Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS server push for OpenVPN split tunnelling

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mstanding
      last edited by

      Hi community!

      I am using pfsense and OpenVPN for VPN connectivity for my office. Currently all internet traffic goes through the OpenVPN connection. This isn't ideal so would like to implement split tunnelling. We've had a go at this already but noticed that when the DHCP reservation is given to a VPN user, no DNS server is supplied despite being set. This is stopping remote LAN name resolution. As soon as we disable split tunnelling the DNS server is set and resolution works.

      Any help/explaination would be greatly appreciated.

      Matt

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @mstanding
        last edited by

        @mstanding
        Seems like you're missing the route to the DNS server.
        So check the DNS setting on the client and if the route to the server is added to the client.

        M 1 Reply Last reply Reply Quote 0
        • M
          mstanding @viragomann
          last edited by

          Hi @viragomann ,

          I can see a route to the network and I am able to tracert/ping a host on the network - but by IP only.

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @mstanding
            last edited by

            @mstanding
            And what's about the clients DNS settings? Does it even use the remote DNS server?

            M 1 Reply Last reply Reply Quote 0
            • M
              mstanding @viragomann
              last edited by

              Hi @viragomann ,

              No. No DNS server is specified.

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @mstanding
                last edited by

                @mstanding
                So either add the remote DNS server as primary DNS on the client or configure the OpenVPN server (assume this is the office) to provide a DNS (remote access mode) and the client to pull the DNS from the server.

                M 1 Reply Last reply Reply Quote 0
                • M
                  mstanding @viragomann
                  last edited by

                  @viragomann said in DNS server push for OpenVPN split tunnelling:

                  configure the OpenVPN server (assume this is the office) to provide a DNS (remote access mode) and the client to pull the DNS from the server.

                  Thanks @viragomann , how would we do this?

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mstanding @mstanding
                    last edited by

                    @viragomann I mean we add the company DNS server address into the DNS server settings for the split tunnelling and it doesn't get advertised to the clients.

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @mstanding
                      last edited by

                      @mstanding said in DNS server push for OpenVPN split tunnelling:

                      I mean we add the company DNS server address into the DNS server settings for the split tunnelling

                      You have to provide it in the OpenVPN server settings:
                      e0d58fb2-0691-40b3-a548-8ef82d4e429d-grafik.png

                      it doesn't get advertised to the clients.

                      And on the client:
                      65ade91a-acaa-432d-b526-1d6cbe239dff-grafik.png

                      If this doesn't work, check the clients OpenVPN log for hints on what's wrong.

                      1 Reply Last reply Reply Quote 1
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.