In short
Give the box a fixed address (DHCP reservation in the
router), then set it as the DNS server in the DHCP of the router. For a
try, set the DNS of one device only. Check:
nslookup doubleclick.net <address> must answer 0.0.0.0.
As long as the router gives its own DNS servers, devices do not go through Warda.
- Fixed address. In the interface of your router, DHCP section, reserve an address for the Warda box (often called "static lease" or "reservation").
- Try on one device. In the network settings of one device only (Wi-Fi of a phone, network card of a PC), set the address of Warda as DNS. Browse for a few minutes: ads disappear and the device shows in Devices.
- The whole network. When all is well, set the address of Warda as the DNS server in the DHCP of the router. Devices take it at their next connection (if needed, turn Wi-Fi off and on).
The assistant recognises the boxes of Free, Orange, SFR and Bouygues Telecom and gives the steps for yours; you find it again in Network → Network analysis, How do I connect the network to Warda?. Another router (Synology, OPNsense, Fritz!Box…) is shown with its model when Warda recognises it, as are the other routers found on the network. The Livebox and the SFR Box do not let you change the DNS: then let Warda give the addresses of the network itself (Let Warda give the addresses of the network (DHCP) in the assistant). It fixes its own address, you turn the DHCP server of the box off, and Warda checks that no other one answers before it starts.
If the box also announces a DNS server over IPv6, Warda warns you: turn IPv6, or its DNS server, off in the box, or the devices may go around Warda. Warda can also announce itself as DNS server over IPv6 (Network → DNS services); turning off the IPv6 DNS of the box stays the sure way.
In Network → Network analysis, Scan the network lists every machine of the network and shows which ones already use Warda (Warda also scans every night). You can give them to a person or a group even before they use Warda. The same page says whether the box is plugged into a managed switch: such a switch announces itself (LLDP or CDP) with the port of the box and its VLAN; an unmanaged switch says nothing.
The devices have a local name, those that get their address from Warda
first, then the machines found on the network, for example
tv-livingroom.home.lan, and the interface also answers at
warda.home.lan. The domain is chosen from the language at installation
(home.lan in English, maison.lan in French) and changed in Network
→ Local DNS. Warda never uses .local, kept for Bonjour and Avahi.
The same page takes names of your own (a NAS, a lab): an address (A,
AAAA), another name (CNAME) or a text (TXT).
Network proxy (WPAD), at the bottom of Local DNS, is for a network that runs its own proxy (a business filter, a cache): give its name or address and its port, and the devices that detect a proxy automatically use it (local sites and networks stay direct; add exceptions if needed). It is off by default and should stay so otherwise: pointing all the devices to a proxy is a classic way to spy on a network. It works best with Warda on port 80 (the page warns otherwise).
Encrypted DNS. In Network → DNS services, Get the certificate with a name given by Warda (nothing to set up, free, renewed by itself): the phones keep their "private DNS" and still go through Warda. Android: Private DNS, with the name shown; iPhone and Mac: the profile to download; Windows and the browsers: the DoH address shown. The same page tells which upstream servers validate DNSSEC. Only at home: Android keeps its private DNS everywhere, so outside, a phone set to this name gets no names at all; use it for the devices that stay home, or set the phone back to Automatic before leaving.