ISP router avoid traffic analysis with VPN/DNS

If both the VPN and the DNS are on the same machine, there’s a fair about of redundancy, depending on the setup.

If the DNS is only on the browser, then what’s happening in the browser goes through the DNS, but what’s happening outside the browser goes through the VPN. For example, you’re using a desktop email app instead of using email through your browser. In that case, the email is going through the VPN.

The way to have both layers at the same time is to have one set up on your router, and the other on your machine. But for the majority of people that’s overkill, unless you want to take advantage of the custom blocking with DNS, which can be very good.

I’ve experimented with that before. I keep permanent ‘kill-switch’ VPN in my router, and when I added DNS to my desktop machine it helped to block ads that I otherwise had trouble blocking. These days I only use the router VPN, in order to keep my setup a bit simpler. It’s easy to make things more complicated than they need to be.

Normally, one or the other is enough for most people. But if certain ads (which your browser ad blocker isn’t stopping) are driving you nuts, DNS is good.