox-b-d\u0026biw=1440\u0026bih=660\u0026sxsrf=ALiCzsaDFykPI5rNea5FvSd5YDwm5cJNUg%3A1667340103798\u0026ei=R5dhY-quMJaGwbkPt5is6Ao\u0026oq=what+is+my+gateway+address\u0026gs_lcp=Cgxnd3Mtd2l6LXNlcnAQARgAMgoIABBHENYEELADMgoIABBHENYEELADMgoIABBHENYEELADMgoIABBHENYEELADMgoIABBHENYEELADMgoIABBHENYEELADMgoIABBHENYEELADMgoIABBHENYEELADMgcIABCwAxBDMgcIABCwAxBDSgQIQRgASgQIRhgAUABYAGCaFWgBcAF4AIABAIgBAJIBAJgBAMgBCsABAQ\u0026sclient=gws-wiz-serp\"\u003eIP gateway address\u003c/a\u003e)\n \n * Find list of all devices connected to network and copy the IP address of the Raspberry Pi. It will most likely have the hostname `raspberrypi`\n\n * Open terminal on host machine \u003ci\u003e(Windows PowerShell or RaspController for \u003ca href=\"https://play.google.com/store/apps/details?id=it.Ettore.raspcontroller\u0026hl=en\u0026gl=US\"\u003eAndroid\u003c/a\u003e\u0026\u003ca href=\"https://apps.apple.com/us/app/raspcontroller/id1584315865\"\u003eiOS\u003c/a\u003e)\u003c/i\u003e.\n\nType the following command:\n```\nssh pi@pi's IP address\n```\n\u003ci\u003eUse right mouse button to paste text in Windows PowerShell\u003c/i\u003e.\n\nType “yes” for fingerprint question, and enter password.\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/Wf30jxG.jpg\"\u003e\u003c/p\u003e\n\nRun in terminal:\n```bash\nsudo apt update -y \u0026\u0026 sudo apt upgrade -y\n```\n*_Reboot when finished_*\n```bash\nsudo reboot\n```\n**[\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e Return to contents \u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e](#table-of-contents)**\n\n#\n\u003ch1 align=\"center\"\u003e\u003cb\u003e\u003ci\u003eInstall AdGuard Home\u003c/b\u003e\u003c/i\u003e \u003c/h1\u003e\n\nInstallation scripts are from \u003ca href=\"https://github.com/AdguardTeam/AdGuardHome\"\u003eAdGuard Home\u003c/a\u003e main project. Follow to keep updated.\u003cbr\u003e\nRun one of the following command in terminal:\n\nStable:\n```bash\ncurl -s -S -L https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh | sh -s -- -v\n```\nBeta - testing version of AdGuard Home. More or less stable versions:\n```bash\ncurl -s -S -L https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh | sh -s -- -c beta\n```\nEdge - newest version of AdGuard Home. New updates are pushed to this channel daily and might not be stable:\n```bash\ncurl -s -S -L https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh | sh -s -- -c edge\n```\n * When installation is finished, it will show the `links` to your AdGuard home page(Get Started) in terminal\n\n * Choose `Eth0` in **Listen Interfaces** option\n \n \u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://i.imgur.com/5W70PLb.png\" width=580px height=650px\u003e\u003c/p\u003e\n\n * Set up username\u0026password and then login admin panel\n\n\u003e [!TIP]\n\u003e In general settings, can set \"Query logs retention\" to `24 hours`. (on forums some users state logs fill up which slows down Pi and needing a reboot, if using powerful device, no need to change settings)\n\n## Setup devices to work with AdGuard\n\n - For Android/Apple, go to WiFi advanced settings and select static option. In `DNS 1` field enter \"Pi's IP\" address\n\n \u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://i.imgur.com/nxpiqDw.jpg\" width=450px height=580px\u003e\u003c/p\u003e\n\n - For PC/Windows\n\n    - \u003ci\u003eIPv4\u003c/i\u003e\n\n    Go to network settings / change adapter options, right click in properties and select \"Internet Protocol Version 4(TCP/IPv4)\". Enter Pi's IP address in `Preferred DNS` server.\n\n    - \u003ci\u003eIPv6 (needed for `DoH`/`DoT`/`oDoH` to detect if using it)\u003c/i\u003e\n\n     Go to \"Internet Protocol Version 6(TCP/IPv6)\" Enter \u003ca href=\"https://www.google.com/search?q=what+is+%3A%3A1\u0026client=firefox-b-d\u0026sxsrf=ALiCzsYu-GId0NA6gwu0SgOIpe6KTsOmAw%3A1667330913170\u0026ei=YXNhY-yLCtWdwbkP-4u4iAY\u0026ved=0ahUKEwiswLXW2437AhXVTjABHfsFDmEQ4dUDCA4\u0026uact=5\u0026oq=what+is+%3A%3A1\u0026gs_lcp=Cgxnd3Mtd2l6LXNlcnAQAzIECCMQJzIECCMQJzIECCMQJzIFCAAQkQIyBQgAEJECMgUIABCRAjIFCAAQkQIyCAgAELEDEIMBMggIABCxAxCDATIFCAAQgARKBAhBGABKBAhGGABQsgJY2BpgnhtoAXAAeACAAfACiAGTBZIBBTItMS4xmAEAoAEBwAEB\u0026sclient=gws-wiz-serp\"\u003e`::1`\u003c/a\u003e\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/8gsDk3z.jpg\"\u003e\u003c/p\u003e\n\n## Updating AdGuard\n \nAdGuard Home can be updated from its user interface or \u003ca href=\"https://github.com/AdguardTeam/AdGuardHome/wiki/FAQ#how-to-update-adguard-home-manually\"\u003emanually\u003c/a\u003e from command line.