🌐 Pi-hole Active Directory Integration
This guide explains how to integrate Pi-hole as the primary DNS resolver with Windows Active Directory (AD). It covers Pi-hole configuration and the AD server-side steps required for headless Windows environments.
1️⃣ Pi-hole Conditional Forwarding
| Setting | Value |
|---|---|
| Local network | 192.168.20.0/24 |
| DHCP server IP | 192.168.20.253 |
| Local domain name | refol.us |
✅ Ensures queries like
_ldap._tcp.refol.usare resolved by the domain controller at192.168.20.251.
2️⃣ AD Server Configuration (Using PowerShell)
a. Configure DNS Zones
Add-DnsServerPrimaryZone -Name "refol.us" -ZoneFile "refol.us.dns"
Add-DnsServerPrimaryZone -NetworkId "192.168.20.0/24" -ZoneFile "20.168.192.in-addr.arpa.dns" -ZoneType Primary
b. Validate DNS Zones
Get-DnsServerZone | Where-Object {$_.ZoneType -eq "Primary"}
Get-DnsServerZone -Name "refol.us" | Format-List *
c. Configure Forwarders
Add-DnsServerForwarder -IPAddress "8.8.8.8"
Add-DnsServerForwarder -IPAddress "1.1.1.1"
d. Validate Forwarding
Get-DnsServerForwarder
Resolve-DnsName google.com -Server 127.0.0.1
Test-NetConnection -ComputerName 8.8.8.8 -Port 53
Get-WinEvent -LogName "DNS Server" -MaxEvents 50 | Format-Table TimeCreated, Id, Message -AutoSize
e. Ensure Required SRV & A Records
Get-DnsServerResourceRecord -ZoneName "refol.us" -RRType "SRV"
Get-DnsServerResourceRecord -ZoneName "refol.us" -Name "dc01"
f. Enable NTP Synchronization
w32tm /config /manualpeerlist:"time.windows.com,0x9" /syncfromflags:manual /reliable:YES /update
w32tm /resync /nowait
g. Configure Firewall Rules
New-NetFirewallRule -DisplayName "Allow DNS TCP" -Direction Inbound -Protocol TCP -LocalPort 53 -Action Allow
New-NetFirewallRule -DisplayName "Allow DNS UDP" -Direction Inbound -Protocol UDP -LocalPort 53 -Action Allow
3️⃣ Additional Recommendations
- Whitelist AD domain in Pi-hole (
refol.us,dc01.refol.us). - Validate Pi-hole conditional forwarding:
nslookup _ldap._tcp.refol.us 192.168.2.253
dig @192.168.20.253 _kerberos._tcp.refol.us SRV
- Monitor hostname resolution in Pi-hole logs.
- Backup Pi-hole configuration via Teleporter or Nebula Sync.