<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification]]></title><description><![CDATA[<p dir="auto">I've installed adguard on the upcoming Cloudron v6. It is installed on a public available VPS. I know the "normal" intended use is for local networks. But because it's possible, I've clicked on install the app <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=fed68e33a46" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
<p dir="auto">I've added the public ip of the Cloudron instance as DNS in my local home router in order to use the adguard functions in my entire local network. BTW: It works perfect.</p>
<p dir="auto">One week later I got an email from the german Federal Office for Information Security (BSI)</p>
<pre><code>Dear Sir or Madam,

open DNS resolvers are abused for conducting DDoS reflection / amplification attacks against third parties on a daily basis. 
</code></pre>
<p dir="auto">The moment I checked the dashboard of adguard, I realized that DDoS had already happened.</p>
<p dir="auto"><img src="/assets/uploads/files/1606994633451-e6742fd0-d0f9-4422-ba58-2a25424f255a-image-resized.png" alt="e6742fd0-d0f9-4422-ba58-2a25424f255a-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">All top clients in the figure above have made a DNS query for the same domain.</p>
<p dir="auto">So my question is: is there any chance to configure the Cloudron firewall/ proxy / whatever to use adguard in the way I want to use it (as a openDNS) without having a tool for attackers out in the wild?</p>
<p dir="auto">If not, I like to see a big red warning sign: do not use adguard on a public infrastructure without having a firewall rule in front of the Cloudron instance. IMHO we as Cloudron users have to be responsible not to have "weapons" for attackers out in the wild.</p>
]]></description><link>https://forum.cloudron.io/topic/3840/adguard-on-upcoming-cloudron-v6-ddos-reflection-amplification</link><generator>RSS for Node</generator><lastBuildDate>Mon, 11 May 2026 08:40:20 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/3840.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 03 Dec 2020 11:28:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 14 Apr 2023 19:39:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lukas" aria-label="Profile: lukas">@<bdi>lukas</bdi></a> you may have a look at the guide from Cloudron here: <a href="https://docs.cloudron.io/apps/adguard-home/#security" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/apps/adguard-home/#security</a></p>
<p dir="auto">However the setup is pretty simple, go to the DNS Settings in Adguard Home and give some names for your client IDs <img src="/assets/uploads/files/1681500834105-img_0209-resized.jpeg" alt="IMG_0209.jpeg" class=" img-fluid img-markdown" /></p>
<p dir="auto">When you entered ClientIDs the DNS will not be available anymore for anyone who is NOT in your Client IDs list. If you want to update your non static IP from your internet service provider, you could do that and put in your public IP. In that case your local clients can use the DNS even without having a named Client ID</p>
<p dir="auto">Then you can use the Tab "Setup Guide" in Adguard Home to get guidance how to get your devices configured.</p>
<p dir="auto">If you want to configure Chrome, Brave or Firefox for DoH you can then use the URL to your Adguard Home DNS Name with appending your ClientId like this for example:<br />
<a href="https://DNS-NAME-TO-YOUR-ADGUARDHOME/dns-query/CLIENTID" target="_blank" rel="noopener noreferrer nofollow ugc">https://DNS-NAME-TO-YOUR-ADGUARDHOME/dns-query/CLIENTID</a></p>
<p dir="auto">Please be aware that you should understand what you do and in case of concerns just don't do it. You will be responsible yourself for anything you do.</p>
]]></description><link>https://forum.cloudron.io/post/64873</link><guid isPermaLink="true">https://forum.cloudron.io/post/64873</guid><dc:creator><![CDATA[Kubernetes]]></dc:creator><pubDate>Fri, 14 Apr 2023 19:39:46 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 14 Apr 2023 19:19:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kubernetes" aria-label="Profile: Kubernetes">@<bdi>Kubernetes</bdi></a> sounds good, is there any guide how to do this correctly?</p>
]]></description><link>https://forum.cloudron.io/post/64872</link><guid isPermaLink="true">https://forum.cloudron.io/post/64872</guid><dc:creator><![CDATA[lukas]]></dc:creator><pubDate>Fri, 14 Apr 2023 19:19:28 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 14 Apr 2023 19:18:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lukas" aria-label="Profile: lukas">@<bdi>lukas</bdi></a> You can specify client IDs in Case you plan to use DoT or DoH method for DNS resolving. This can be configured for each browser and in iOS Devices as a Profile (export from Adguard Home). This may help?</p>
]]></description><link>https://forum.cloudron.io/post/64871</link><guid isPermaLink="true">https://forum.cloudron.io/post/64871</guid><dc:creator><![CDATA[Kubernetes]]></dc:creator><pubDate>Fri, 14 Apr 2023 19:18:23 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 14 Apr 2023 19:05:25 GMT]]></title><description><![CDATA[<p dir="auto">so no way to let connect only from selected clients, like from specific indentifier? Would like to run AdGuard Home for some devices, but I don't have a static IP</p>
