onelnx
← Back to all posts

4 October 2026

PiHole, Unifi & Proton VPN

PiHole, Unifi, Proton VPN Blog Post Image

Intro

My home network is divided into 4 sub-networks:

  • Main
  • Kids
  • IoT
  • Surveillance

The purpose of separating my home network is to grant me maximum control over how devices on my network behave. For example, the Kids network can only access the internet between 8am to 8pm. The IoT network cannot directly access any other networks without explicit network rules.

All sub-networks use the same DNS server which is run by PiHole which then routes traffic through the Proton's VPN DNS server and then through the default gateway as follows:

DNS path through Pi-hole, UniFi and ProtonVPNDiagram: DNS queries from the Main, Kids, IoT and Surveillance networks go to Pi-hole, then the UniFi gateway, through an encrypted ProtonVPN tunnel to the internet. 1. Every device sends DNS to Pi-hole. 2. Pi-hole drops blocked domains, forwards the rest. 3. Gateway routes traffic into the VPN tunnel. 4. ProtonVPN exits to the internet.DNS PATH · HOME NETWORKEvery query, filtered and encryptedFour isolated networks resolve through Pi-hole, route via the UniFi gateway, and reach the internet through ProtonVPN.HOME NETWORK · UNIFICORE · VLAN 1PROTONVPNINTERNETMain192.168.X.X/24VLAN 10LaptopDesktopPhoneNASKids192.168.X.X/24VLAN 20TabletConsoleChromebookPhoneIoT192.168.X.X/24VLAN 30Smart TVSpeakerThermostatLightsSurveillance192.168.X.X/24VLAN 40Front camRear camDoorbellNVRENCRYPTEDTUNNELPi-holeDNS · 192.168.1.2:53blocks ads & trackersUniFi Gateway192.168.1.1default routeVPN serverWireGuard exitmasks home IPWebupstream DNS& sites12341Every device sends DNS to Pi-hole2Pi-hole drops blocked domains, forwards the rest3Gateway routes traffic into the VPN tunnel4ProtonVPN exits to the internet

Rotate your phone to landscape for a larger view.

This provides multiple layers of network protection:

  • All 'dodgy' DNS queries are dropped by PiHole
  • Further DNS filtering and ad-blocking occurs at the VPN DNS
  • Lastly all traffic exiting my home is via an encrypted tunnel through the VPN.

Configuration / Setup

The following setup needs to happen in order to achieve this design:

  1. Installation and configuration of PiHole
  2. Custom network DNS configuration
  3. Configuration and installation of VPN client in Unifi
  4. Update PiHole's upstream DNS Server

1. Installation and configuration of PiHole

PiHole needs to be downloaded and installed onto your network see https://pi-hole.net/ There are many options on how to install PiHole, I have blogged on an approach here: https://www.onelnx.com/blog/configuring-pihole-and-unifi-for-dns

2. Custom network DNS configuration

In Unifi at the network settings page /network/default/settings/networks you need to go to each network and set the DNS Server to the IP address of the server where PiHole was installed: Setting PiHole DNS in Unifi Also you should have a firewall rule for each subnet to prevent the use of any other DNS servers. Thus ensuring that all devices only use the PiHole server.

3. Configuration and installation of VPN client in Unifi

You need to go into your Proton VPN account and navigate to the downloads page: https://account.protonvpn.com/downloads

Use the WireGuard configuration to create a .conf file that can be imported into Unifi. Follow each step and select a server which is close to you that supports IPv6 and has a low load amount.

Export that configuration and go back into Unifi network overview network/default/settings/settings_overview and click Create New under VPN Client

Select the following options in the configuration dialog:

  1. WireGuard as the connection type
  2. File as the Setup and upload the file
  3. Associate all of the internal networks with this policy / route

4. Update PiHole's upstream DNS Server

Lastly, PiHole needs to be configured to use the DNS server from proton. The DNS server IP used by the Proton VPN will be available in Unifi as a result from step 3.

Go into PiHole's DNS settings admin/settings/dns and remove all other selected IPs and type the Proton's VPN IP into the custom DNS servers box, and save. 🎉

Latency / Speed Examples

My current broadband package gives me 500Mbps down and 40Mbps up. Below are some examples of the speed tests that I've run using this setup:

Unifi Router

From the Unifi router I'm getting 550Mbs down and 53Mbps up.

fast.com

From fast.com I'm getting 530Mbs down and 42Mbps up.

Benefits / Consequences

Here are some general benefits / consequences of using this approach to secure your home network traffic

Benefits

  • The entire house is secured behind a VPN not an individual device.
  • All devices use PiHole hence all 'dodgy' DNS queries are blocked before reaching the internet.
  • Because the VPN is at the router level no split tunnelling is needed.
  • Actual location & IP will be masked for all devices.
  • All traffic is hidden from the ISP.
  • Proton's Malware, Ads & Trackers protection works across all devices (inc. Smart TVs).

Consequences

  • If a VPN server is experiencing high load levels this will impact your latency
  • Some services / devices such as Amazon & Google use processes which may result in either blocking the service completely or allowing the service including tracking, ads etc.
Need help with this? See our IT Networking Installation service →