• Wispy2891@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    16 hours ago

    Right, it won’t ask the DNS server to resolve it, the solution requires a much more expensive blocking on firewall

      • mic_check_one_two@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        8
        ·
        8 hours ago

        No, a machine won’t even contact the pihole if it finds the address in its hosts file. Hosts is step 0 for DNS, so if it finds something there it doesn’t even bother with contacting an external server (like a pihole).

      • Wispy2891@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 hours ago

        i realized that the problem with an hosts file is the the system will completely bypass the dns server and directly contact the address. There is the need of something that enforces an IP address blocklist at the router level like opnsense