In short
Warda checks the network every 5 minutes: Network → Network analysis, Network check, and a warning on the dashboard. The usual cause is the box of the Internet announcing its own IPv6 DNS server: turn it off (or put the IPv6 address of Warda instead), with the guide of your box below.
A device goes around Warda without any error: pages open, ads come back, and the device shows little or nothing in Reports → Query log. Warda looks for two causes on its own and tells you:
- a box or a router that announces another DNS server over IPv6 than Warda (told on the dashboard, in Protection → Alerts, and in the assistant);
- devices present on the network that never ask Warda for a day.
The Network check card (Network → Network analysis) shows the router at fault (name, IPv6 address, hardware address, the servers it announces), the IPv6 address of Warda to give instead, a link to the guide of your box (below), and the silent devices. Check again runs it at once.
The IPv6 of the box#
Most boxes of the Internet turn IPv6 on by default and announce their own DNS server with it (router advertisement, RDNSS, or DHCPv6). Windows, Android, iOS and macOS ask this server first, or as well, even when the IPv4 DNS server of the network is Warda. Three ways out, the first one the safest:
- Turn off IPv6 on the local network of the box (or its IPv6 DNS server). Internet keeps working in IPv4, and every name goes through Warda.
- Put the IPv6 address of Warda as IPv6 DNS server of the box, when it
offers it (Freebox). Use a local address (
fd…) when Warda has one; an address taken from the prefix of the provider changes with it. - Let Warda announce itself over IPv6 (Network → DNS services): the devices get Warda too, but keep the server of the box beside it.
Then turn the Wi-Fi of the devices off and on again (or unplug the cable).
On Windows, this shows the DNS servers really used; a line of the family
23 (IPv6) must no longer show the address of the box:
Get-DnsClientServerAddress | Where-Object ServerAddresses | Format-Table InterfaceAlias, AddressFamily, ServerAddresses -AutoSizeFreebox#
In Freebox OS (Freebox settings, advanced mode):
- DHCP: put the IPv4 address of Warda as the only DNS server.
- IPv6 configuration, tab IPv6 DNS: tick the use of custom IPv6 DNS servers and put the IPv6 address of Warda shown by the check; or turn IPv6 off on the same page.
Livebox#
The Livebox does not let you change the DNS server it gives, and its DHCPv6 cannot be turned off on its own:
- let Warda give the addresses of the network (Let Warda give the addresses of the network (DHCP) in the assistant, chapter 3), then turn off the DHCP server of the Livebox (Network, DHCP);
- in the advanced settings of the Livebox, tab IPv6, turn IPv6 off.
Bbox#
In the interface of the Bbox, the DHCP server settings accept a DNS server on most models: put the IPv4 address of Warda. In the IPv6 settings, turn IPv6 off on the local network, or its DNS server when the page offers it. The menus change with the model (Must, Ultym, Fit…).
SFR Box#
The SFR Box does not let you change the DNS server it gives: let Warda give the addresses of the network (chapter 3) and turn off the DHCP server of the box. In its IPv6 settings (Network v6 on most models), turn IPv6 off.
Synology router#
In SRM:
- Network Center → Local Network → the network → DHCP IPv4: Primary DNS is the IPv4 address of Warda, Secondary DNS empty.
- Network Center → Internet → Connection → IPv6 setup: set IPv6 setup to Disabled. In Auto, the router relays the IPv6 of the box in front of it, its DNS server with it, even when DHCPv6 is off on the local network.
Other routers#
In the IPv6 settings of the local network, look for what announces a DNS server: the router advertisements (RDNSS) and the DHCPv6 server. Put the IPv6 address of Warda there, or turn them off; turning IPv6 off on the local network works everywhere. On OPNsense and pfSense, it is in Services → Router Advertisements (DNS options) and DHCPv6. If the router sits behind a box that also runs IPv6, check the box too: a router in relay mode passes its announcements on.
Devices that never ask Warda#
A device present on the network for an hour at least, which has not asked Warda anything for a day, is listed in the check. The causes, most frequent first:
- the IPv6 of the box (above): check it first;
- a DNS server written by hand in the device (network settings of
Windows or macOS,
8.8.8.8): set it back to automatic; - the secure DNS of a browser (Chrome, Edge, Firefox): turn it off, or give it the DoH address of Warda (chapter 9);
- the private DNS of Android set to a provider: Automatic, or the name of Warda (chapter 9);
- a VPN, or iCloud Private Relay: the names go through the tunnel;
- a device with its own DNS (some televisions, speakers and cameras
use
8.8.8.8whatever the network says): only a rule of the router that sends every DNS query (ports 53 and 853) to Warda brings them back.
A switch or an access point asks nothing, rightly: they are not listed. A printer asleep may stay silent for days.
Some devices use their own DNS on purpose (a printer, a camera). Ignore this device, on its line in Network → Network analysis, lists it apart under Devices ignored, for every administrator, and it no longer counts; Stop ignoring counts it again. On the dashboard, Hide until a new one appears hides the notice until another device goes silent. A device only counts once it has been on the network for an hour without a break: a laptop just woken up is not listed.