\u003cbr\u003e\n_Use script constructed with manual commands and can be set to autorun\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/AdGuard-Home-update-script\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e_.\n\n## Setting up AdGuard blocklist\n\nIn AdGuard homepage under filters, select DNS blocklist section for adding URLs.\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/xAlbKPW.png\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n\u003cbr\u003e\n\u003ca href=\"https://github.com/T145/black-mirror\"\u003e\u003cimg src=\"https://raw.githubusercontent.com/T145/black-mirror/master/.github/images/logo.png\" width=220px height=60px\u003e\u003c/a\u003e\n\u003cbr\u003e\nAiming to promote security, safety, and sanity across the internet! \u003c/p\u003e\n\n\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Animated-Fluent-Emojis/master/Emojis/Hand%20gestures/Oncoming%20Fist.png\" alt=\"Oncoming Fist\" width=\"25\" height=\"25\" /\u003eBIG THANKS\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Animated-Fluent-Emojis/master/Emojis/Hand%20gestures/Oncoming%20Fist.png\" alt=\"Oncoming Fist\" width=\"25\" height=\"25\" /\u003e to \u003ca href=\"https://github.com/T145\"\u003eT145\u003c/a\u003e\u003cbr\u003e\nLarge list of Blocklists and Allowlists Sources\u003ca href=\"https://github.com/T145/black-mirror/blob/master/dist/SOURCES.md\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e\n\u003cb\u003e\n\u003c/b\u003e\n\n\u003e [!CAUTION]\n\u003e Some Blocklists can block important web content. To unblock, go to \"Query Log\" section, hover cursor over that specific query\u003ci\u003e(look for client IP \u0026 time)\u003c/i\u003e to show _unblock_ option. The links is automatically created in \"Custom filtering rules\" example: `@@||bitly.com^$important`(can add the websites manually as well).\n\n## Add/Remove multiple URLs\n\nOnly one URL can be added at a time in DNS blocklist with AdGuard for now, but a python script can be used to add multiple URLs at once.\u003cbr\u003e\nCreate a new python file(bulkurls.py):\n```bash\nnano bulkurls.py\n```  \n\nThen copy and paste script text\u003ca href=\"https://raw.githubusercontent.com/trinib/Adguard-Wireguard-Unbound-Cloudflare/main/bulkurls.py\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e. Set `your AdGuard credentials` and save (control+x then y then enter).\n \n\u003e [!NOTE]\n\u003e If using **DietPi** install `sudo apt-get install python3-pip -y \u0026\u0026 pip install requests` for it is not currently installed by default.\n  \nTo run : `sudo python3 bulkurls.py`\u003cbr\u003e\n_(Reboot when finished)_\n\nTo **remove** change `add` in \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/62ba01ed8ed3a5bc5294b9fe7ee38c3e83ae1b86/bulkurls.py#L150\"\u003esecond of last line\u003c/a\u003e to `remove` in bulkurls.py file.\u003cbr\u003e\nOr just change it from command line in terminal:\n```bash\nsed -i 's/add_url/remove_url/g' bulkurls.py\n\n# Revert\nsed -i 's/remove_url/add_url/g' bulkurls.py\n```\n\n## Uninstall AdGuard\n\nRun this \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/main/assets/scripts/remove_adguard.sh\"\u003escript\u003c/a\u003e from repo through network using \u003ca href=\"https://www.google.com/search?q=What+does+cURL+actually+do%3F\u0026client=firefox-b-d\u0026sxsrf=ALiCzsbIVTaRzlDt3jC6H5lirpsy2S0LoA%3A1654699803869\u0026ei=G7egYprXNNbawbkP38uIqAE\u0026ved=0ahUKEwja0JOQjZ74AhVWbTABHd8lAhUQ4dUDCA0\u0026uact=5\u0026oq=What+does+cURL+actually+do%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyBQghEKABMgUIIRCgATIFCCEQoAEyBQghEKABMggIIRAeEBYQHTIICCEQHhAWEB0yCAghEB4QFhAdMggIIRAeEBYQHTIICCEQHhAWEB0yCAghEB4QFhAdOgcIIxCwAxAnOgcIABBHELADSgQIQRgASgQIRhgAUI8DWI8DYNgGaAFwAXgAgAGcAYgBnAGSAQMwLjGYAQCgAQKgAQHIAQnAAQE\u0026sclient=gws-wiz\"\u003ecurl\u003c/a\u003e in terminal:\n```bash\ncurl -s -L https://raw.githubusercontent.