[{"data":1,"prerenderedAt":1528},["ShallowReactive",2],{"post-how-to-configure-pi-hole-and-mullvad-on-a-raspberry-pi-en":3,"related-posts-how-to-configure-pi-hole-and-mullvad-on-a-raspberry-pi-en":1526,"related-categories-how-to-configure-pi-hole-and-mullvad-on-a-raspberry-pi-en":1527},{"id":4,"title":5,"author":6,"authorImageUrl":7,"authorUrl":8,"body":9,"categorySlug":1490,"categoryText":1491,"dateModified":1492,"datePublished":1492,"description":1493,"extension":1494,"faqs":1495,"image":1517,"language":1518,"meta":1519,"navigation":1520,"path":1521,"seo":1522,"sitemap":1523,"stem":1524,"__hash__":1525},"blog\u002Fblog\u002Fhow-to-configure-pi-hole-and-mullvad-on-a-raspberry-pi.md","How To Use Pi-hole And The Mullvad VPN On a Raspberry Pi","Bruma","\u002Fimages\u002Fauthors\u002Fbruma.jpg","https:\u002F\u002Fbrumaombra.com",{"type":10,"value":11,"toc":1452},"minimark",[12,17,21,24,27,44,47,51,54,59,67,76,85,88,91,95,102,108,111,114,117,119,123,126,129,131,135,138,141,144,147,156,160,163,189,197,200,204,207,210,223,227,230,233,277,281,284,304,308,311,314,330,338,341,344,346,350,354,357,360,398,406,410,413,416,439,442,448,451,454,457,463,472,478,485,488,494,497,509,512,520,524,527,530,545,548,556,559,567,569,573,576,579,582,585,592,594,598,607,612,617,620,624,627,652,660,663,667,678,681,699,703,706,724,727,748,755,758,761,779,787,790,806,810,813,817,820,835,848,852,855,870,878,889,909,912,945,951,963,966,974,978,981,984,1054,1057,1088,1091,1109,1112,1120,1123,1129,1132,1147,1155,1159,1162,1165,1168,1171,1175,1178,1185,1188,1200,1203,1210,1222,1225,1228,1241,1244,1247,1250,1263,1271,1274,1285,1293,1296,1298,1302,1311,1318,1322,1325,1329,1344,1350,1354,1360,1364,1371,1374,1381,1392,1396,1399,1402,1405,1410,1413,1417,1420,1424,1427,1430,1433,1435,1439,1442,1445,1448],[13,14,16],"h2",{"id":15},"introduction","Introduction",[18,19,20],"p",{},"Are you afraid that your ISP (Internet Service Provider) might be spying on you and reading all of your home network traffic? Are you tired of seeing ads everywhere? Or maybe you simply don't like the idea of a random company seeing and tracking every single mouse movement and keyboard stroke while you surf the web?",[18,22,23],{},"Well, if those are some of your concerns, you're definitely in the right place!",[18,25,26],{},"In this practical and easy-to-follow guide, we will configure a network-wide ad and tracker blocker, creating a sort of digital shield between you, your ISP, and third-party analytics companies.",[18,28,29,30,37,38,43],{},"In this setup, we will use ",[31,32,36],"a",{"href":33,"rel":34},"https:\u002F\u002Fpi-hole.net\u002F",[35],"nofollow","Pi-hole"," (a very popular DNS filtering system) to block ads and some of the most popular trackers, and the ",[31,39,42],{"href":40,"rel":41},"https:\u002F\u002Fmullvad.net\u002F",[35],"Mullvad VPN"," (a very privacy-friendly VPN provider) to hide your web traffic from your ISP.",[45,46],"hr",{},[13,48,50],{"id":49},"what-we-need","What We Need",[18,52,53],{},"First, let's start by listing all the things we need to make our home or office network a lot safer and more private.",[55,56,58],"h3",{"id":57},"raspberry-pi","Raspberry Pi",[18,60,61,62,66],{},"The most important element of our little project is the ",[31,63,58],{"href":64,"rel":65},"https:\u002F\u002Fwww.raspberrypi.com\u002F",[35],". The Raspberry Pi (usually called just the Pi) is a very well-known and popular tiny PC, often used by nerds like us to test fun projects easily at home, without the need for an expensive server or dedicated remote server. It has a powerful ARM-based CPU, along with plenty of RAM to handle our processes. Basically, it has everything we need to implement our network-wide shield without performance issues.",[18,68,69],{},[70,71],"img",{"alt":72,"height":73,"src":74,"width":75},"Raspberry Pi overview",941,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fraspberry-pi-description.png",1672,[18,77,78,79,84],{},"As the operating system for the Raspberry Pi, we'll be using its custom-built Linux distro, called ",[31,80,83],{"href":81,"rel":82},"https:\u002F\u002Fwww.raspberrypi.com\u002Fsoftware\u002F",[35],"Raspberry Pi OS",". In particular, we will be using the Lite version of the OS, the one without a graphical user interface, called Raspberry Pi OS Lite.",[18,86,87],{},"When it comes to memory, I would suggest getting the 4 GB or 8 GB Raspberry Pi variant, even though the setup will take a lot less than that.",[18,89,90],{},"Last but not least, you should have a basic understanding of the terminal and SSH connections, as we will be using them as our main human-to-machine interface.",[55,92,94],{"id":93},"mullvad","Mullvad",[18,96,97,98,101],{},"For this project, we're going to need a ",[99,100,94],"strong",{}," account. Mullvad is a very popular, privacy-friendly VPN provider and is probably one of the most secure on the market right now. You don't even need an email address to use them! When you subscribe, they assign you a random numerical account number, and that's all you need to use the product. Not even a password!",[18,103,104],{},[70,105],{"alt":106,"height":73,"src":107,"width":75},"Mullvad VPN overview","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fmullvad-vpn-description.png",[18,109,110],{},"Mullvad also has a strict no-logging policy, which means that they do not save the history of their users' traffic, DNS requests, connection timestamps, IP addresses, or bandwidth usage.",[18,112,113],{},"This is an amazing policy to have, and if your goal is to keep your Internet traffic away from your ISP and avoid creating another detailed record of your online activity, this is definitely a great option.",[18,115,116],{},"I've chosen Mullvad exactly for this reason, and because I truly admire their devotion to free speech and an open Internet, and I think they're the perfect provider for this kind of application!",[45,118],{},[13,120,122],{"id":121},"_1-prepare-the-raspberry-pi","1. Prepare the Raspberry Pi",[18,124,125],{},"In this guide, we will not cover how to set up and flash the operating system on the Raspberry Pi, and will jump straight to the network configuration. But don't worry, there are plenty of detailed and easy-to-follow guides online, so you're in good hands!",[18,127,128],{},"OK, now let's start the project by configuring the Pi's IP address.",[45,130],{},[13,132,134],{"id":133},"_2-set-a-static-ip","2. Set a static IP",[18,136,137],{},"To use the Raspberry Pi as both the DNS server (for Pi-hole) and gateway (for Mullvad), we need to set a static IP. When you connect a new device to a network via Wi-Fi or an Ethernet cable, an IP address is automatically assigned to it by the DHCP server (in a home network, this job is usually done by the router).",[18,139,140],{},"This is what's called a dynamic IP address assignment. However, for this project, we need what's called a static IP address assignment. \"But why?