<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Troubleshooting DNS failures over VPN from Win11 clients]]></title><description><![CDATA[<p dir="auto">Hi</p>
<p dir="auto">Would appreciate any help to troubleshoot why DNS resolutions are failing after Windows 11 clients successfully make VPN connections to pfsense+ ver 23.09.1-RELEASE.</p>
<p dir="auto">Configurations:</p>
<ul>
<li>Configured pfsense+ with IPsec Remote Access VPN Using IKEv2 with EAP-MSCHAPv2 by following<img src="https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-eap-mschapv2.html#ipsec-remote-access-vpn-example-using-ikev2-with-eap-mschapv2" alt="these" class=" img-fluid img-markdown" /> steps.</li>
<li>Windows client configured following these <img src="https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-client-windows.html#configuring-ipsec-ikev2-remote-access-vpn-clients-on-windows" alt="steps" class=" img-fluid img-markdown" />.</li>
</ul>
<p dir="auto">On the Windows client, after connecting to VPN <img src="https://imgur.com/cOmLGxp" alt="see here" class=" img-fluid img-markdown" /></p>
<p dir="auto">DNS Servers is showing to be set correctly (192.168.222.1). I believe the reason for DNS failure is that the DNS Server is showing unknown.</p>
<p dir="auto">Client configurations made on pfsense+ : <img src="https://imgur.com/KVpO7kl" alt="see here" class=" img-fluid img-markdown" /></p>
<p dir="auto">Can someone please help me why DNS is failing on clients after a successful VPN connection? What am I missing?</p>
<p dir="auto">Thanks in advance<br />
Best Regards<br />
SMK</p>
]]></description><link>https://forum.netgate.com/topic/185523/troubleshooting-dns-failures-over-vpn-from-win11-clients</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 19:51:03 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/185523.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 14 Jan 2024 02:54:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Troubleshooting DNS failures over VPN from Win11 clients on Sat, 20 Jan 2024 04:14:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/smk">@<bdi>smk</bdi></a> said in <a href="/post/1148711">Troubleshooting DNS failures over VPN from Win11 clients</a>:</p>
<blockquote>
<p dir="auto">Default Gateway is not being set on the VPN connection.</p>
</blockquote>
<p dir="auto">Pfsense does what you tell it to do - just because you connect to some vpn service - unless you tell pfsense to route all traffic out that connection, why would you think it should be default?</p>
]]></description><link>https://forum.netgate.com/post/1148725</link><guid isPermaLink="true">https://forum.netgate.com/post/1148725</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 20 Jan 2024 04:14:52 GMT</pubDate></item><item><title><![CDATA[Reply to Troubleshooting DNS failures over VPN from Win11 clients on Sat, 20 Jan 2024 00:39:29 GMT]]></title><description><![CDATA[<p dir="auto">Thanks @johnpoz. Apologies for the delay in response.</p>
<p dir="auto">168.63.129.16 is a virtual public IP address that is used by Azure to facilitate a communication channel to Azure where the client VM resides.</p>
<p dir="auto">You hit it on the nail! No problems when testing on a laptop as VPN client!</p>
<p dir="auto">It bothers me that the Default Gateway is not being set on the VPN connection. How can I force that to be set from pfsense?</p>
<p dir="auto">Regards</p>
]]></description><link>https://forum.netgate.com/post/1148711</link><guid isPermaLink="true">https://forum.netgate.com/post/1148711</guid><dc:creator><![CDATA[smk]]></dc:creator><pubDate>Sat, 20 Jan 2024 00:39:29 GMT</pubDate></item><item><title><![CDATA[Reply to Troubleshooting DNS failures over VPN from Win11 clients on Sun, 14 Jan 2024 04:43:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/smk">@<bdi>smk</bdi></a> what server is 168.63.129.16 ?? Why would he know about your stuff?</p>
]]></description><link>https://forum.netgate.com/post/1147741</link><guid isPermaLink="true">https://forum.netgate.com/post/1147741</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 14 Jan 2024 04:43:25 GMT</pubDate></item></channel></rss>