NUNIVIA
NUNIVIA Protection Wall

Four protection layers. One afternoon.

Router firewall, encrypted DNS and browser hardening — the next step after AdGuard Home. No extras needed, no Linux knowledge.

Fritz!BoxAdGuard Home requiredChromeFirefoxWindowsmacOS
  • Reinforce the router firewall — prevent DNS bypass
  • Enable encrypted DNS (DoH/DoT) in AdGuard Home
  • Browser hardening with uBlock Origin and HTTPS-only
  • Endpoint basics: malware scan + password manager
  • Functional test at the end — you'll see right away if everything works

Who is this guide for?

This guide requires the NUNIVIA Home Guide. You should be able to tick off these points:

  • NUNIVIA Home Guide completed

    AdGuard Home is running on your mini PC at home

    To the Home Guide
  • Router DNS pointed to the mini PC

    The DNS address in your router points to your AdGuard Home server (explained in the Home Guide)

  • AdGuard Home dashboard reachable

    You can log in at http://[IP-of-the-mini-PC]:3000

All three points met? Then you're ready for the four protection layers.

Why 4 layers?

DNS filtering is good. But it has blind spots.

AdGuard Home blocks known malicious domains before they load. That's real protection. But three gaps remain: new phishing domains not yet on block lists; apps that bypass DNS filtering directly; and attacks via already-allowed, legitimate sites.

Three more layers close these gaps — without extra hardware:

  • Router firewall: prevents DNS bypass and blocks suspicious connections
  • Encrypted DNS: protects your DNS queries from eavesdropping and tampering
  • Browser hardening: blocks at the content level what DNS can't see
Requirement: AdGuard Home is already running on your network. If not: Set up the Home Guide first
Layer 2 — Preview

What does the router firewall do — and why isn't DNS filtering enough?

DNS filtering blocks domains — but a clever device can bypass the DNS filter by connecting directly to IP addresses instead of resolving domain names. This happens with some games, VPN apps or peer-to-peer connections.

DNS filtering alone

  • Blocks known malicious domains
  • Can be bypassed via direct IP connection
  • No protection against DNS leaks

+ Router firewall (Layer 2)

  • DNS bypass attempts blocked
  • UPnP disabled (prevents apps from opening ports)
  • Encrypted DNS upstream (DoH/DoT)

The complete step-by-step instructions for Fritz!Box and other routers are available after purchase in Layer 2 (~20 minutes).

Layer 4 — Preview

Why isn't network protection enough — and what does browser hardening add?

Network filters see DNS queries and IP connections — but not what happens on an allowed site. Ads, trackers and malicious scripts often run on the same domains as legitimate content.

  • uBlock Origin: Blocks ads and trackers at the content level — even on allowed domains
  • HTTPS-only mode: Prevents unencrypted connections — protects against man-in-the-middle
  • Disable browser DoH: Ensures the browser uses your AdGuard Home, not its own DNS

Layer 4 shows the exact settings for Chrome, Firefox, Windows and macOS — with screenshots (~20 minutes).

MS
Illustrative example

“I thought the Protection Guide was just some checklist. But it was more like a conversation with myself — what do I actually want for my children, and what are we already doing well as a family? That surprised me.”

Miriam S., mother (children 9 and 14)

FK
Illustrative example

“We were constantly arguing about phones. No clear system, no real rules — different every evening. The Protection Guide helped us sit down once, think it through, and write it all down. Since then the arguments have dropped off significantly.”

Florian K., father (son 11)

NW
Illustrative example

“I'd been putting it off for weeks. Then I worked through the Protection Guide in one evening — made the decisions once, wrote everything down. Since then I don't have to rethink it every single day.”

Nicole W., mother (children 9 and 12)

🛡️ NUNIVIA Home Guide required: Requires NUNIVIA Home Guide No Home Guide yet?

Unlock all 4 protection levels.

Router firewall, DoH/DoT, browser hardening, and endpoint protection — with function test. Unlock once.

79EUR

one-time · no subscription · instant access

  • Level 1: Check DNS foundation (5 min.)
  • Level 2: Router firewall + DoH upstream (20 min.)
  • Level 3: Enable DNSSEC + encrypted DNS (15 min.)
  • Level 4: Browser hardening for all devices (20 min.)
  • Bonus: Basic endpoint protection at no cost (10 min.)
  • Function test: see immediately if all levels are active
Secure payment · Instant access
Payment via Stripe
Data in Germany
SSL secured

Prefer to start free — Checklist

Secure purchase via Stripe · Privacy Policy