Enforce any client that uses port 53 for a DNS lookup to get redirected to the DNS server of your choice. This effectively forces any client with custom or self-configured DNS to still go through your DNS server of choice.
Navigate to the UI and then to: Firewall/NAT -> NAT. Click on "Add a Destination NAT Rule". In my case eth1
is the port all clients
go and eth0
is where the WAN goes in, and 192.168.0.1 is the router itself where the DNS server is
- Inbound interface: eth1
- Translations Address: 192.168.0.1