]]></description><link>https://forum.cloudron.io/post/64870</link><guid isPermaLink="true">https://forum.cloudron.io/post/64870</guid><dc:creator><![CDATA[lukas]]></dc:creator><pubDate>Fri, 14 Apr 2023 19:05:25 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Thu, 28 Jan 2021 18:04:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mehdi" aria-label="Profile: mehdi">@<bdi>mehdi</bdi></a> I agree with this. However, it would also be important to have the ability to give the container a static internal IP and allow the configuration of the VPN app to set that container as the default DNS server.</p>
]]></description><link>https://forum.cloudron.io/post/24274</link><guid isPermaLink="true">https://forum.cloudron.io/post/24274</guid><dc:creator><![CDATA[iamthefij]]></dc:creator><pubDate>Thu, 28 Jan 2021 18:04:33 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 20:18:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> I think a reasonable default would be to blacklist all non-local IPs (RFC 1918) by default. That way, connecting from VPNs should work, connecting from LAN should work, but connecting from public internet would require manual white-listing.</p>
]]></description><link>https://forum.cloudron.io/post/24186</link><guid isPermaLink="true">https://forum.cloudron.io/post/24186</guid><dc:creator><![CDATA[mehdi]]></dc:creator><pubDate>Wed, 27 Jan 2021 20:18:11 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 18:43:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> sure. The goal was only to make the user a bit more aware of the security settings. It doesn't solve anything else, as you say.</p>
]]></description><link>https://forum.cloudron.io/post/24174</link><guid isPermaLink="true">https://forum.cloudron.io/post/24174</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 27 Jan 2021 18:43:06 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 18:40:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> that doesn't work for most clients as they have dynamic IPs.</p>
<p dir="auto">Unless there's an auth of some sort, port knocking or VPN access to it.</p>
<p dir="auto">Let's go Wireguard. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3c1.png?v=fed68e33a46" class="not-responsive emoji emoji-android emoji--checkered_flag" style="height:23px;width:auto;vertical-align:middle" title=":checkered_flag:" alt="🏁" /></p>
]]></description><link>https://forum.cloudron.io/post/24172</link><guid isPermaLink="true">https://forum.cloudron.io/post/24172</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Wed, 27 Jan 2021 18:40:25 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 18:06:22 GMT]]></title><description><![CDATA[<p dir="auto">One idea might be to fix the package to block all clients by default. I think we just need to put some wildcard to deny all the IP addresses. Would that make things better? This way user has a UI to manually white list their client IP addresses.</p>
]]></description><link>https://forum.cloudron.io/post/24168</link><guid isPermaLink="true">https://forum.cloudron.io/post/24168</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 27 Jan 2021 18:06:22 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 17:41:58 GMT]]></title><description><![CDATA[<p dir="auto">This was something that came up early on when we were discussing AdGuardHome and PiHole. Most folks recommend only exposing something like this via a VPN without binding to 53 on  your public network interface. A VPN still allows people to use it from anywhere but adds a layer of authentication.</p>
<p dir="auto">The way things are now, it's very likely that folks misconfigure their DNS server. Part of Cloudron's draw is that users don't have to think so hard about "doing the right thing". The best way to do that would be to not bind only to a VPN interface and support the VPN setting the DNS server as the default.</p>
<p dir="auto">A setting to "do the wrong thing" could be there for folks that really know what they are doing, but maybe a little more difficult to get to so someone who enables it will also know how to manage their firewalls. Either through their VPS provider or on the machine.</p>
<p dir="auto">Personally, I host mine at home and access over a VPN.</p>
]]></description><link>https://forum.cloudron.io/post/24165</link><guid isPermaLink="true">https://forum.cloudron.io/post/24165</guid><dc:creator><![CDATA[iamthefij]]></dc:creator><pubDate>Wed, 27 Jan 2021 17:41:58 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 15:07:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> yes of course I've read those. My proposal is to have cloudron blocking the port 53 during the installation automatically -- instead of asking the user to do it manually in the docs. In that way we make AdGuard installation more secure by default, instead of relying to the end user to take care of it.</p>