\", you may ask. Why not keep the dynamic IP? Well, there's a very simple reason.",[18,142,143],{},"With a dynamic IP, we're not 100% sure that the IP will remain the same in the future. The DHCP server might decide to change our device's IP address, making it impossible for other devices on the network to know where to find the Raspberry Pi.",[18,145,146],{},"For this reason, we need to set a fixed IP address, so all other devices always know where to point when they need to ask questions to the Raspberry Pi.",[18,148,149,150,155],{},"To change the network settings of the Raspberry Pi, we're going to use the ",[31,151,154],{"href":152,"rel":153},"https:\u002F\u002Fnetworkmanager.dev\u002F",[35],"NetworkManager"," utility.",[55,157,159],{"id":158},"list-all-network-interfaces","List all network interfaces",[18,161,162],{},"First, let's check all our network interfaces, so we can change only the right one. To do that, you can use the following command.",[164,165,170],"pre",{"className":166,"code":167,"language":168,"meta":169,"style":169},"language-bash shiki shiki-themes github-light github-dark","nmcli con show\n","bash","",[171,172,173],"code",{"__ignoreMap":169},[174,175,178,182,186],"span",{"class":176,"line":177},"line",1,[174,179,181],{"class":180},"sScJk","nmcli",[174,183,185],{"class":184},"sZZnC"," con",[174,187,188],{"class":184}," show\n",[18,190,191],{},[70,192],{"alt":193,"height":194,"src":195,"width":196},"NetworkManager connection list",418,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fcheck-networks.png",1024,[18,198,199],{},"In my case, I have netplan-eth0 as the network name, and eth0 as the device name.",[55,201,203],{"id":202},"configure-it-with-the-interactive-text-ui","Configure it with the interactive text UI",[18,205,206],{},"When it comes to the NetworkManager utility, you have two options: using the simpler UI version or configuring it directly from the command line. There isn't a right or wrong approach, so choose whichever works best for you.",[18,208,209],{},"To open the UI version, use the following command.",[164,211,213],{"className":166,"code":212,"language":168,"meta":169,"style":169},"sudo nmtui\n",[171,214,215],{"__ignoreMap":169},[174,216,217,220],{"class":176,"line":177},[174,218,219],{"class":180},"sudo",[174,221,222],{"class":184}," nmtui\n",[55,224,226],{"id":225},"or-configure-it-from-the-command-line","Or configure it from the command line",[18,228,229],{},"However, for this specific case, I suggest using the command-line approach. It is simpler and faster, making it a good choice for a quick IP change.",[18,231,232],{},"To do that, use the command below, replacing the connection name, interface name, and IP addresses with the values used by your network.",[164,234,236],{"className":166,"code":235,"language":168,"meta":169,"style":169},"sudo nmcli con mod netplan-eth0 ipv4.addresses \"192.168.21.82\u002F24\" ipv4.gateway \"192.168.21.1\" ipv4.dns \"192.168.21.1,1.1.1.1\" ipv4.method manual\n",[171,237,238],{"__ignoreMap":169},[174,239,240,242,245,247,250,253,256,259,262,265,268,271,274],{"class":176,"line":177},[174,241,219],{"class":180},[174,243,244],{"class":184}," nmcli",[174,246,185],{"class":184},[174,248,249],{"class":184}," mod",[174,251,252],{"class":184}," netplan-eth0",[174,254,255],{"class":184}," ipv4.addresses",[174,257,258],{"class":184}," \"192.168.21.82\u002F24\"",[174,260,261],{"class":184}," ipv4.gateway",[174,263,264],{"class":184}," \"192.168.21.1\"",[174,266,267],{"class":184}," ipv4.dns",[174,269,270],{"class":184}," \"192.168.21.1,1.1.1.1\"",[174,272,273],{"class":184}," ipv4.method",[174,275,276],{"class":184}," manual\n",[55,278,280],{"id":279},"apply-the-changes","Apply the changes",[18,282,283],{},"To apply the network changes, execute the command below.",[164,285,287],{"className":166,"code":286,"language":168,"meta":169,"style":169},"sudo nmcli device reapply eth0\n",[171,288,289],{"__ignoreMap":169},[174,290,291,293,295,298,301],{"class":176,"line":177},[174,292,219],{"class":180},[174,294,244],{"class":184},[174,296,297],{"class":184}," device",[174,299,300],{"class":184}," reapply",[174,302,303],{"class":184}," eth0\n",[55,305,307],{"id":306},"verify-the-network-interface-info","Verify the network interface info",[18,309,310],{},"After making the change, check that the address, gateway, and DNS settings are correct and match the values you set in the previous command.",[18,312,313],{},"You can see the updated settings with the following command.",[164,315,317],{"className":166,"code":316,"language":168,"meta":169,"style":169},"nmcli device show eth0\n",[171,318,319],{"__ignoreMap":169},[174,320,321,323,325,328],{"class":176,"line":177},[174,322,181],{"class":180},[174,324,297],{"class":184},[174,326,327],{"class":184}," show",[174,329,303],{"class":184},[18,331,332],{},[70,333],{"alt":334,"height":335,"src":336,"width":337},"NetworkManager interface details",483,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fcheck-network-info.png",1086,[18,339,340],{},"As you can see, the Raspberry Pi now has a static IP, which means there is no risk of losing track of it on the network because its address will remain the same.",[18,342,343],{},"If you are connected over