Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN client and Google domains

    Scheduled Pinned Locked Moved General pfSense Questions
    19 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic
      last edited by

      Good day!
      Have VPN client on pfsense and home traffic going over this client. In general setting DNS servers are empty. DNS resolver outbound interface set to localhost. No any problems with internet anywhere. DNS leak test show me VPN/DNS servers. But can not entering any Google domains or Youtube. Youtube inform that PC is offline. Can someone explain , what is going on?

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Is the client you're testing from using pfSense for DNS?

        You might be hitting some DoH issue, try a different browser.

        Steve

        A 2 Replies Last reply Reply Quote 0
        • A
          Antibiotic @stephenw10
          last edited by

          @stephenw10 I'm tried other browser but still the same. All browsers use system default DNS. Laptop also using pfsense DNS.

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          1 Reply Last reply Reply Quote 0
          • A
            Antibiotic @stephenw10
            last edited by Antibiotic

            @stephenw10 Tried from pfsense DNS lookup to google.com and received - Host "google.com" could not be resolved but bing.com OK!

            pfSense plus 24.11 on Topton mini PC
            CPU: Intel N100
            NIC: Intel i-226v 4 pcs
            RAM : 16 GB DDR5
            Disk: 128 GB NVMe
            Brgds, Archi

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by stephenw10

              Try it against a different DNS server: dig @8.8.8.8 google.com

              Seems like maybe your VPN providers DNS servers are doing something.

              A 1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @stephenw10
                last edited by

                @stephenw10 This is result
                Screenshot 2023-03-25 003744.png

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  OK so it resolves fine against 8.8.8.8.
                  So what is it trying to resolve against that's failing? The VPN providers servers?

                  A 2 Replies Last reply Reply Quote 0
                  • A
                    Antibiotic @stephenw10
                    last edited by Antibiotic

                    @stephenw10 Idk just have working VPN client on pfsense from ExpressVPN. But this Google crying))) Looks like Google thinking that my Laptop dont have working DNS but I'm not expert))

                    pfSense plus 24.11 on Topton mini PC
                    CPU: Intel N100
                    NIC: Intel i-226v 4 pcs
                    RAM : 16 GB DDR5
                    Disk: 128 GB NVMe
                    Brgds, Archi

                    1 Reply Last reply Reply Quote 0
                    • A
                      Antibiotic @stephenw10
                      last edited by Antibiotic

                      @stephenw10 I tried from Laptop with native VPN client connected and Youtube start working . But wanna use on pfsense for whole home network with Google domains in working condition. This disaster did my day today)))

                      pfSense plus 24.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Ok so check what the clients are using for DNS. It would normally be the pfSense LAN IP address.

                        Check what DNS servers pfSense is using in Diag > DNS Lookup.

                        If you set Unbound to localhost did you also set it to forwarding mode?

                        Is the VPN client setting itself as the default route when it connects?

                        A 3 Replies Last reply Reply Quote 0
                        • A
                          Antibiotic @stephenw10
                          last edited by

                          @stephenw10 said in VPN client and Google domains:

                          Ok so check what the clients are using for DNS. It would normally be the pfSense LAN IP address.
                          Check what DNS servers pfSense is using in Diag > DNS Lookup.
                          If you set Unbound to localhost did you also set it to forwarding mode?
                          Is the VPN client setting itself as the default route when it connects?

                          1. Client using pfSense LAN IP
                          2. Pfsense using 127.0.0.1 as DNS server
                          3. Negative, Unbound not in forwarding mode
                          4. Default route gateway is my ISP gateway if talking about System/routing settings
                            Screenshot 2023-03-25 012125.png

                          pfSense plus 24.11 on Topton mini PC
                          CPU: Intel N100
                          NIC: Intel i-226v 4 pcs
                          RAM : 16 GB DDR5
                          Disk: 128 GB NVMe
                          Brgds, Archi

                          1 Reply Last reply Reply Quote 0
                          • A
                            Antibiotic @stephenw10
                            last edited by Antibiotic

                            @stephenw10 Screenshot 2023-03-25 012451.png Screenshot 2023-03-25 012517.pngScreenshot 2023-03-25 012936.png

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            1 Reply Last reply Reply Quote 0
                            • A
                              Antibiotic @stephenw10
                              last edited by Antibiotic

                              @stephenw10 Screenshot 2023-03-25 012824.pngScreenshot 2023-03-25 013513.png

                              pfSense plus 24.11 on Topton mini PC
                              CPU: Intel N100
                              NIC: Intel i-226v 4 pcs
                              RAM : 16 GB DDR5
                              Disk: 128 GB NVMe
                              Brgds, Archi

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Ok, then Unbound is going to using the default route for resolving which is directly via the WAN and not via the VPN. Unless your VPN wasn't connected when you checked that?
                                So I would expect a DNS leak test to show the WAN IP and not the VPN.

                                However it should still be able to resolve google via either route. You might try turning up the logging level in unbound and check for errors.

                                Did this just start happening?

                                A 3 Replies Last reply Reply Quote 0
                                • A
                                  Antibiotic @stephenw10
                                  last edited by

                                  @stephenw10 I don'Screenshot 2023-03-25 015636.png t have any leakages and don not see any errors in logScreenshot 2023-03-25 015904.png

                                  pfSense plus 24.11 on Topton mini PC
                                  CPU: Intel N100
                                  NIC: Intel i-226v 4 pcs
                                  RAM : 16 GB DDR5
                                  Disk: 128 GB NVMe
                                  Brgds, Archi

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    Antibiotic @stephenw10
                                    last edited by

                                    @stephenw10 Screenshot 2023-03-25 020232.png Screenshot 2023-03-25 020259.png

                                    pfSense plus 24.11 on Topton mini PC
                                    CPU: Intel N100
                                    NIC: Intel i-226v 4 pcs
                                    RAM : 16 GB DDR5
                                    Disk: 128 GB NVMe
                                    Brgds, Archi

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      Antibiotic @stephenw10
                                      last edited by

                                      @stephenw10 VPN all time was connected

                                      pfSense plus 24.11 on Topton mini PC
                                      CPU: Intel N100
                                      NIC: Intel i-226v 4 pcs
                                      RAM : 16 GB DDR5
                                      Disk: 128 GB NVMe
                                      Brgds, Archi

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Ok, then your default route must switch when the client connects. Which is expected with the gateway set to automatic like that if the OpenVPN config doesn't expressly prevent it.
                                        However Unbound should still be able to resolve via either route.

                                        You probably need to turn up the logging level further to see query level logs.

                                        You might try disabling IPSec and see if that allows it to resolve though.

                                        Steve

                                        A 1 Reply Last reply Reply Quote 0
                                        • A
                                          Antibiotic @stephenw10
                                          last edited by Antibiotic

                                          @stephenw10 Solved by set in firewall rule( Lan traffic to ExpressVpn) default gateway to ExpressVpn. Thank you for your assistance. Have a good weekend!
                                          Screenshot 2023-03-25 022907.png

                                          pfSense plus 24.11 on Topton mini PC
                                          CPU: Intel N100
                                          NIC: Intel i-226v 4 pcs
                                          RAM : 16 GB DDR5
                                          Disk: 128 GB NVMe
                                          Brgds, Archi

                                          1 Reply Last reply Reply Quote 1
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.