]]></description><link>https://forum.cloudron.io/post/24152</link><guid isPermaLink="true">https://forum.cloudron.io/post/24152</guid><dc:creator><![CDATA[drpaneas]]></dc:creator><pubDate>Wed, 27 Jan 2021 15:07:29 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 11:12:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/drpaneas" aria-label="Profile: drpaneas">@<bdi>drpaneas</bdi></a> did you see the docs at <a href="https://docs.cloudron.io/apps/adguard-home/#securing-installation" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/apps/adguard-home/#securing-installation</a> already?</p>
]]></description><link>https://forum.cloudron.io/post/24141</link><guid isPermaLink="true">https://forum.cloudron.io/post/24141</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Wed, 27 Jan 2021 11:12:15 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Wed, 27 Jan 2021 10:14:58 GMT]]></title><description><![CDATA[<p dir="auto">Would that be OK to configure the firewall on the machine where cloudron is running? In the documentation says to not touch iptables/ufw and similar stuff, so I guess it's not a good idea. Yet, since this is a very serious matter of having AdGuard running wild out there, I would propose to have the app configure the firewall itself -- instead of relying to 3rd party firewalls -- and make this configurable (enable/disable).</p>
<p dir="auto">Upon installation, it could ask you what you would like to do:</p>
<ol>
<li>Block port 53 - allow internal traffic only for AdGuard (recommended)</li>
<li>Do not configure firewall.</li>
</ol>
<p dir="auto">WDYT?</p>
]]></description><link>https://forum.cloudron.io/post/24138</link><guid isPermaLink="true">https://forum.cloudron.io/post/24138</guid><dc:creator><![CDATA[drpaneas]]></dc:creator><pubDate>Wed, 27 Jan 2021 10:14:58 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Sat, 02 Jan 2021 21:07:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> you might have to put it behind a firewall then and only allow internal - you could then have your servers vpn in to your box to query it (I do that for one of my friends).<br />
There's another thread about making apps accessible only from OpenVPN - that would be a neat use case.</p>
]]></description><link>https://forum.cloudron.io/post/22669</link><guid isPermaLink="true">https://forum.cloudron.io/post/22669</guid><dc:creator><![CDATA[doodlemania2]]></dc:creator><pubDate>Sat, 02 Jan 2021 21:07:40 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Sat, 02 Jan 2021 17:38:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dylightful" aria-label="Profile: dylightful">@<bdi>dylightful</bdi></a> said in <a href="/post/20749">adguard on upcoming Cloudron v6 DDoS reflection/amplification</a>:</p>
<blockquote>
<p dir="auto">Playing around with ADGuard today. The inbuilt IP limiter works great and correctly blocks amp attacks.</p>
</blockquote>
<p dir="auto">Do you mean the requests per second limit?<br />
Which setting blocks amp attacks?</p>
<blockquote>
<p dir="auto">Only issue i found was the ability to use DDNS hostnames as a whitelist for dynamic IP nets. CIDR works just aswell i guess...</p>
</blockquote>
<p dir="auto">I had an issue with this too, as I couldn't come up with a CIDR address that would exclude some of the abusing IPs without blocking my own (same network provider).</p>
]]></description><link>https://forum.cloudron.io/post/22641</link><guid isPermaLink="true">https://forum.cloudron.io/post/22641</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Sat, 02 Jan 2021 17:38:29 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Sun, 06 Dec 2020 10:09:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a><br />
Playing around with ADGuard today. The inbuilt IP limiter works great and correctly blocks amp attacks.</p>
<p dir="auto">Only issue i found was the ability to use DDNS hostnames as a whitelist for dynamic IP nets. CIDR works just aswell i guess...</p>
]]></description><link>https://forum.cloudron.io/post/20749</link><guid isPermaLink="true">https://forum.cloudron.io/post/20749</guid><dc:creator><![CDATA[dylightful]]></dc:creator><pubDate>Sun, 06 Dec 2020 10:09:56 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 23:01:40 GMT]]></title><description><![CDATA[<p dir="auto">I am reading up on what the upstream project recommends because IMO it's actually fairly easy to do an IP based rate limit in the app itself. There are several issues around this:</p>
<ul>
<li><a href="https://github.com/AdguardTeam/AdGuardHome/issues/1137" target="_blank" rel="noopener noreferrer nofollow ugc">DNS amplification prevention</a></li>
<li><a href="https://github.com/AdguardTeam/AdGuardHome/issues/805" target="_blank" rel="noopener noreferrer nofollow ugc">Automatically block IP when it reaches a configurable requests limit</a></li>
<li><a href="https://github.com/AdguardTeam/AdGuardHome/issues/1665" target="_blank" rel="noopener noreferrer nofollow ugc">Provide a smarter way to detect &amp; block DNS amplification</a>- Looks like they might add a setting for this</li>
<li><a href="https://github.com/AdguardTeam/AdGuardHome/issues/1032" target="_blank" rel="noopener noreferrer nofollow ugc">Allow the use of IP blocklists to reject DNS requests from the listed IPs</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/20600</link><guid isPermaLink="true">https://forum.cloudron.io/post/20600</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 04 Dec 2020 23:01:40 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 22:26:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a><br />