SSH, keep in mind that the connection might drop and that you'll need to reconnect using the newly updated IP address.",[45,345],{},[13,347,349],{"id":348},"_3-install-pi-hole","3. Install Pi-hole",[55,351,353],{"id":352},"update-the-system-first","Update the system first",[18,355,356],{},"Before installing Pi-hole, let's make sure that the operating system and all installed packages are up to date, so we start with the latest available security fixes.",[18,358,359],{},"Execute the following commands to get the latest updates. After that, reboot the Raspberry Pi to be sure to use the new up-to-date software.",[164,361,363],{"className":166,"code":362,"language":168,"meta":169,"style":169},"sudo apt update && sudo apt full-upgrade -y\nsudo reboot\n",[171,364,365,390],{"__ignoreMap":169},[174,366,367,369,372,375,379,381,383,386],{"class":176,"line":177},[174,368,219],{"class":180},[174,370,371],{"class":184}," apt",[174,373,374],{"class":184}," update",[174,376,378],{"class":377},"sVt8B"," && ",[174,380,219],{"class":180},[174,382,371],{"class":184},[174,384,385],{"class":184}," full-upgrade",[174,387,389],{"class":388},"sj4cs"," -y\n",[174,391,393,395],{"class":176,"line":392},2,[174,394,219],{"class":180},[174,396,397],{"class":184}," reboot\n",[18,399,400],{},[70,401],{"alt":402,"height":403,"src":404,"width":405},"Raspberry Pi system update",1197,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fupdate-system.png",2371,[55,407,409],{"id":408},"install-pi-hole","Install Pi-hole",[18,411,412],{},"Now we can finally install Pi-hole using its official one-step installer, making it extremely easy to install everything we need to run the program.",[18,414,415],{},"If you prefer to know exactly what will be executed on your Raspberry Pi and have a basic understanding of shell scripts, you can review the script before running it.",[164,417,419],{"className":166,"code":418,"language":168,"meta":169,"style":169},"curl -sSL https:\u002F\u002Finstall.pi-hole.net | bash\n",[171,420,421],{"__ignoreMap":169},[174,422,423,426,429,432,436],{"class":176,"line":177},[174,424,425],{"class":180},"curl",[174,427,428],{"class":388}," -sSL",[174,430,431],{"class":184}," https:\u002F\u002Finstall.pi-hole.net",[174,433,435],{"class":434},"szBVR"," |",[174,437,438],{"class":180}," bash\n",[18,440,441],{},"After executing the script, you should see the screen below.",[18,443,444],{},[70,445],{"alt":446,"height":403,"src":447,"width":405},"Pi-hole installer welcome screen","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-installer.png",[18,449,450],{},"Pretty exciting, isn't it?",[18,452,453],{},"The installer will now guide you through a few interactive screens.",[18,455,456],{},"First, let's confirm that our Raspberry Pi already has a static IP address. Click Continue to move to the next step.",[18,458,459],{},[70,460],{"alt":461,"height":403,"src":462,"width":405},"Pi-hole installer interface selection","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-installer-2.png",[18,464,465,466,471],{},"Now we need to choose an upstream DNS provider. We can select ",[31,467,470],{"href":468,"rel":469},"https:\u002F\u002Fwww.cloudflare.com\u002F",[35],"Cloudflare"," for now; we will change this later, once the Mullvad VPN tunnel is working.",[18,473,474],{},[70,475],{"alt":476,"height":403,"src":477,"width":405},"Pi-hole upstream DNS selection","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-installer-3.png",[18,479,480,481,484],{},"In the next step, we're going to set the default blocklist, which is the list of domains that Pi-hole will block. Pi-hole uses the ",[99,482,483],{},"StevenBlack Unified Hosts"," blocklist by default, which is a great starting point for blocking known advertising and tracking domains.",[18,486,487],{},"We can just confirm here.",[18,489,490],{},[70,491],{"alt":492,"height":403,"src":493,"width":405},"Pi-hole installation complete","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-installer-4.png",[18,495,496],{},"Great! The installation should now be complete! If you want, you can write down the Pi-hole admin dashboard link along with the password.",[18,498,499,500,503,504,508],{},"The Pi-hole address is usually something like ",[99,501,502],{},"http:\u002F\u002F\u003Cpi-ip>\u002Fadmin",", or, if you prefer the DNS version, something like ",[31,505,506],{"href":506,"rel":507},"http:\u002F\u002Fpi.hole\u002Fadmin",[35],".",[18,510,511],{},"If everything went well, opening the Pi-hole dashboard link should take us to the login page!",[18,513,514],{},[70,515],{"alt":516,"height":517,"src":518,"width":519},"Pi-hole web interface login",1438,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-web-interface.jpg",2004,[55,521,523],{"id":522},"set-a-new-password","Set a new password",[18,525,526],{},"If you don't like the auto-generated password and prefer something easier to read and memorize, you can change it from the command line.",[18,528,529],{},"For this project, I recommend changing it immediately to a password you can manage securely. As always, do not reuse a password from another service!",[164,531,533],{"className":166,"code":532,"language":168,"meta":169,"style":169},"sudo pihole setpassword\n",[171,534,535],{"__ignoreMap":169},[174,536,537,539,542],{"class":176,"line":177},[174,538,219],{"class":180},[174,540,541],{"class":184}," pihole",[174,543,544],{"class":184}," setpassword\n",[18,546,547],{},"After changing the password, we can log in to the Pi-hole dashboard.",[18,549,550],{},[70,551],{"alt":552,"height":553,"src":554,"width":555},"Pi-hole dashboard",1921,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-web-interface-2.jpg",1914,[18,557,558],{},"Fantastic! Now we have a working network-wide ad and tracker blocker!",[18,560,561,562,508],{},"If you want to learn more about Pi-hole and how it works, you can check ",[31,563,566],{"href":564,"rel":565},"https:\u002F\u002Fdocs.pi-hole.net\u002Fmain\u002Fbasic-install\u002F",[35],"the official documentation",[45,568],{},[13,570,572],{"id":571},"_4-configure-dns-for-your-network","4. Configure DNS for your