Four protection layers. One afternoon.
Router firewall, encrypted DNS and browser hardening — the next step after AdGuard Home. No extras needed, no Linux knowledge.
- Reinforce the router firewall — prevent DNS bypass
- Enable encrypted DNS (DoH/DoT) in AdGuard Home
- Browser hardening with uBlock Origin and HTTPS-only
- Endpoint basics: malware scan + password manager
- Functional test at the end — you'll see right away if everything works
Who is this guide for?
This guide requires the NUNIVIA Home Guide. You should be able to tick off these points:
- ✓
- ✓
Router DNS pointed to the mini PC
The DNS address in your router points to your AdGuard Home server (explained in the Home Guide)
- ✓
AdGuard Home dashboard reachable
You can log in at http://[IP-of-the-mini-PC]:3000
All three points met? Then you're ready for the four protection layers.
DNS filtering is good. But it has blind spots.
AdGuard Home blocks known malicious domains before they load. That's real protection. But three gaps remain: new phishing domains not yet on block lists; apps that bypass DNS filtering directly; and attacks via already-allowed, legitimate sites.
Three more layers close these gaps — without extra hardware:
- ✓Router firewall: prevents DNS bypass and blocks suspicious connections
- ✓Encrypted DNS: protects your DNS queries from eavesdropping and tampering
- ✓Browser hardening: blocks at the content level what DNS can't see
What does the router firewall do — and why isn't DNS filtering enough?
DNS filtering blocks domains — but a clever device can bypass the DNS filter by connecting directly to IP addresses instead of resolving domain names. This happens with some games, VPN apps or peer-to-peer connections.
DNS filtering alone
- ✓Blocks known malicious domains
- –Can be bypassed via direct IP connection
- –No protection against DNS leaks
+ Router firewall (Layer 2)
- ✓DNS bypass attempts blocked
- ✓UPnP disabled (prevents apps from opening ports)
- ✓Encrypted DNS upstream (DoH/DoT)
The complete step-by-step instructions for Fritz!Box and other routers are available after purchase in Layer 2 (~20 minutes).
Why isn't network protection enough — and what does browser hardening add?
Network filters see DNS queries and IP connections — but not what happens on an allowed site. Ads, trackers and malicious scripts often run on the same domains as legitimate content.
- ✓uBlock Origin: Blocks ads and trackers at the content level — even on allowed domains
- ✓HTTPS-only mode: Prevents unencrypted connections — protects against man-in-the-middle
- ✓Disable browser DoH: Ensures the browser uses your AdGuard Home, not its own DNS
Layer 4 shows the exact settings for Chrome, Firefox, Windows and macOS — with screenshots (~20 minutes).
“I thought the Protection Guide was just some checklist. But it was more like a conversation with myself — what do I actually want for my children, and what are we already doing well as a family? That surprised me.”
— Miriam S., mother (children 9 and 14)
“We were constantly arguing about phones. No clear system, no real rules — different every evening. The Protection Guide helped us sit down once, think it through, and write it all down. Since then the arguments have dropped off significantly.”
— Florian K., father (son 11)
“I'd been putting it off for weeks. Then I worked through the Protection Guide in one evening — made the decisions once, wrote everything down. Since then I don't have to rethink it every single day.”
— Nicole W., mother (children 9 and 12)
Unlock all 4 protection levels.
Router firewall, DoH/DoT, browser hardening, and endpoint protection — with function test. Unlock once.
one-time · no subscription · instant access
- ✓Level 1: Check DNS foundation (5 min.)
- ✓Level 2: Router firewall + DoH upstream (20 min.)
- ✓Level 3: Enable DNSSEC + encrypted DNS (15 min.)
- ✓Level 4: Browser hardening for all devices (20 min.)
- ✓Bonus: Basic endpoint protection at no cost (10 min.)
- ✓Function test: see immediately if all levels are active
Prefer to start free — Checklist
Secure purchase via Stripe · Privacy Policy