How to block DNS requests from a smart device in my LAN

How to block DNS requests from a smart device in my LAN

How to block DNS requests from a smart device in my LAN
How to block DNS requests from a smart device in my LAN
2024-06-24 07:19:18 - last edited 2024-06-25 01:13:14
Model: ER605 (TL-R605)   SL2428P   EAP653  
Hardware Version:
Firmware Version:

I have a Tuya Devices that I'm only wanting to control locally via Home Assistant. I'm using the Local Tuya integration you can find here https://github.com/rospogrigio/localtuya .

 

I've blocked internet via ACL WAN Restriction but on the Github page I linked it says:

 

NOTE - Nov 2020: If you plan on integrating these devices on a network that has internet and blocking their internet access, you must block DNS requests too (to the local DNS server eg 192.168.1.1). If you only block outbound internet then the device will sit in zombie state, it will refuse / not respond to any connections with the localkey. Connect the devices first with an active internet connection, grab each device localkey and then implement the block.

 

 

Does anybody know, how I can Block DNS Requests.

 

I have tried with Port53 restriction or Block my DNS IP Adress. But the Tuya Device is still not available.

 

After disable the WAN Internet Restriction, and reconnect the Device, everything works fine. But I want to have a 100% Cloud Free Tuya Device.

 

Thanks

  0      
  0      
#1
Options
1 Reply
Re:How to block DNS requests from a smart device in my LAN
2024-06-25 01:22:22 - last edited 2024-06-25 01:22:37

Hi @Sternness7769 

Thanks for posting in our business forum.

What you described contradicts yourself.

Sternness7769 wrote

I have a Tuya Devices that I'm only wanting to control locally via Home Assistant. I'm using the Local Tuya integration you can find here https://github.com/rospogrigio/localtuya .

 

I've blocked internet via ACL WAN Restriction but on the Github page I linked it says:

 

NOTE - Nov 2020: If you plan on integrating these devices on a network that has internet and blocking their internet access, you must block DNS requests too (to the local DNS server eg 192.168.1.1). If you only block outbound internet then the device will sit in zombie state, it will refuse / not respond to any connections with the localkey. Connect the devices first with an active internet connection, grab each device localkey and then implement the block.

 

 

Does anybody know, how I can Block DNS Requests.

 

I have tried with Port53 restriction or Block my DNS IP Adress. But the Tuya Device is still not available.

 

After disable the WAN Internet Restriction, and reconnect the Device, everything works fine. But I want to have a 100% Cloud Free Tuya Device.

 

Thanks

I don't really understand what you mean and what you need. Do you need it to be Internet-capable? Or you want to block its Internet access?

You blocked it but not available which isn't something you plan to do with the ACL?

I think you should figure out what you need.

 

Block DNS is UDP 53, if you don't have this Service, go and create it in the Preference/Group.

IP Group is needed as well for your IoT device it gets. You might reserve the IP address as well.

Create the ACL and block it from accessing the LAN DNS and WAN DNS individually. DST should be GW(LAN) and ANY IP(WAN).

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. Don't be a lazy asker. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#2
Options

Information

Helpful: 0

Views: 208

Replies: 1

Related Articles