network",[18,574,575],{},"At this point, Pi-hole is installed on our Raspberry Pi, but it will only filter DNS requests that are actually sent to it. To apply the filtering across our entire network, we can change the router's settings. We need to update the router's DHCP configuration so that the Raspberry Pi's IP address is used as the primary DNS server for every device that connects to the network.",[18,577,578],{},"In my case, I have a router that does not let me change the DNS server sent through DHCP, so I have to set the DNS server manually on each device. Both options are valid, but configuring it at the network-wide router level is definitely the more reliable option when your router supports it.",[18,580,581],{},"After changing the DHCP settings, renew the lease or reconnect each client, and then verify that the Raspberry Pi is listed as its DNS server.",[18,583,584],{},"You can check whether Pi-hole is receiving traffic from its main dashboard.",[18,586,587,588,591],{},"You can also configure the Raspberry Pi itself to use Pi-hole as its DNS server by editing the ",[99,589,590],{},"\u002Fetc\u002Fdhcpcd.conf"," file or using the NetworkManager utility. Be careful when changing these values, because an incorrect DNS or network configuration can completely break its network connectivity!",[45,593],{},[13,595,597],{"id":596},"_5-install-wireguard-and-mullvad","5. Install WireGuard and Mullvad",[18,599,600,601,606],{},"Once Pi-hole is fully working on our network, we can install ",[31,602,605],{"href":603,"rel":604},"https:\u002F\u002Fwww.wireguard.com\u002F",[35],"WireGuard"," and configure the Mullvad tunnel. \"Wait, WireGuard? What's WireGuard?\", you may ask.",[18,608,609,611],{},[99,610,605],{}," is a modern VPN protocol that creates a secure and encrypted tunnel between the Raspberry Pi and a VPN server. It is lightweight, fast, and relatively simple to configure, which makes it a great fit for a small device such as the Raspberry Pi.",[18,613,614,616],{},[99,615,94],{}," provides WireGuard configuration files for its VPN servers, but it does not directly install or manage the VPN connection on our Raspberry Pi. In a nutshell, WireGuard is the software that reads this configuration, establishes the encrypted connection to Mullvad, and routes the Raspberry Pi's Internet traffic through the VPN server. Without WireGuard, the Raspberry Pi would have no way to use the Mullvad tunnel.",[18,618,619],{},"The idea is to use the tunnel as the Raspberry Pi's outbound route while keeping Pi-hole responsible for filtering DNS requests.",[55,621,623],{"id":622},"install-wireguard","Install WireGuard",[18,625,626],{},"Ok, now that we know what WireGuard is, let's install it on our Raspberry Pi:",[164,628,630],{"className":166,"code":629,"language":168,"meta":169,"style":169},"sudo apt install wireguard wireguard-tools resolvconf -y\n",[171,631,632],{"__ignoreMap":169},[174,633,634,636,638,641,644,647,650],{"class":176,"line":177},[174,635,219],{"class":180},[174,637,371],{"class":184},[174,639,640],{"class":184}," install",[174,642,643],{"class":184}," wireguard",[174,645,646],{"class":184}," wireguard-tools",[174,648,649],{"class":184}," resolvconf",[174,651,389],{"class":388},[18,653,654],{},[70,655],{"alt":656,"height":657,"src":658,"width":659},"WireGuard installation",976,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer.png",1924,[18,661,662],{},"Ok, great! Now WireGuard is successfully installed on our little machine!",[55,664,666],{"id":665},"configure-wireguard","Configure WireGuard",[18,668,669,670,673,674,677],{},"The next step is to download a WireGuard configuration from the Mullvad account dashboard. Select WireGuard, choose Linux as the platform, select a server location, and save the resulting configuration file as ",[99,671,672],{},"mullvad.conf",", and put it in the ",[99,675,676],{},"\u002Fetc\u002Fwireguard"," folder on the Raspberry Pi.",[18,679,680],{},"Because this configuration contains your private key, let's make it a bit more secure by making it readable only by the root user:",[164,682,684],{"className":166,"code":683,"language":168,"meta":169,"style":169},"sudo chmod 600 \u002Fetc\u002Fwireguard\u002Fmullvad.conf\n",[171,685,686],{"__ignoreMap":169},[174,687,688,690,693,696],{"class":176,"line":177},[174,689,219],{"class":180},[174,691,692],{"class":184}," chmod",[174,694,695],{"class":388}," 600",[174,697,698],{"class":184}," \u002Fetc\u002Fwireguard\u002Fmullvad.conf\n",[55,700,702],{"id":701},"start-and-verify-the-tunnel","Start and verify the tunnel",[18,704,705],{},"Ok, now let's start the WireGuard interface manually first, so we can test the connection before configuring it to start automatically:",[164,707,709],{"className":166,"code":708,"language":168,"meta":169,"style":169},"sudo wg-quick up mullvad\n",[171,710,711],{"__ignoreMap":169},[174,712,713,715,718,721],{"class":176,"line":177},[174,714,219],{"class":180},[174,716,717],{"class":184}," wg-quick",[174,719,720],{"class":184}," up",[174,722,723],{"class":184}," mullvad\n",[18,725,726],{},"Now check the tunnel status and confirm that the public IP address is being provided by Mullvad:",[164,728,730],{"className":166,"code":729,"language":168,"meta":169,"style":169},"sudo wg show\ncurl https:\u002F\u002Fam.i.mullvad.net\u002Fconnected\n",[171,731,732,741],{"__ignoreMap":169},[174,733,734,736,739],{"class":176,"line":177},[174,735,219],{"class":180},[174,737,738],{"class":184}," wg",[174,740,188],{"class":184},[174,742,743,745],{"class":176,"line":392},[174,744,425],{"class":180},[174,746,747],{"class":184}," https:\u002F\u002Fam.i.mullvad.net\u002Fconnected\n",[18,749,750,751,754],{},"You should see a response similar to ",[99,752,753],{},"\"You are connected to Mullvad\"",", together with the name of the Mullvad server and its public IP address.",[18,756,757],{},"If the test succeeds, congratulations! Your Raspberry Pi is going through the Mullvad VPN!",[18,759,760],{},"Now let's enable the tunnel so that it starts automatically whenever the Raspberry Pi