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/main/assets/scripts/remove_adguard.sh | sh\n```\n\n## Install SSL certificate\n\nIf using AdGuard Home on a `VPS(Virtual private server)`, get a \u003ca href=\"https://www.google.com/search?q=What+is+purpose+of+SSL+certificate%3F\u0026client=firefox-b-d\u0026sxsrf=APq-WBsi9wVR8QaPcOuMXEpKVMqtOxrI-A%3A1650799271342\u0026ei=pzJlYvDEFJbUkPIP48mPkAY\u0026ved=0ahUKEwiwtKfByqz3AhUWKkQIHePkA2IQ4dUDCA0\u0026uact=5\u0026oq=What+is+purpose+of+SSL+certificate%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyBggAEBYQHjIGCAAQFhAeOgcIABBHELADOgcIABCwAxBDOgoIABDkAhCwAxgBOhUILhDHARCvARDUAhDIAxCwAxBDGAI6EgguEMcBENEDEMgDELADEEMYAkoECEEYAEoECEYYAVC7AVi7AWDnBGgBcAF4AIABbYgBbZIBAzAuMZgBAKABAqABAcgBE8ABAdoBBggBEAEYCdoBBggCEAEYCA\u0026sclient=gws-wiz\"\u003eSSL certificate\u003c/a\u003e to make connection secure and data safe\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Create-auto-renewal-SSL-certificate\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e. In this case your DNS resolver(AdGuard Home) resides outside your network, and your DNS requests have better protection from the third parties.\n\n### _Install Pi-hole as an alternative\u003ca href=\"https://github.com/pi-hole/pi-hole/#one-step-automated-install\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e_\n\n**[\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e Return to contents \u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e](#table-of-contents)**\n\n#\n\u003ch1 align=\"center\"\u003e\u003cb\u003e\u003ci\u003eInstall Unbound\u003c/b\u003e\u003c/i\u003e \u003c/h1\u003e\n\n\u003e [!TIP]\n\u003e Before installing other DNS resolvers, it is a good idea to turn off \u003ca href=\"https://www.freedesktop.org/software/systemd/man/systemd-resolved.service.html\"\u003esystemd-resolved\u003c/a\u003e DNSStubListener(\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/issues/27\"\u003eissue#27\u003c/a\u003e).\n\n`OPTIONAL:` Installing via the package manager is the easiest option with automatic updates and stable versions. The downside is that it can be outdated for some distributions or not have all the compile-time options included that you want.\u003cbr\u003e**Building and compiling** Unbound yourself ensures that you have the latest version and all the compile-time options you desire\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Build-Unbound-from-source\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e.\n\nFor the version from package manager, run the following command in terminal:\n```bash\nsudo apt install unbound -y\n```\n\u003e [!IMPORTANT]\n\u003e If using **DietPi** or other OS that do not auto insert `nameserver 127.0.0.1` in resolv.conf(to check - `sudo nano /etc/resolv.conf`) and want to query cache on \u003ca href=\"https://www.google.com/search?q=localhost+in+linux+meaning\u0026client=firefox-b-d\u0026biw=1440\u0026bih=660\u0026sxsrf=ALiCzsZQjrruvwGr5xLnu1DMlt8k1FU1jQ%3A1667331220024\u0026ei=lHRhY_iPAZydwbkP6sWwwAw\u0026oq=localhost+in+linux+mea\u0026gs_lcp=Cgxnd3Mtd2l6LXNlcnAQARgAMgYIABAWEB4yBQgAEIYDMgUIABCGAzIFCAAQhgM6CggAEEcQ1gQQsAM6BQgAEIAEOgUIIRCgAToICCEQFhAeEB1KBAhBGABKBAhGGABQjThY_D9g7UhoAnABeACAAdoBiAHyBJIBBTAuMy4xmAEAoAEByAEIwAEB\u0026sclient=gws-wiz-serp\"\u003elocal\u003c/a\u003e hosts, just install resolvconf package and restart unbound-resolvconf.service which should be automatically set:\n\u003e \n\u003e     sudo apt-get install resolvconf -y \u0026\u0026 sudo systemctl restart unbound-resolvconf.service\n\u003e Run `ping -c 3 google.com` to confirm localhost is reachable to internet. If not, set/add your default network's dns/gateway or whatever was the default\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Set-permanent-DNS-nameservers\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e\n\nConfirm 127.0.0.1 address interface is up:\n```bash\n## Install dig: sudo apt install dnsutils\ndig google.com @127.0.0.1\n```\n![image](https://user-images.githubusercontent.com/18756975/198690997-62cea763-f1c1-4b15-b68c-e7a05f483182.png)\n\n* For recursively querying a host that is not cached as an address, the resolver needs to start at the top of the server tree and query the root servers, to know where to go for the top level domain for the address being queried. Unbound comes with default built-in hints.