Hi,

On Fri, Dec 18, 2015 at 8:24 PM, ValdikSS <i...@valdikss.org.ru> wrote:

> Well, actually Linux can leak DNS requests too, just as Windows 7 and
> older. The leak is usually occurs when DNS didn't respond in time and it
> falls back to secondary server which could be your ISP one.
> Windows 8.1 and 10 is another story, they send DNS queries in parallel to
> all interfaces.
>

True, but Linux/BSD users know how to use netfilter/ipfw/pf/.., don't they?
Anyway, we should stress that this option won't do anything to mitigate dns
issues on non-windows platforms. And to use trusted dns servers and send
the traffic through the tunnel.

In case of windows 7 there is another scenario of a subtle leak when it
fails to properly register the dns server on the tap adapter. Then public
servers defined on other interfaces gets used through the tunnel (yes, that
should not happen, but does happen). Even the block-outside-dns cannot stop
that. Its somewhat orthogonal to the situation in windows8.1/10 where
servers on the LAN causes the problem, while here public servers and broken
dns registration are the issue.

Selva
------------------------------------------------------------------------------
_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to