VPN with public dns?
Team,
See also attached screenshot:
I'm trying to setup an OpenVPN connection with the attempt of having all traffic routed via this VPN.
However, based on the DNS-settings it looks like at least partially, the traffic is bypassing the VPN?
This is because the second DNS-server belongs to Google (i.e. 8.8.8.8)?
Any suggestions?
Is there a way to assign the internal DNS-server (i.e. 192.168.139.235)?
This because this DNS-server also runs Pihole.
With warm regards - Will
=====
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
As a follow-up to this post:
I just noticed that the router is also using Google-DNS - even without an active VPN and without any Google-config on the WAN-port (see attached images).
The first image shows the IP-statistics between Google-DNS and the TP-link router.
The second image shows the WAN-settings of the TP-link router.
Is there anything I can do to prevent this from happening?
Alternatively: would it work to block all outgoing DNS traffic with destination 8.8.8.8?
Cheers - Will
=====
- Copy Link
- Report Inappropriate Content
EDIT
- Copy Link
- Report Inappropriate Content
@ITV I would think you could create a stub LAN subnet (ie dummy subnet that goes nowhere, except maybe some unused port on the ER605) on the router for 8.0.0.0/8, router IP being 8.0.0.1 and that should blackhole any Google DNS traffic. I don't think any Policy Route should be required, but you'll know soon enough in your PCAP.
- Copy Link
- Report Inappropriate Content
Thank you all for the feedback.
I took the easy way out by adding a rule which denies all DNS traffic to the Google DNS-services.
This was easy because the TP-link router ACL's work with an "implicit allow" (versus "implicit deny" like most other vendors).
- Copy Link
- Report Inappropriate Content
Team Tp-link-support:
Just read the release notes of the new controller version (i.e. 5.6.3) - in particular the section called "VPN optimization":
Does this mean that this issue is fixed when the new gateway firmware is also made available?
Cheers - Will
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 4434
Replies: 36
Voters 0
No one has voted for it yet.