\u003cbr\u003eDownload latest:\n```bash\nwget -O root.hints https://www.internic.net/domain/named.root \u0026\u0026 sudo mv root.hints /var/lib/unbound/\n```\n\n* This needs to update every 6 months using \u003ca href=\"https://www.google.com/search?q=How+does+cron+job+work%3F\u0026client=firefox-b-d\u0026sxsrf=ALiCzsbaAmCCZqLJt2cOtQ3UXn7wxrWD3Q%3A1651353477111\u0026ei=hadtYt-vBoavqtsP_fGX4Ak\u0026ved=0ahUKEwifhpuL27z3AhWGl2oFHf34BZwQ4dUDCA0\u0026uact=5\u0026oq=How+does+cron+job+work%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyBggAEBYQHjoHCAAQRxCwAzoHCAAQsAMQQ0oECEEYAEoECEYYAFDTAVjTAWDRBmgBcAF4AIABfYgBfZIBAzAuMZgBAKABAqABAcgBCcABAQ\u0026sclient=gws-wiz\"\u003ecron job\u003c/a\u003e. Enter in command line `crontab -e`, it will ask select an editor(choose 1), paste these lines at the bottom of crontab and save (control+x then y then enter):\n\n\u003e   1 0 1 */6 * wget -O root.hints https://www.internic.net/domain/named.root\u003cbr\u003e\n\u003e   2 0 1 */6 * sudo mv root.hints /var/lib/unbound/\n\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/26ro62t.jpg\"\u003e\u003c/p\u003e\n \nSkip straight ahead to configuring DoT in this [**section**](#configure-dot-on-unbound), and setup with AdGuard in this [**section**](#configure-adguard-with-dohdotodoh) if not interested in Stubby or Cloudflared or DNScrypt proxy below.\n \n### _Install Knot Resolver as an alternative\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Install-Knot-Resolver\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e_\n\n**[\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e Return to contents \u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e](#table-of-contents)**\n\n#    \n\u003ch1 align=\"center\"\u003e\u003cb\u003e\u003ci\u003eSetup DNS Security\u003c/b\u003e\u003c/i\u003e \u003c/h1\u003e\n\n## Configure DoH/oDoH\n\u003ci\u003eOption 1 (Simple)\u003c/i\u003e\u003ch4\u003eCloudflared Tunnel\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Install-Cloudflared-Tunnel-(DoH)\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e:\u003c/h4\u003e- DNS over HTTPS only\u003cbr\u003e\u003cbr\u003e\n\n\u003ci\u003eOption 2 (Advanced) - no need for cloudflare tunnel or stubby methods\u003c/i\u003e\u003ch4\u003eDNScrypt proxy\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Install-DNScrypt-proxy-(DoH)(oDoH)(Anonymized-DNS)\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e:\u003c/h4\u003e- DNS over HTTPS\n\n\u003cdetails\u003e\u003csummary\u003e\u003cb\u003eOblivious DNS Over HTTPS\u003c/b\u003e\u003c/summary\u003e\n\u003cp\u003e\n \n_\u003ca href=\"https://blog.cloudflare.com/oblivious-dns/\"\u003eOblivious DNS Over HTTPS\u003c/a\u003e\u003c/h4\u003e(oDoH) is a newly proposed open-source DNS standard built by engineers from Cloudflare, Apple, and Fastly which is supposed to increase the privacy of already existing DNS Over HTTPS_.\u003cbr\u003e\n \n \u003c/p\u003e\n \u003c/details\u003e\n \n\u003cdetails\u003e\u003csummary\u003e\u003cb\u003eAnonymized-DNS\u003c/b\u003e\u003c/summary\u003e\n\u003cp\u003e\n \n_\u003ca href=\"https://github.com/DNSCrypt/dnscrypt-proxy/wiki/Anonymized-DNS\"\u003eAnonymized DNS\u003c/a\u003e is a lightweight alternative to Tor and SOCKS proxies, dedicated to DNS traffic. They hide the client IP address to DNS resolvers, providing anonymity in addition to confidentiality and integrity._.\n \n \u003c/p\u003e\n \u003c/details\u003e\n \n## Configure DoT on Unbound\n\nDownload unbound \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/main/unbound.conf\"\u003econfiguration\u003c/a\u003e file with DNS over TLS settings and move it to unbound folder.\u003cbr\u003e\nEnter in terminal:\n```bash\nwget https://raw.githubusercontent.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/main/unbound.conf \u0026\u0026 sudo mv unbound.conf /etc/unbound/unbound.conf.d/\n```\n - Choose DNS provider\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/DNS-Providers#unbound\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e\n\nRestart unbound service and check status:\n```bash\nsudo systemctl restart unbound \u0026\u0026 sudo systemctl status unbound \n```\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/Ul32WLD.png\" width=700 height=220\u003e\u003c/p\u003e\n \nRun `dig google.com @127.0.0.1` and check for `NOERROR` status to confirm its connected to DNS server.