- Log into unifi controller web UI
- Go to Settings
- Search for "Firewall" and click on ""Add New Firewall Group
- Enter all your DNS servers here you want to be allowed on the local LAN (Eg, mine is 10.0.1.1 - gateway, 10.0.1.14 - pi-hole)
- Name this "Allowed DNS Servers"
- Hit OK
- SSH into the Gateway - NOT the CloudKey (username/password is whatever you set up)
- do this: 'mca-ctrl -t dump-cfg > config.txt'
- edit the new file, config.txt 'vi config.txt'
- Look for something that has the description field:
"description": "customized-Allowed DNS Servers"