Redirecting DNS on UniFi Gateways

Let's say you are like me and you have something like Pi-hole or AdGuard on your network to provide DNS filtering/blocking as well as an IoT or untrusted network/VLAN on your UniFi gateway and you want to ensure all DNS queries are sent to your Pi-hole/AdGuard instead of maybe something like hardcoded DNS. We sometimes see hardcoded DNS in things like smart lights or Google/Amazon devices. We can set up a NAT rule to translate the destination of that DNS request to your Pi-hole/AdGuard instance to ensure all plain DNS requests are being filtered by your DNS filtering setup. Side note: this only works for DNS requests sent to an IP address and NOT DNS over HTTPS or DNS over TLS.

Head to Settings - Routing - NAT and click "Create Entry"

Choose "Destination" as the Type and reference the screenshot below for setup:

UniFi Destination NAT rule Redirect IoT DNS: UDP on the IoT interface, Match Opposite checked, port 53 translated to port 53

IMPORTANT!
I emphasized the sections that are required.

Select the proper network under "Interface", since our rule is in Destination mode, we will be translating or "redirecting" DNS requests to anything other than what is listed in the "Translated" sections.

Set the Destination to the IP(s) of your internal DNS servers. Notice how I put an arrow on the "Match Opposite" checkbox under Destination. This is crucial as it will cover anything not destined for your internal DNS servers.

Make sure to duplicate the IP(s) of your internal DNS servers in the "Translated IP Address" section.

Need help with your website?

Dynamic Technologies builds, hosts and maintains websites for small businesses in Coeur d'Alene and North Idaho.