Skip to content
Arshansh Agarwal, home

Ramblings//6 min read

Homelabbing (1)

Creating a network wide Ad blocker

I recently got into Homelabbing.

For the un-initiated, Homelabbing is the idea of hosting and managing your own servers and other IT infrastructure on a small scale at your Home. The idea behind a Home lab is to learn how networking and hosting works, and create your own services like Cloud storage, Adblocker, VPN, media server; and if you are lucky you can even stop paying Giant Corporations money for these services by hosting your own (Exciting, right?).

There is so much you can do with a Home lab, that it makes it hard not get into it. Even a small NAS (network attached storage) can make your google Storage unnecessary, and also keep your data near you locally (not in cloud, making it private). But it is also a slippery slope. There is a reason why most people don't host their own servers and choose to pay Giants like Google and Apple monthly fees for small amount of storage.

  1. It is not for a layman guy - It required more than basic understanding of tech to even start.
  2. It gets expensive fast
  3. Reliability - Your own homelab cannot compete with Google on reliability, availability or even features, but it can get pretty dang close.

This reddit comment defined it perfectly -

Homelab is a cute little monster that eats money and free time, lots of it, and it starts to get bigger and bigger, then eats a ton of electricity and maybe less free time or not

Anyway, now that we’ve covered the basics.

I wanted to start with a Media Server (JellyFin) to host my own content. But that was not possible because i didn't had a capable enough machine lying around which can do video transcoding, which required atleast the 7th Gen Intel. So I went with the other thing that i wanted to try - Adding a adblocker to my network, which would theoretically block every Ad and malicious website on every device on my network. Which honestly sounds like a pretty sweet deal to me!

Now, you might be wondering - How does these magical Ad-blockers work, Arshansh?

Excellent question! let me explain (putting my nerd glasses ON!)

Whenever you send a request to any website like Google.com, that request is sent to a DNS. The DNS is like a big phone directory which maps that domain to an IP Address, and send the request to that specific IP, completing the request. These Adblockers work on the concept of DNS Sinkhole. They act as a DNS server. When an app or browser tries to look up an Ad or tracking domain, this special DNS responds with a null or empty address (a "black hole") so the connection never happens. They use a opensource list of pre-determined domains which are deemed malicious, and responds null whenever these requests are made.

To make them network wide, we use a computer which acts as the DNS sinkhole on the same network and configure our router to use the IP of that computer as the primary DNS.

Because the task doesn't need too much compute and power, i went with a Raspberry Pi 4B as the computer of choice. Frankly, they are so expensive right now, if I didn't had one lying around, i would have went with something else.

There were mainly 2 contenders for the firmware for the DNS sinkhole. Pi-hole and AdGuard Home. Both AdGuard Home and Pi-hole are popular and open-source which makes either of them a easy option. But i went with AdGuard, mainly because it natively supports DoT (DNS over TLS) and DoH (DNS over HTTPS), which provides a new layer of encryption to my DNS calls.

The whole process went pretty smoothly. I flashed the Raspberry PI OS (lite 32 bit) on the Pi. Connected the Pi to my network. SSH-ed into the pi using the terminal. Installed AdGuard Home. Frankly, the toughest part of this process was to find a spare micro-SD card for my Raspberry Pi OS, which took embarrassingly long.

Now, what's left was to configure my AdGuard Home and my router. The AdGuard was simple enough, the GUI was intuitive and easy to navigate. The tough part was configuring the router. It will be an understatement to say that i hate my Router's GUI. If I had two bullets, Hitler, and my router’s creator in a room. I’d shoot the creator twice. Not just out of hatred, but because I’m pretty sure the first shot wouldn’t register without a page refresh. Every click took 10 seconds to register, and even then the interface would occasionally logout while navigating. It took me half an hour to even find the setting i was looking for.

Which is DHCP configurations. I had to do 2 things here. First, set a static IP for my Raspberry Pi on the network, so that on reconnecting the Pi a new IP is not assigned to it, And the second thing was to set my Primary DNS as that static IP. After that, i restarted my router and...

Voilà! It worked, Now I was able to access any weird website without worrying about millions of popup every second. It worked better than i expected, not only did it blocked Ads, it also blocked other tracking domains, so no 3rd party website can track my data. Take that Google Analytics!

In the last 12 days alone, it has blocked more than 146k malicious n/w requests, which is more than 25% of the total network requests. Also the internet experience seems to be faster, because no unnecessary calls are taking n/w bandwidth anymore.

It works wonders! But, it is not a perfect solution as well. There are many types of Ads that adGuard cannot block. Ads with the same origin as website cannot be blocked, because the DNS cannot differentiate b/w a valid and an Ad call. This makes YouTube ads un-avoidable, because they use the same domain as their video streaming requests.

What's next -

I will be doing more fun things in this Homelabbing journey. Next plan is to create a JellyFin media server and connect it to Arr stack to make my very own self hosted Netflix. I finally got my hands on a machine which can do video transcoding! I also want to explore Tailscale (or NetBird) for my personal VPN and play with immich to host my own images.

Until then,

Stay Hydrated

Later aligator!

All ramblings