boots:",[164,762,764],{"className":166,"code":763,"language":168,"meta":169,"style":169},"sudo systemctl enable wg-quick@mullvad\n",[171,765,766],{"__ignoreMap":169},[174,767,768,770,773,776],{"class":176,"line":177},[174,769,219],{"class":180},[174,771,772],{"class":184}," systemctl",[174,774,775],{"class":184}," enable",[174,777,778],{"class":184}," wg-quick@mullvad\n",[18,780,781],{},[70,782],{"alt":783,"height":784,"src":785,"width":786},"WireGuard service enabled",318,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer-2.png",1605,[18,788,789],{},"If you need to stop the tunnel while troubleshooting, use:",[164,791,793],{"className":166,"code":792,"language":168,"meta":169,"style":169},"sudo wg-quick down mullvad\n",[171,794,795],{"__ignoreMap":169},[174,796,797,799,801,804],{"class":176,"line":177},[174,798,219],{"class":180},[174,800,717],{"class":184},[174,802,803],{"class":184}," down",[174,805,723],{"class":184},[55,807,809],{"id":808},"route-network-traffic-through-mullvad","Route network traffic through Mullvad",[18,811,812],{},"Now that our VPN is running, the traffic originating on the Raspberry Pi is going through Mullvad, but we still need to manage the traffic of other devices. To route traffic from another device on the local network, such as a PC, the Pi must also forward and masquerade that traffic. The steps below assume that:",[814,815],"blog-list",{":items":816},"[\"The LAN interface is eth0.\",\"The Mullvad WireGuard interface is mullvad, because the configuration file is named mullvad.conf.\",\"The Raspberry Pi's LAN address is 192.168.21.82.\"]",[18,818,819],{},"Before running the following commands, replace these example values with the ones from your own network. If you are not sure which interfaces are being used, you can find their names with:",[164,821,823],{"className":166,"code":822,"language":168,"meta":169,"style":169},"ip link show\n",[171,824,825],{"__ignoreMap":169},[174,826,827,830,833],{"class":176,"line":177},[174,828,829],{"class":180},"ip",[174,831,832],{"class":184}," link",[174,834,188],{"class":184},[18,836,837,838,841,842,844,845,847],{},"For example, if your WireGuard interface is named ",[99,839,840],{},"wg0",", replace ",[99,843,93],{}," with ",[99,846,840],{}," in the commands below.",[55,849,851],{"id":850},"enable-ipv4-forwarding","Enable IPv4 forwarding",[18,853,854],{},"Check whether forwarding is already enabled:",[164,856,858],{"className":166,"code":857,"language":168,"meta":169,"style":169},"sudo sysctl net.ipv4.ip_forward\n",[171,859,860],{"__ignoreMap":169},[174,861,862,864,867],{"class":176,"line":177},[174,863,219],{"class":180},[174,865,866],{"class":184}," sysctl",[174,868,869],{"class":184}," net.ipv4.ip_forward\n",[18,871,872],{},[70,873],{"alt":874,"height":875,"src":876,"width":877},"IPv4 forwarding disabled",201,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer-3.png",789,[18,879,880,881,884,885,888],{},"The value must be ",[99,882,883],{},"1",". If it is ",[99,886,887],{},"0",", as it was in my case, the Raspberry Pi can access the Internet itself, but it cannot forward traffic from a PC or another LAN device using the Pi as its gateway. Enable forwarding immediately with:",[164,890,892],{"className":166,"code":891,"language":168,"meta":169,"style":169},"sudo sysctl -w net.ipv4.ip_forward=1\n",[171,893,894],{"__ignoreMap":169},[174,895,896,898,900,903,906],{"class":176,"line":177},[174,897,219],{"class":180},[174,899,866],{"class":184},[174,901,902],{"class":388}," -w",[174,904,905],{"class":184}," net.ipv4.ip_forward=",[174,907,908],{"class":388},"1\n",[18,910,911],{},"To make the setting persistent across reboots, add it to a sysctl configuration file and reload the system settings:",[164,913,915],{"className":166,"code":914,"language":168,"meta":169,"style":169},"echo 'net.ipv4.ip_forward=1' | sudo tee \u002Fetc\u002Fsysctl.d\u002F99-router.conf\nsudo sysctl --system\n",[171,916,917,936],{"__ignoreMap":169},[174,918,919,922,925,927,930,933],{"class":176,"line":177},[174,920,921],{"class":388},"echo",[174,923,924],{"class":184}," 'net.ipv4.ip_forward=1'",[174,926,435],{"class":434},[174,928,929],{"class":180}," sudo",[174,931,932],{"class":184}," tee",[174,934,935],{"class":184}," \u002Fetc\u002Fsysctl.d\u002F99-router.conf\n",[174,937,938,940,942],{"class":176,"line":392},[174,939,219],{"class":180},[174,941,866],{"class":184},[174,943,944],{"class":388}," --system\n",[18,946,947,948,950],{},"The result of the following command should now be ",[99,949,883],{},", confirming that forwarding is enabled:",[164,952,953],{"className":166,"code":857,"language":168,"meta":169,"style":169},[171,954,955],{"__ignoreMap":169},[174,956,957,959,961],{"class":176,"line":177},[174,958,219],{"class":180},[174,960,866],{"class":184},[174,962,869],{"class":184},[18,964,965],{},"As you can see in the screenshot, the setting is now enabled.",[18,967,968],{},[70,969],{"alt":970,"height":971,"src":972,"width":973},"IPv4 forwarding enabled",243,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer-4.png",747,[55,975,977],{"id":976},"allow-forwarding-and-add-nat","Allow forwarding and add NAT",[18,979,980],{},"Now we need to allow traffic to travel from the LAN to Mullvad, and allow established return traffic to come back from the tunnel.",[18,982,983],{},"To do that, use the following commands:",[164,985,987],{"className":166,"code":986,"language":168,"meta":169,"style":169},"sudo iptables -A FORWARD -i eth0 -o mullvad -j ACCEPT\nsudo iptables -A FORWARD -i mullvad -o eth0 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT\n",[171,988,989,1020],{"__ignoreMap":169},[174,990,991,993,996,999,1002,1005,1008,1011,1014,1017],{"class":176,"line":177},[174,992,219],{"class":180},[174,994,995],{"class":184}," iptables",[174,997,998],{"class":388}," -A",[174,1000,1001],{"class":184}," FORWARD",[174,1003,1004],{"class":388}," -i",[174,1006,1007],{"class":184}," eth0",[174,1009,1010],{"class":388}," -o",[174,1012,1013],{"class":184}," mullvad",[174,1015,1016],{"class":388}," -j",[174,1018,1019],{"class":184}," ACCEPT\n",[174,1021,1022,1024,1026,1028,1030,1032,1034,1036,1038,1041,1044,1047,1050,1052],{"class":176,"line":392},[174,1023,219],{"class":180},[174,1025,995],{"class":184},[174,1027,998],{"class":388},[174,1029,1001],{"class":184},[174,1031,1004],{"class":388},[174,1033,1013],{"class":184},[174,1035,1010],{"class":388},[174,1037,1007],{"class":184},[174,1039,1040],{"class":388}," -m",[174,1042,1043],{"class":184}," conntrack",[174,1045,1046],{"class":388}," --ctstate",[174,1048,1049],{"class":184}," ESTABLISHED,RELATED",[174,1051,1016],{"class":388},[174,1053,1019],{"class":184},[18,1055,1056],{},"Next, masquerade