\n\n![image](https://user-images.githubusercontent.com/18756975/198691170-142c0f62-c5c2-4148-a7bf-f7833ca2ebc0.png)\n\n## Configure Stubby and Unbound\n\nUse Unbound for caching and Stubby as a \u003ca href=\"https://www.google.com/search?q=How+does+TLS+proxy+work%3F\u0026client=firefox-b-d\u0026sxsrf=ALiCzsaNlPunZpYtzDVoVA6PVTkY6rOqyQ%3A1651275938995\u0026ei=onhsYsqtPImRggez_K2oBA\u0026ved=0ahUKEwjKhpSeurr3AhWJiOAKHTN-C0UQ4dUDCA4\u0026uact=5\u0026oq=How+does+TLS+proxy+work%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyBQghEKABMgUIIRCgATIFCCEQoAEyBQghEKABMggIIRAWEB0QHjIICCEQFhAdEB4yCAghEBYQHRAeMggIIRAWEB0QHjIICCEQFhAdEB4yCAghEBYQHRAeOgcIABBHELADSgQIQRgASgQIRhgAUMUBWMUBYMkHaAFwAXgAgAGfAYgBnwGSAQMwLjGYAQCgAQKgAQHIAQjAAQE\u0026sclient=gws-wiz\"\u003eTLS forwarder\u003c/a\u003e\n\u003e [!WARNING]  \n\u003e Stubby and DNScrypt **should not** be used together when both are set to run as a forwarder in Unbound, else redundant caching will occur. Use with Cloudflare tunnel only.\n\n`OPTIONAL:` **Building and compiling** Stubby yourself ensures that you have the latest version\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Build-Stubby-from-source\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e.\n \nInstall the version from package manager:\n```bash\nsudo apt install stubby -y\n```\n- Download stubby \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/main/stubby.yml\"\u003econfiguration\u003c/a\u003e file and replace with default one in stubby folder:\n```bash\nwget https://raw.githubusercontent.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/main/stubby.yml \u0026\u0026 sudo mv stubby.yml /etc/stubby/\n```\n\n - Forward Stubby address in Unbound upstreams. Open `sudo nano /etc/unbound/unbound.conf.d/`\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/main/unbound.conf\"\u003e`unbound.conf`\u003c/a\u003e and uncomment Stubby addresses(remove # infront of lines [169](https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/68726b2c1e24d1940ac82775be9aa76748f564d2/unbound.conf#L169)\u0026[170](https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/blob/68726b2c1e24d1940ac82775be9aa76748f564d2/unbound.conf#L170))\u003cbr\u003eOr do it from command line:\n```bash\nawk '{sub(/[#]forward-addr: 127.0.0.1@8053/,\"forward-addr: 127.0.0.1@8053\") || sub(/[#]forward-addr: ::1@8053/,\"forward-addr: ::1@8053\")}1' /etc/unbound/unbound.conf.d/unbound.conf \u003e unbound.conf \u0026\u0026 sudo mv unbound.conf /etc/unbound/unbound.conf.d/\n```\n - Choose DNS provider\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/DNS-Providers#stubby\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e\n\nRestart stubby service and check status:\n```bash\nsudo systemctl restart stubby \u0026\u0026 sudo systemctl status stubby \n```\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/PCxwdDC.png\" width=700 height=240\u003e\u003c/p\u003e\n \n## Configure AdGuard with `(DoH/DoT/oDoH)`\n\n * In AdGuard homepage under settings, select **DNS settings**\n\n * Delete everything from both _**Upstream**_ and _**Bootstrap DNS**_ server options and add the following for:\n\n   - DNS over TLS(unbound/knot) : `127.0.0.1:53`\n \n   - DNS over HTTPS/Oblivious DNS over HTTPS :\n \n      - `127.0.0.1:5053`(cloudflared tunnel) \n      - `127.0.0.1:5353`(dnscrypt proxy)\n \n   - TLS forwarder(stubby) : `127.0.0.1:8053` \n\n\n- Select \u003ca href=\"https://adguard.com/en/blog/in-depth-review-adguard-home.html#dns\"\u003eParallel Request\u003c/a\u003e option for DNS resolvers to work simultaneously.\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/iQRdMax.png\" width=650px height=320px\u003e\u003c/p\u003e\n \n- In DNS setting look for DNS cache configuration section and set cache size to `0` (caching is already handled by Unbound) and save.\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/TdzhNUo.png\" width=650px height=350px\u003e\u003c/p\u003e\n \n\u003cp align=\"center\"\u003e\nClick apply and test upstreams\u003c/p\u003e\n\n#### Now go to https://1.1.1.1/help in browser and these options should output 'Yes'.\n\u003e [!NOTE]\n\u003e only detects for cloudflare servers in the first 3 info lines\n - [x] Connected to 1.1.1.1\n - [x] DNS over HTTPS(DoH)\n - [x] DNS over TLS(DoT)\n - [ ] DNS over WARP\n \u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://i.imgur.com/ootfGYq.jpg\" width=650px height=300px\u003e\u003c/p\u003e\n \n### Sometimes DoH or DoT shows no?\nThis could just be a fault on 1.1.1.1/help and host cause according to logs, for example DNScrypt with DNS over HTTPS shows it **does recieve a query response/PASS** although when showing \"no\" for DNS over HTTPS.