Not what I said, but in effect yes.</p>
<p dir="auto">What I am suggesting is to limit it to an actual interface not an IP. Anything flowing through a VPN interface for example which is a higher abstraction.</p>
<p dir="auto">Since private networks use RFC1918 addressing that's what ends up flowing through those interfaces. Hence the effect.</p>
<p dir="auto">Having a by default secure install is the only option IMO.<br />
Anyone installing it will need to configure it properly, be it for VPN access and network interfaces, or by going lower into the networking stack and using IP:port settings.</p>
<p dir="auto">It's also a question of liability for you, allowing deployment for DDoS or not.</p>
<p dir="auto">Subsequent modification is the users responsibility.</p>
<p dir="auto">Even if you had an app level firewall, how will it dynamically configure itself for a new client IP every hour? (there are ways but beyond the scope of this discussion)</p>
]]></description><link>https://forum.cloudron.io/post/20596</link><guid isPermaLink="true">https://forum.cloudron.io/post/20596</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Fri, 04 Dec 2020 22:26:33 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 21:43:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> If I understand correctly, you are suggesting that we restrict the app to only private IPs by default. Maybe the IP blocks in <a href="https://en.wikipedia.org/wiki/Reserved_IP_addresses" target="_blank" rel="noopener noreferrer nofollow ugc">https://en.wikipedia.org/wiki/Reserved_IP_addresses</a> ? Thing is I would say the most common deployment of Cloudron is on a VPS and with that as the default a big chunk of people won't be able to use the app out of the box.</p>
<p dir="auto">I think a good solution is to add a app level firewall to Cloudron. I think it's something we can easily add for next release.</p>
]]></description><link>https://forum.cloudron.io/post/20591</link><guid isPermaLink="true">https://forum.cloudron.io/post/20591</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 04 Dec 2020 21:43:29 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 20:47:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> couldn't it just be limited to the VPN interface which you get once connected? That way it remains private and there's no issue with dynamic IPs from home.</p>
]]></description><link>https://forum.cloudron.io/post/20587</link><guid isPermaLink="true">https://forum.cloudron.io/post/20587</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Fri, 04 Dec 2020 20:47:29 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 18:41:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dylightful" aria-label="Profile: dylightful">@<bdi>dylightful</bdi></a> said in <a href="/post/20481">adguard on upcoming Cloudron v6 DDoS reflection/amplification</a>:</p>
<blockquote>
<p dir="auto">I though ADGuard had an inbuilt feature to allow only whitelisted IP's through?</p>
</blockquote>
<p dir="auto">Indeed, I will put this in the docs and the POSTINSTALL.</p>
]]></description><link>https://forum.cloudron.io/post/20561</link><guid isPermaLink="true">https://forum.cloudron.io/post/20561</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 04 Dec 2020 18:41:28 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 02:42:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> I can help with this doc when you're read sir - I've got a PiHole on the public internet and simply block all requests at the router except requests from my IP address. If I'm not mistaken, we'll have some sort of control in 6 to whitelist/blacklist access by IP address to an app?</p>
]]></description><link>https://forum.cloudron.io/post/20483</link><guid isPermaLink="true">https://forum.cloudron.io/post/20483</guid><dc:creator><![CDATA[doodlemania2]]></dc:creator><pubDate>Fri, 04 Dec 2020 02:42:41 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 02:20:21 GMT]]></title><description><![CDATA[<p dir="auto">I though ADGuard had an inbuilt feature to allow only whitelisted IP's through?</p>
]]></description><link>https://forum.cloudron.io/post/20481</link><guid isPermaLink="true">https://forum.cloudron.io/post/20481</guid><dc:creator><![CDATA[dylightful]]></dc:creator><pubDate>Fri, 04 Dec 2020 02:20:21 GMT</pubDate></item><item><title><![CDATA[Reply to adguard on upcoming Cloudron v6 DDoS reflection&#x2F;amplification on Fri, 04 Dec 2020 02:18:18 GMT]]></title><description><![CDATA[<p dir="auto">@humptydumpty No, Pihole is installed locally on the pi attached to the local VPN adapter (wg0 if you're using wireguard). PiVPN internally handles DNS queries and is not publicly resolvable from the public IP/</p>
<p dir="auto">Unless you install Pihole on your public facing adapter instead of your VPN adapter. Then you're in abit of trouble.....</p>
]]></description><link>https://forum.cloudron.io/post/20480</link><guid isPermaLink="true">https://forum.cloudron.io/post/20480</guid><dc:creator><![CDATA[dylightful]]></dc:creator><pubDate>Fri, 04 Dec 2020 02:18:18 GMT</pubDate></item></channel></rss>