the forwarded traffic so that the Mullvad tunnel knows how to return it to the Raspberry Pi:",[164,1058,1060],{"className":166,"code":1059,"language":168,"meta":169,"style":169},"sudo iptables -t nat -A POSTROUTING -o mullvad -j MASQUERADE\n",[171,1061,1062],{"__ignoreMap":169},[174,1063,1064,1066,1068,1071,1074,1076,1079,1081,1083,1085],{"class":176,"line":177},[174,1065,219],{"class":180},[174,1067,995],{"class":184},[174,1069,1070],{"class":388}," -t",[174,1072,1073],{"class":184}," nat",[174,1075,998],{"class":388},[174,1077,1078],{"class":184}," POSTROUTING",[174,1080,1010],{"class":388},[174,1082,1013],{"class":184},[174,1084,1016],{"class":388},[174,1086,1087],{"class":184}," MASQUERADE\n",[18,1089,1090],{},"These firewall rules may not survive a reboot by default, so once you have tested that the route works, install the persistence helper and save them:",[164,1092,1094],{"className":166,"code":1093,"language":168,"meta":169,"style":169},"sudo apt install iptables-persistent -y\n",[171,1095,1096],{"__ignoreMap":169},[174,1097,1098,1100,1102,1104,1107],{"class":176,"line":177},[174,1099,219],{"class":180},[174,1101,371],{"class":184},[174,1103,640],{"class":184},[174,1105,1106],{"class":184}," iptables-persistent",[174,1108,389],{"class":388},[18,1110,1111],{},"When the installer asks whether you want to save the current IPv4 rules, confirm the choice:",[18,1113,1114],{},[70,1115],{"alt":1116,"height":1117,"src":1118,"width":1119},"Saved IPv4 firewall configuration",841,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer-5.png",1719,[18,1121,1122],{},"Do the same for the current IPv6 rules:",[18,1124,1125],{},[70,1126],{"alt":1127,"height":1117,"src":1128,"width":1119},"Saved IPv6 firewall configuration","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer-6.png",[18,1130,1131],{},"Perfect! Now let's save the changes:",[164,1133,1135],{"className":166,"code":1134,"language":168,"meta":169,"style":169},"sudo netfilter-persistent save\n",[171,1136,1137],{"__ignoreMap":169},[174,1138,1139,1141,1144],{"class":176,"line":177},[174,1140,219],{"class":180},[174,1142,1143],{"class":184}," netfilter-persistent",[174,1145,1146],{"class":184}," save\n",[18,1148,1149],{},[70,1150],{"alt":1151,"height":1152,"src":1153,"width":1154},"Persisted firewall rules",594,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fwireguard-installer-7.png",1272,[55,1156,1158],{"id":1157},"configure-the-network-devices","Configure the network devices",[18,1160,1161],{},"Finally, we can configure all the devices on the network to use the Pi as both the DNS server and the gateway.",[18,1163,1164],{},"Update the devices with the following values:",[814,1166],{":items":1167},"[\"An IP address in the same LAN as the Raspberry Pi.\",\"The Raspberry Pi's IP address as the default gateway.\",\"The Raspberry Pi's IP address as the DNS server.\"]",[18,1169,1170],{},"Great! Our devices are now using the newly configured network shield!",[55,1172,1174],{"id":1173},"test-the-route-in-stages","Test the route in stages",[18,1176,1177],{},"Before celebrating our victory too early, let's run a few tests to make sure that the network and routing are working as they should.",[18,1179,1180,1181,1184],{},"To do that, we will ping a few devices and servers. If you're not too technical, pinging basically means using the ",[99,1182,1183],{},"ping"," command to check whether one device can \"talk\" to another over the network.",[18,1186,1187],{},"First, let's check whether the device can reach the Raspberry Pi, which acts as both its DNS server and gateway. Keep in mind that you need to replace the IP in the command below with the actual IP address of your Pi.",[164,1189,1191],{"className":166,"code":1190,"language":168,"meta":169,"style":169},"ping 192.168.21.82\n",[171,1192,1193],{"__ignoreMap":169},[174,1194,1195,1197],{"class":176,"line":177},[174,1196,1183],{"class":180},[174,1198,1199],{"class":388}," 192.168.21.82\n",[18,1201,1202],{},"You should see multiple successful responses from the Raspberry Pi.",[18,1204,1205,1206,1209],{},"Okay, great. Now let's try something a bit more difficult: pinging an external server to see whether the routing works as planned. For this example, we will ping Cloudflare's DNS server at the well-known and iconic ",[99,1207,1208],{},"1.1.1.1"," address.",[164,1211,1213],{"className":166,"code":1212,"language":168,"meta":169,"style":169},"ping 1.1.1.1\n",[171,1214,1215],{"__ignoreMap":169},[174,1216,1217,1219],{"class":176,"line":177},[174,1218,1183],{"class":180},[174,1220,1221],{"class":388}," 1.1.1.1\n",[18,1223,1224],{},"As before, you should see several successful responses from the Cloudflare DNS server.",[18,1226,1227],{},"Now, for the final test, let's try a DNS resolution:",[164,1229,1231],{"className":166,"code":1230,"language":168,"meta":169,"style":169},"nslookup example.com\n",[171,1232,1233],{"__ignoreMap":169},[174,1234,1235,1238],{"class":176,"line":177},[174,1236,1237],{"class":180},"nslookup",[174,1239,1240],{"class":184}," example.com\n",[18,1242,1243],{},"If the tests do not go as planned, and you do not receive successful responses from all of them, here's a quick checklist you can follow:",[814,1245],{":items":1246},"[\"If the first test fails, check the PC's network settings and gateway.\",\"If the first test succeeds but 1.1.1.1 fails, check IPv4 forwarding, the NAT rule, and the Mullvad firewall rules.\",\"If the public IP works but DNS fails, check that Pi-hole is listening on the LAN and that the PC is using Pi-hole for DNS.