UpdatesExplore the release notes
Back to Blog

Use Pi-hole or AdGuard Home Remotely with Baseguard

Run a DNS filter on one Baseguard node and use it across your connected devices, including on mobile data. Your DNS server stays private.

Your Pi-hole works at home. Then you leave the house, your phone switches to mobile data, and it stops using your DNS filter.

The same thing happens with AdGuard Home. The filtering is still running. Your phone just needs a way to reach it.

With Baseguard, the setup is straightforward: run your DNS filter on one node, then add that node’s private address as a nameserver. Your connected devices can use it wherever they are.

No public DNS endpoint. No port forwarding on your home router. No manual DNS address to enter on every phone and laptop.

DNS over your private network
Your phoneOn mobile data
BaseguardEncrypted
Pi-hole or AdGuard Home100.64.0.13
Your filtering rules follow you. The DNS server stays private.
Example address. Use the private IP of your DNS node.

1. Pick a node for your DNS filter

Install Pi-hole or AdGuard Home on a machine that stays online. A small home server, a Raspberry Pi or a cloud machine can do the job. Join that machine to your Baseguard network.

Already running one of them? Install Baseguard on the same host and use its Baseguard address.

For this example, the DNS node has the private address 100.64.0.13. Use the address shown for your own node in the console.

Keep your blocklists, upstream resolvers and filtering preferences in Pi-hole or AdGuard Home. Baseguard provides the private connection and distributes the DNS configuration.

If you need the initial installation instructions, use the official guides for Pi-hole or AdGuard Home.

The DNS service needs to accept requests on the node’s Baseguard address. If it currently listens only on localhost or accepts only local clients, adjust that on the DNS host. Pi-hole documents its interface and client-origin settings here. If you restrict network access, allow the intended clients to reach DNS on port 53, over UDP and TCP. This access stays inside your private network.

2. Add the private nameserver

In the Baseguard console, open DNS → Nameservers → Add Nameserver.

Give it a name, select your DNS node’s private address, leave Match Domain off, and use All for Tags if you want it applied across the network.

Configure nameserverExample
Name
AdGuard Home
Addresses
100.64.0.13
Match Domain
OffUse for general DNS queries
Tags
AllApply to all nodes

Running Pi-hole? Use the same settings with your Pi-hole node’s private address.

Save the nameserver. With Baseguard DNS enabled, the applicable connected nodes receive the setting. You do not need to visit each device’s Wi-Fi settings or change the router on every network you use.

The same form works for either product. Call it Pi-hole or AdGuard Home; the address determines which server receives the queries.

3. Take it outside

Connect your phone to Baseguard, turn off Wi-Fi, and open a website over mobile data. Check the query log in Pi-hole or AdGuard Home for a fresh query.

Your phone reaches the DNS node over the encrypted Baseguard network. The filter checks the requested domain against its rules and handles the DNS response.

Manage a blocklist once on the DNS server, and devices using that server benefit from the change. The phone can be on mobile data and the laptop on hotel Wi-Fi. Neither needs to be on your home network.

This routes DNS queries to your filter. It does not turn the DNS node into an exit point for all your browsing traffic.

Why Match Domain stays off

For general DNS filtering, you want ordinary internet-domain queries to use your filter. Leaving Match Domain off makes this an upstream nameserver for the applicable nodes. Baseguard still resolves its own node names and custom records first.

Turning Match Domain on creates a different setup: split DNS. A nameserver with corp.internal as its match domain handles queries under that suffix. It will not receive unrelated ad or tracking-domain queries just because it is listed in the console.

Use split DNS when a resolver should handle a particular internal domain. Leave it off when this resolver should provide your general DNS filtering.

You can read more in the Names and DNS lesson.

All your devices, or just some of them

Tags: All applies the nameserver to all nodes in scope. To use it only on a group of devices, select their tags instead.

That lets you try the setup with your own devices first, or keep different DNS arrangements for different parts of the network. The assignment lives in Baseguard; the filtering rules live in Pi-hole or AdGuard Home.

What “DNS firewall” means here

Pi-hole and AdGuard Home filter domain lookups. Depending on your lists, that can block advertising, tracking and known unwanted domains before an application connects to them. Pi-hole also describes VPN access as a way to bring its filtering to cellular devices. See Pi-hole’s overview.

DNS filtering does not inspect every connection or remove every kind of ad. An application using its own DNS resolver can bypass this path. For the setup to apply, keep Baseguard connected and make sure the device is using its DNS configuration.

The DNS host also needs to stay online. Avoid adding an unfiltered public resolver alongside it if you expect every upstream query to be filtered.

The useful part is how little changes when you leave home. Your filter stays on one machine. Baseguard gives your other devices a private way to keep using it.

Explore Private DNS, or connect your first device.

Keep reading

All articles

Insights · 3 min read

Why We Built Baseguard

A laptop, a staging server, a private database. Connecting them should be a small part of the job. We built Baseguard to keep it that way.

Read the article
Get Started

Ready to try Baseguard?

Connect two devices, then follow a short lesson to see how your private network works.

Get started for free