DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

DNAT on Vigor 2927? - IoT devices

  • Jonathan
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
31 Aug 2025 12:08 - 31 Aug 2025 12:08 #105423 by Jonathan
DNAT on Vigor 2927? - IoT devices was created by Jonathan
Hi all,

I have some IoT devices on my home LAN that I want to 'force' to use a specific DNS IP - I can't access the device settings to alter this manually.

Does anyone know if the Vigor 2927 which I have is capable of DNAT or SNAT rules?   I'm thinking this might be the best solution to force the IoT device DNS on port 53 to a custom DNS setting
Last edit: 31 Aug 2025 12:08 by Jonathan.

Please Log in or Create an account to join the conversation.

More
01 Sep 2025 09:57 - 01 Sep 2025 09:59 #105425 by HodgesanDY
Replied by HodgesanDY on topic DNAT on Vigor 2927? - IoT devices
Hi Jonathan ,

I'm guessing these IoT devices are on the same LAN as other devices that do not require this specific DNS entry?

I would say using DHCP options would solve this problem for you but the 2927, and most - or all other models, do not support Host-specific level options. To get that you'd need to host an external DHCP server (that can cater to those granular settings) or create a new subnet VLAN with the specific DNS entry (or entries) you desire within that subnet's DHCP settings on the 2927 and then inter-link that subnets with any others that require access. 

(If I am understanding your dilemma correctly?)


 
Last edit: 01 Sep 2025 09:59 by HodgesanDY.

Please Log in or Create an account to join the conversation.

  • Jonathan
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
01 Sep 2025 13:41 #105426 by Jonathan
Replied by Jonathan on topic DNAT on Vigor 2927? - IoT devices

Hi Jonathan ,

I'm guessing these IoT devices are on the same LAN as other devices that do not require this specific DNS entry?

I would say using DHCP options would solve this problem for you but the 2927, and most - or all other models, do not support Host-specific level options. To get that you'd need to host an external DHCP server (that can cater to those granular settings) or create a new subnet VLAN with the specific DNS entry (or entries) you desire within that subnet's DHCP settings on the 2927 and then inter-link that subnets with any others that require access. 

(If I am understanding your dilemma correctly?)
Thanks for replying.

Yeah so the IoT devices (robot vacuums) are on their own VLAN which is shared with some other devices - they pull IPs via DHCP from a scope for that VLAN - the DNS for that scope points to my piholes that do the DNS filtering 10.7.0.xxx

Because these IoT devices 'phone back'  to China etc I was looking at running them through my NordVPN connection so they go through a VPN.   The issue I have is that if I point the IoT device to my pihole custom DNS, it creates a DNS leak.   So I was thinking about trying to 'point' those devices to Nords VPN DNS but I can't do that manually as there's no way to change the DNS IP on the devices itself, hence asking about DNAT to redirect the DNS queries.

So yeah, maybe it's best if I use LAN7 which is free and change the DNS entry in the scope to NordVPNs DNS and then connect the IoT devices to that VLAN associated with LAN7 perhaps.

Please Log in or Create an account to join the conversation.

Moderators: Chris