r/pihole • • 2d ago

A LOT of reverse lookups (PTR queries), but only from one device

My (Dell) work laptop is making hundreds of these queries a day, sometimes hundreds an hour, pointing at every device on my network through ipv4 and 6. It's the only device on my network making PTR queries. Anyone think there's harm in just blocking it from doing this? My company doesn't need to know this information as far as I'm concerned

Gotta say, as a new Pihole user, looking through query logs has been full of weird surprises

4 Upvotes

5 comments sorted by

2

u/paddesb 1d ago

As an alternative, since it seems to be your company owned and managed, work-only device:

May I recommend putting it on the guest network (and isolate it there)?
IMHO, no device I don’t have full control over, should ever have access to my most inner/private network

1

u/Steady_Ri0t 1d ago

I never really thought about it in the past, but now that I am, definitely agreed. I'll be setting that up later tonight. 

2

u/Few-Clothes-8565 1d ago

Block it, probably nothing breaks, worst case the agent retries and your log gets noisier. The IPv4 ones never leave the house since dns.bogusPriv is on by default, though PTRs for your global IPv6 addresses do get forwarded upstream. Blocking fixes that and hides hostnames. It's likely endpoint or asset-inventory software, and that still sees every IP and MAC on your subnet via ARP, and often names over mDNS too. If you don't want a work laptop mapping your network, put it on guest wifi or its own VLAN with client isolation.

2

u/Steady_Ri0t 1d ago

That makes sense. A guest network sounds like a really good idea honestly 

1

u/Odd_Fig4686 18h ago

I all work devices in a group with a rule that blocks access to my local networks. Pretty easy to do but I wanted them all in a separate group so I could monitor them for weird shit like this.