\n\n\u003cdetails\u003e\u003csummary\u003eQuery logs\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Animated-Fluent-Emojis/master/Emojis/Hand%20gestures/Eyes.png\" alt=\"Eyes\" width=\"25\" height=\"25\" /\u003e\u003c/summary\u003e\n\u003cp\u003e\n\nhttps://user-images.githubusercontent.com/18756975/197397288-18c7f33b-abb3-4628-b8e3-1ad29623f693.mp4\n\nSame goes in Unbound logs when DNS over TLS shows \"no\"(still gets queried):\u003c/br\u003e\nA records(IPv4)\n![1](https://user-images.githubusercontent.com/18756975/197861561-eba3ed9d-470e-4ee6-956a-4b734d6c7c1d.jpg)\n\nAAA records(IPv6)\n![2](https://user-images.githubusercontent.com/18756975/197861617-89136d97-2d0f-4702-968e-bd3023217be0.jpg)\n\n\u003c/p\u003e\n \u003c/details\u003e\n\n### Use \u003ca href=\"https://www.google.com/search?q=what+does+tail+command+do+linux\u0026client=firefox-b-d\u0026sxsrf=ALiCzsawidkeBiELxfyKyqucXz1ghKk8tQ%3A1667339937159\u0026ei=oZZhY7GwCZ6WwbkP0vCowAg\u0026ved=0ahUKEwjxhLKl_Y37AhUeSzABHVI4CogQ4dUDCA4\u0026uact=5\u0026oq=what+does+tail+command+do+linux\u0026gs_lcp=Cgxnd3Mtd2l6LXNlcnAQAzIICAAQCBAHEB4yBQgAEIYDMgUIABCGAzIFCAAQhgM6BAgAEEc6BwgjELACECc6BwgAEIAEEA06CggAEAgQBxAeEA86CAgAEAUQBxAeOgYIABAIEB5KBAhBGABKBAhGGABQ5Q5YoDRg6TRoAHAEeACAAZ0BiAHWC5IBBDEuMTKYAQCgAQHIAQjAAQE\u0026sclient=gws-wiz-serp\"\u003etail\u003c/a\u003e command to monitor logs in realtime:\n```bash\n## Unbound\n## If using unbound from package manager, manually create log file - sudo touch /var/log/unbound.log\n## and set permission - sudo chown unbound:unbound /var/log/unbound.log\n## Choose verbosity level and set log path in unbound.conf - logfile: /var/log/unbound.log\n## Restart unbound - sudo systemctl restart unbound\nsudo tail -f /var/log/unbound.log\n\n## DNSCrypt\nsudo tail -f /var/log/dnscrypt-proxy/query.log\n```\n\n\u003e [!TIP]\n\u003e Stable DNS resolving\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Stable-DNS-resolving(optional)\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e\n\n#### Other sites to test security\n[browserleaks](https://browserleaks.com/dns) - should show all connected to \"Cloudflare\"\n\n[dnssec](https://rootcanary.org/test.html) - should say \"Yes, your DNS resolver validates DNSSEC signatures\"\n \n[dnscheck tools](https://dnscheck.tools/) - inspect your dns resolvers (DNSSEC using ECDSA P-256,DNSSEC using ECDSA P-384,DNSSEC using Ed25519)\n\n**[\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e Return to contents \u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e](#table-of-contents)**\n\n#\n\u003ch1 align=\"center\"\u003e\u003cb\u003e\u003ci\u003eInstall WireGuard\u003c/b\u003e\u003c/i\u003e \u003c/h1\u003e\n\n\u003e [!WARNING]\n\u003e **Before installing WireGuard**, if you do not have a external/public \u003ca href=\"https://www.google.com/search?client=firefox-b-d\u0026q=static+IP\"\u003estatic IP\u003c/a\u003e it will change dynamically from your internet service provider or from a router reboot. You will need to setup a dynamic DNS service with a hostname to keep automatically up-to-date with a dynamic IP\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Create-a-DNS-domain-hostname\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e. Or else skip this.\n\n\u003e [!IMPORTANT]\n\u003e You also need to set up \u003ca href=\"https://www.google.com/search?q=What+is+port+forwarding+used+for%3F\u0026client=firefox-b-d\u0026sxsrf=APq-WBuwPqGlPJ6N9_l6qpQ3e5sYoUxZAQ%3A1650219365125\u0026ei=ZVlcYo6sB6SGwbkP8tGOwA8\u0026ved=0ahUKEwjO8ryY2pv3AhUkQzABHfKoA_gQ4dUDCA0\u0026uact=5\u0026oq=What+is+port+forwarding+used+for%3F\u0026gs_lcp=Cgdnd3Mtd2l6EAMyBggAEBYQHjoHCAAQRxCwAzoHCAAQsAMQQ0oECEEYAEoECEYYAFDMAVjMAWCBBWgBcAF4AIABbIgBbJIBAzAuMZgBAKABAqABAcgBCsABAQ\u0026sclient=gws-wiz\"\u003eport forwarding\u003c/a\u003e on your router so you can access WireGuard network anywhere like open wifi/hotspots and even from mobile data tethering.\n\nTYPE | VALUE     \n------------ | -------------\nDevice | Raspberry Pi's hostname or IP\nProtocol | UDP\nPort range | 51820-51820\nOutgoing port | 51820\nPermit Internet access(if have) | yes \n\nExample of my router port settings:\n\n \u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://i.imgur.com/TNK2QMt.jpg\" width=650px height=450px\u003e\u003c/p\u003e\n\n\u003e [!NOTE] \n\u003e Other router brands will have a different interface look. Google search it for help. If you cannot connect from a outside network that means your ISP has blocked incoming connections and only allow outgoing, call them and ask nicely to unblock.