

Search for private DNS in your browser's settings. Alternatively, disable DoT/DoH on the offending clients. To block DoH you need to block access to each individual DoH servers by their IP address. DoH runs over port 443 and is indistinguishable from other HTTPS traffic. DoT can be easily blocked by blocking port 853.The end result is something like this: Test it out by attempting to access the pfSense web interface from a host on the blocked VLAN. Go to the Floating Firewall Rules and create a rule which blocks certain VLANs from accessing the pfSense GUI from its TCP Port.

Mine is currently 443 but I changed it to 444.