\"]",[18,1248,1249],{},"While making a request from the PC, we can monitor the WireGuard counters to see whether traffic is going through the Raspberry Pi:",[164,1251,1253],{"className":166,"code":1252,"language":168,"meta":169,"style":169},"sudo wg show\n",[171,1254,1255],{"__ignoreMap":169},[174,1256,1257,1259,1261],{"class":176,"line":177},[174,1258,219],{"class":180},[174,1260,738],{"class":184},[174,1262,188],{"class":184},[18,1264,1265],{},[70,1266],{"alt":1267,"height":1268,"src":1269,"width":1270},"Mullvad traffic check",690,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fraspberry-mullvad-traffic.png",1288,[18,1272,1273],{},"The transfer counters should increase as the PC's traffic passes through the tunnel. You can also verify the public exit address of the VPN directly from the PC with:",[164,1275,1277],{"className":166,"code":1276,"language":168,"meta":169,"style":169},"curl https:\u002F\u002Fam.i.mullvad.net\u002Fconnected\n",[171,1278,1279],{"__ignoreMap":169},[174,1280,1281,1283],{"class":176,"line":177},[174,1282,425],{"class":180},[174,1284,747],{"class":184},[18,1286,1287],{},[70,1288],{"alt":1289,"height":1290,"src":1291,"width":1292},"Mullvad connection command output",588,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fcmd-mullvad-check.png",1357,[18,1294,1295],{},"So, that's it! You now have a secure and private network! But before we end the guide, we can make one final, very important check to see if our network is properly protected and shielded.",[45,1297],{},[13,1299,1301],{"id":1300},"_6-check-if-were-actually-secure","6. Check if we're actually secure",[18,1303,1304,1305,1310],{},"The final step is to check whether everything is working as expected and that our network is secure and shielded from outside eyes. Open the ",[31,1306,1309],{"href":1307,"rel":1308},"https:\u002F\u002Fmullvad.net\u002Fcheck",[35],"Mullvad connection check"," page and look at both the exit IP address and the DNS resolvers being reported.",[18,1312,1313],{},[70,1314],{"alt":1309,"height":1315,"src":1316,"width":1317},1317,"\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fmullvad-check.jpg",2383,[55,1319,1321],{"id":1320},"what-the-result-means","What the result means",[18,1323,1324],{},"Mullvad has a very quick and easy way to see if your network is fully protected. If every section is green, you're OK! If some is red, well... Not so good.",[814,1326],{":items":1327,"variant":1328},"[\"If the exit IP belongs to a Mullvad server, such as **it-mil-wg-001** in Milan, your traffic is going through Mullvad correctly.\",\"If the listed DNS resolvers are Cloudflare addresses such as **172.70.x.x**, **1.1.1.1**, or the corresponding IPv6 address, Pi-hole is currently forwarding DNS queries to Cloudflare.\"]","circle",[18,1330,1331,1332,1335,1336,1339,1340,1343],{},"In the vast majority of cases, you will see that the ",[99,1333,1334],{},"Using Mullvad VPN"," and ",[99,1337,1338],{},"No WebRTC leaks"," sections are green, and that the ",[99,1341,1342],{},"No DNS leaks"," section is red. The issue is that we are using Cloudflare as our DNS resolver, and Mullvad considers that a problem.",[18,1345,1346,1347,1349],{},"Cloudflare is a well-known privacy-friendly DNS resolver, but it is not operated by Mullvad. To be 100% sure that data is not leaked to third-party providers, Mullvad's connection check only reports ",[99,1348,1342],{}," when the DNS resolvers belong to Mullvad itself, so it usually flags Cloudflare even when the VPN tunnel itself is working correctly.",[55,1351,1353],{"id":1352},"make-the-dns-check-green","Make the DNS check green",[18,1355,1356,1357,1359],{},"To make the Mullvad check completely green and report a successful ",[99,1358,1342],{}," result, we need to change Pi-hole's upstream DNS server to one of Mullvad's DNS resolvers. You can use one of the following options, depending on whether you want filtering and whether the tunnel needs to remain active. In our case, I would opt for the first option, as we're already using Pi-hole to block malicious DNS requests.",[814,1361],{":items":1362,"variant":1363},"[\"Mullvad's internal DNS: 10.64.0.1. This works only while the WireGuard tunnel is active.\",\"Mullvad public DNS without filtering: 194.242.2.2. This continues to work if the tunnel briefly drops.\",\"Mullvad public DNS with ad, tracker, and malware blocking: 194.242.2.4.\",\"Mullvad public DNS with ad blocking only: 194.242.2.3.\"]","numbered",[18,1365,1366,1367,1370],{},"To change the upstream DNS resolver in Pi-hole, open the ",[31,1368,552],{"href":506,"rel":1369},[35]," and follow these simple steps:",[814,1372],{":items":1373,"variant":1363},"[\"Open the Pi-hole admin interface.\",\"Go to Settings, then DNS.\",\"Under Upstream DNS Servers, uncheck Cloudflare and any other selected providers.\",\"Select Custom and enter one of the Mullvad DNS addresses above. You can add both IPv4 and IPv6 resolvers if required by your network.\",\"Click Save at the bottom of the page.\"]",[18,1375,1376],{},[70,1377],{"alt":1378,"height":553,"src":1379,"width":1380},"Pi-hole DNS settings","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fpi-hole-web-interface-3.jpg",1900,[18,1382,1383,1384,1388,1389,1391],{},"Wait a few seconds for the settings change to persist, then run the check again at ",[31,1385,1387],{"href":1307,"rel":1386},[35],"mullvad.net\u002Fcheck",". If the setup is fully correct, it should show a green ",[99,1390,1342],{}," result and list only Mullvad DNS servers.",[55,1393,1395],{"id":1394},"if-the-check-still-shows-a-dns-leak","If the check still shows a DNS leak",[18,1397,1398],{},"If the Mullvad check still shows a DNS leak after changing Pi-hole's upstream DNS server to one managed by Mullvad, the most common reason is that the browser itself is using its own DNS-over-HTTPS (DoH) service. In that case, the browser ignores the system and Pi-hole DNS settings and connects directly to a provider such as Cloudflare or Google.",[18,1400,1401],{},"To fix this issue, disable the secure DNS feature in the browser you're using to surf the web.",[18,1403,1404],{},"Follow the steps below for the browser you're using:",[1406,1407,1409],"h4",{"id":1408},"firefox","Firefox",[814,1411],{":items":1412,"variant":1363},"[\"Open Settings, then Privacy & Security.