\n\n#\n\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Animated-Fluent-Emojis/master/Emojis/Hand%20gestures/Oncoming%20Fist.png\" alt=\"Oncoming Fist\" width=\"25\" height=\"25\" /\u003eBIG THANKS\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Animated-Fluent-Emojis/master/Emojis/Hand%20gestures/Oncoming%20Fist.png\" alt=\"Oncoming Fist\" width=\"25\" height=\"25\" /\u003e for this installation script from \u003ca href=\"https://github.com/Nyr/wireguard-install\"\u003eNyr\u003c/a\u003e. Follow to keep updated.\u003cbr\u003e(\u003ca href=\"https://www.pivpn.io/\"\u003ePiVPN\u003c/a\u003e script can also be used)\n\nDownload and run script in terminal:\n```bash\nwget https://git.io/wireguard -O wireguard-install.sh \u0026\u0026 sudo bash wireguard-install.sh\n```\n * The script is going to ask for a Public IPv4/hostname for the VPN. If you have static IP then continue or else type the dynamic DNS hostname that was created from the \u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Create-a-DNS-domain-hostname\"\u003einstructions\u003c/a\u003e. For example:`trinibvpn.freeddns.org`\n\n * For port option `press enter` for default 51820, set client name and for DNS use option 3 (`1.1.1.1`) for now.\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/WUNZIK4.jpg\"\u003e\u003c/p\u003e\n\n * Wait until the installation is finished and QR code to show, \u003cb\u003edon't close\u003c/b\u003e. But if do, to `regenerate qrcode`, enter in terminal but replacing just the name `yourclientname.conf` file to yours: \n```bash\nsudo cp /root/yourclientname.conf /home/pi \u0026\u0026 sudo qrencode -t ansiutf8 \u003c yourclientname.conf\n```\n                                                                                             \n\u003e [!NOTE]\n\u003e For each device, you will need to add a new client/user\u003ci\u003e(cannot use 1 client for multiple devices at the same time)\u003c/i\u003e. To add, re-run the script and create another user with different client name.\n\n### Connecting VPN To Android/iOS Phone\n\nInstall the WireGuard app from Google Play or App Store:\n\nWireGuard (Google Play): https://play.google.com/store/apps/details?id=com.wireguard.android\n\nWireGuard (App Store): https://apps.apple.com/us/app/wireguard/id1441195209\n\nScan the QR code shown in the terminal with WireGuard app, select the `+ button` and use the option `Scan from QR code` to install configuration.\n\n- Enable **kernel module backend** in settings\n\n\u003cp align=\"left\"\u003e\n \u003cimg src=\"https://i.imgur.com/R4qbiOQ.jpg\" width=250px height=350px\u003e\u003c/p\u003e\n\n### Connecting VPN to Windows\n\nWireGuard for windows: https://download.wireguard.com/windows-client/wireguard-installer.exe\n\n * Create a `new text document` with any name on PC to copy over the text from WireGuard client configuration file.\n\n * To see text in client config file, type in terminal:\n```bash\nsudo cat /root/yourclientname.conf\n```\n * Highlight all the text, copy and paste it in the txt file on PC and save. Then rename the extension from `txt` to `conf`. Now you have config file for that specific WireGuard client/user.\n\n * Import the config file to WireGuard (import from file option), save and connect.\n\n## Configure WireGuard with adblocking \u0026 DNS security\n\n\u003e [!NOTE]\n\u003e I think it might not make much of a difference to use DoT/DoH/oDoH with WireGuard security protocols. Though from my experience and in forums, it does not seem to cause any issues using them together. Mainly this is to achieve adblocking with a VPN on public networks.\n \n * In WireGuard app, select your tunnel name and select edit (pencil on top right)\n\n * Under DNS servers enter `Pi's IP`(IPv4 \u0026 IPv6) and save\n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/UC0vWfE.jpg\" width=450px height=500px\u003e\u003c/p\u003e\n \n### _Install OpenVPN as an alternative\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Install-OpenVPN\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e_\n \n#\n### Limit traffic\n\nSelf-hosted VPNs will lose a fair percentage of internet speed from the process of tunneling through Linux system, to router, to devices. You need send traffic through your local network only for better speeds\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Limit-traffic-on-VPN\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e.