Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Does openVPN client support updating the resolv.conf ?

    OpenVPN
    2
    4
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      euidzero
      last edited by

      Hello,

      I'm using openVPN client on pfsense 2.2.6. I bridge (TAP) my local LAN with a remote LAN where there is a specific internal DNS.
      This DNS holds the map for my internal.domain.
      Some of the hosts at the remote LAN can also be reached via a public IP.
      When the VPN is up I want pfsense to use the internal DNS (at the remote end of the tunnel).
      When the VPN is down I want pfsense to use my ISP DNS servers (and ther resolve to the public IP for some servers)

      It seems to me that openvpn client on pfsense lack the ability to update pfsense  resolv.conf when it receive the "DHCP option DNS" from the openvpn server. I  tried to force the option in openvpn client configuration without better results.

      Can someone confirm that resolv.conf is not updated by the openvpn client ?

      I've tried to workaround with many dnsmasq configurations without perfect results (domain overrides with strict order simply don't work).

      Thanks,
      EiZ

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        It does not support that at this time. There is a feature request open on redmine to add that support IIRC.

        1 Reply Last reply Reply Quote 0
        • E
          euidzero
          last edited by

          Well : https://redmine.pfsense.org/issues/753 is 5 years old.

          Seems like a WontFix for me :/ Any chance this issue could be examined again ?

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            Very rarely desirable to do that when the firewall's a client is why it's sat there forever with no movement. It's not hard to add to ovpn-linkup if you want to do so.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.