\",\"Scroll down to DNS over HTTPS.\",\"Select Off.\",\"Restart Firefox and run the Mullvad check again.\"]",[1406,1414,1416],{"id":1415},"chrome","Chrome",[814,1418],{":items":1419,"variant":1363},"[\"Open chrome:\u002F\u002Fsettings\u002Fsecurity.\",\"Under Use secure DNS, turn the setting Off.\",\"Restart Chrome and run the Mullvad check again.\"]",[1406,1421,1423],{"id":1422},"edge","Edge",[814,1425],{":items":1426,"variant":1363},"[\"Open edge:\u002F\u002Fsettings\u002Fprivacy.\",\"Find Use secure DNS and turn the setting Off.\",\"Restart Edge and run the Mullvad check again.\"]",[18,1428,1429],{},"If the result is still unchanged, try running the test in a private or incognito window, or use a different browser. This can help confirm whether the leak is caused by the browser rather than Pi-hole, WireGuard, or the Mullvad connection.",[18,1431,1432],{},"If the new test succeeds, congratulations! Your network is now fully shielded!",[45,1434],{},[13,1436,1438],{"id":1437},"conclusion","Conclusion",[18,1440,1441],{},"We're finally at the end of this journey! Your Raspberry Pi is now acting as a network-wide ad and tracker blocker while routing your Internet traffic through the Mullvad VPN!",[18,1443,1444],{},"Remember to keep Raspberry Pi OS, Pi-hole, WireGuard, and the Mullvad configuration up to date so your setup can continue to work reliably and receive the latest security patches.",[18,1446,1447],{},"So, we're done for today! I hope you liked this guide, and I hope to see you in another one soon!",[1449,1450,1451],"style",{},"html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .szBVR, html code.shiki .szBVR{--shiki-default:#D73A49;--shiki-dark:#F97583}",{"title":169,"searchDepth":392,"depth":392,"links":1453},[1454,1455,1460,1461,1468,1473,1474,1484,1489],{"id":15,"depth":392,"text":16},{"id":49,"depth":392,"text":50,"children":1456},[1457,1459],{"id":57,"depth":1458,"text":58},3,{"id":93,"depth":1458,"text":94},{"id":121,"depth":392,"text":122},{"id":133,"depth":392,"text":134,"children":1462},[1463,1464,1465,1466,1467],{"id":158,"depth":1458,"text":159},{"id":202,"depth":1458,"text":203},{"id":225,"depth":1458,"text":226},{"id":279,"depth":1458,"text":280},{"id":306,"depth":1458,"text":307},{"id":348,"depth":392,"text":349,"children":1469},[1470,1471,1472],{"id":352,"depth":1458,"text":353},{"id":408,"depth":1458,"text":409},{"id":522,"depth":1458,"text":523},{"id":571,"depth":392,"text":572},{"id":596,"depth":392,"text":597,"children":1475},[1476,1477,1478,1479,1480,1481,1482,1483],{"id":622,"depth":1458,"text":623},{"id":665,"depth":1458,"text":666},{"id":701,"depth":1458,"text":702},{"id":808,"depth":1458,"text":809},{"id":850,"depth":1458,"text":851},{"id":976,"depth":1458,"text":977},{"id":1157,"depth":1458,"text":1158},{"id":1173,"depth":1458,"text":1174},{"id":1300,"depth":392,"text":1301,"children":1485},[1486,1487,1488],{"id":1320,"depth":1458,"text":1321},{"id":1352,"depth":1458,"text":1353},{"id":1394,"depth":1458,"text":1395},{"id":1437,"depth":392,"text":1438},"guides","Guides","2026-08-03","A practical guide to installing Pi-hole and configuring a Raspberry Pi as a Mullvad WireGuard gateway, including DNS, forwarding, NAT, and leak troubleshooting.","md",[1496,1499,1502,1505,1508,1511,1514],{"question":1497,"answer":1498},"What is the purpose of using Pi-hole with Mullvad on a Raspberry Pi?","Pi-hole blocks ads and trackers at the DNS level, while Mullvad routes Internet traffic through an encrypted VPN tunnel. Together, they provide network-wide DNS filtering and VPN protection for devices that use the Raspberry Pi as their DNS server and gateway.",{"question":1500,"answer":1501},"Can a Raspberry Pi run Pi-hole and Mullvad WireGuard at the same time?","Yes. A Raspberry Pi can run Pi-hole as the network DNS server and WireGuard as the Mullvad VPN client. With IPv4 forwarding and NAT configured, it can also route traffic from other devices through the VPN tunnel.",{"question":1503,"answer":1504},"Why does the Raspberry Pi need a static IP address?","The Raspberry Pi needs a stable IP address so other devices can always find it as their DNS server and gateway. A changing DHCP address could interrupt DNS filtering and prevent devices from reaching the VPN gateway.",{"question":1506,"answer":1507},"How do I route my home network traffic through Mullvad?","Enable IPv4 forwarding on the Raspberry Pi, allow forwarding between the LAN and WireGuard interfaces, add a masquerade rule for the VPN interface, and configure each device to use the Pi as its gateway and DNS server.",{"question":1509,"answer":1510},"Which Mullvad DNS server should I use with Pi-hole?","Use Mullvad's internal DNS at 10.64.0.1 when the WireGuard tunnel is active. For public Mullvad DNS, use 194.242.2.2 without filtering, 194.242.2.4 with ad and tracker blocking, or 194.242.2.3 with ad blocking only.",{"question":1512,"answer":1513},"Why does Mullvad's connection check show a DNS leak with Cloudflare?","Cloudflare is not operated by Mullvad, so Mullvad's check may report a DNS leak even when the VPN tunnel works correctly. To show No DNS leaks, configure Pi-hole to use a Mullvad DNS resolver instead of Cloudflare.",{"question":1515,"answer":1516},"How can I fix a DNS leak caused by my browser?","Disable DNS over HTTPS or secure DNS in the browser, then run the Mullvad connection check again. If the result does not change, test in a private window or use another browser to determine whether the browser is bypassing Pi-hole.","\u002Fimages\u002Fblog\u002Fpi-hole-and-mullvad\u002Fraspberry-pi-network.png","en",{},true,"\u002Fblog\u002Fhow-to-configure-pi-hole-and-mullvad-on-a-raspberry-pi",{"title":5,"description":1493},{"loc":1521},"blog\u002Fhow-to-configure-pi-hole-and-mullvad-on-a-raspberry-pi","a49zuUflMisLCHnPE3hq0wa4DiwXSzziWBnOfyRu6WY",[],[],1786183715709]