\n\n#\n### Disable all IPv6\n\n#### Disable IPv6 if you don't have it or don't want it\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/wiki/Disable-all-IPv6\"\u003e\u003cb\u003e🔗click here🔗\u003c/b\u003e\u003c/a\u003e. In result if you have weak internet, disabling IPv6 can speed up dns records and request but have less security.\n\n#\n## Test VPN\n\nHow to know if WireGuard VPN is really working?\n\nFor **windows** download Wireshark: https://www.wireshark.org/#download\n\nOnce downloaded, use the application to inspect data packets where the protocol is set to the one used by WireGuard VPN. When a packet traffic is `encrypted`, it can be read  like this for example:\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/Tn4M47R.jpg\"\u003e\u003c/p\u003e\n\nFor **android** use PCAPdroid: https://play.google.com/store/apps/details?id=com.emanuelef.remote_capture\u0026hl=en\u0026gl=US\n                                                                                                                                \nYou should see all connections `closed` and status showing all `DNS port 53` and not any TLS port 443 connections from all apps. (open and use apps for PCAPdroid to scan)\n\n**[\u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e Return to contents \u003cimg src=\"https://raw.githubusercontent.com/Tarikul-Islam-Anik/Telegram-Animated-Emojis/main/Symbols/Up%20Button.webp\" alt=\"Up Button\" width=\"25\" height=\"25\" /\u003e](#table-of-contents)**\n\n***\n\n\u003cp align=\"center\"\u003e\n\u003cb\u003e\u003ci\u003e✨ 𝘈𝘕𝘠 𝘐𝘚𝘚𝘜𝘌𝘚, 𝘍𝘐𝘟𝘌𝘚 𝘖𝘙 𝘛𝘐𝘗𝘚 𝘛𝘖 𝘔𝘈𝘒𝘌 𝘛𝘏𝘌𝘚𝘌 𝘗𝘙𝘖𝘑𝘌𝘊𝘛𝘚 𝘉𝘌𝘛𝘛𝘌𝘙 𝘗𝘓𝘌𝘈𝘚𝘌 𝘊𝘖𝘕𝘛𝘙𝘐𝘉𝘜𝘛𝘌 ✨\u003c/i\u003e\u003c/b\u003e\n\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"https://user-images.githubusercontent.com/73097560/115834477-dbab4500-a447-11eb-908a-139a6edaec5c.gif\"\n\u003cbr\u003e \n\u003cbr\u003e \n\u003cbr\u003e \n\n\u003cp align=\"center\"\u003e\n \u003cimg src=\"https://i.imgur.com/Q07E7SW.gif\" width=500px height=30px\u003e\n\n\u003cp align=\"center\"\u003e\n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-Cloudflare/stargazers\"\u003e\u003cimg src=\"http://reporoster.com/stars/dark/trinib/AdGuard-WireGuard-Unbound-DNScrypt\"\u003e\u003c/a\u003e\n\n\u003cp align=\"center\"\u003e\n\u003cimg src=\"https://user-images.githubusercontent.com/73097560/115834477-dbab4500-a447-11eb-908a-139a6edaec5c.gif\"\u003e\u003c/p\u003e\n\n#\n## Extras\n\n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Install-NextDNS\"\u003eNextDNS Client\u003c/a\u003e\n\n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Network-CLI-Tools\"\u003eNetwork CLI Tools\u003c/a\u003e\n\n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Secure-Raspberry-Pi(Linux)\"\u003eSecure Raspberry Pi\u003c/a\u003e\n \n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Auto-Update-Raspberry-Pi\"\u003eAuto Update Raspberry Pi\u003c/a\u003e\n\n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/AdGuard-Home-Dark-Theme\"\u003eAdGuard Home Dark Theme\u003c/a\u003e\n \n\u003ca href=\"https://github.com/trinib/AdGuard-WireGuard-Unbound-DNScrypt/wiki/Improve-SD-Card%E2%80%99s-lifespan\"\u003eImprove SD Card’s lifespan\u003c/a\u003e\n \n\u003ca href=\"https://github.com/trinib/Linux-Bash-Commands\"\u003eLinux Bash commands\u003c/a\u003e\n \n#\n\n## Repository Resources\n\nhttps://github.com/AdguardTeam/AdGuardHome/wiki\n\nhttps://docs.pi-hole.net/\n\nhttps://developers.cloudflare.com/\n\nhttps://unbound.docs.nlnetlabs.nl/en/latest/\n \nhttps://knot-resolver.readthedocs.io/en/stable/#\n\nhttps://dnsprivacy.org/dns_privacy_clients/\n \nhttps://github.com/DNSCrypt/dnscrypt-proxy/wiki\n\nhttps://github.com/Nyr/wireguard-install\n     \nhttps://github.com/T145/black-mirror\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftrinib%2Fadguard-wireguard-unbound-dnscrypt","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftrinib%2Fadguard-wireguard-unbound-dnscrypt","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftrinib%2Fadguard-wireguard-unbound-dnscrypt/lists"}