OPNsense Forum

English Forums => Virtual private networks => Topic started by: foss-johnny on February 22, 2025, 01:11:35 AM

Title: Wireguard Road Warrior - Some iPhone Apps not loading content
Post by: foss-johnny on February 22, 2025, 01:11:35 AM
Hi,

I've setup WireGuard based on the road warrior configuration tutorial. I'm able to browse the internet when connected from an iPhone, and can see my public IP address is that of the Opnsense router WAN ip.

However, I've noticed that some iPhone apps don't work properly. As an example twitter is not loading new content.

I can nslookup x.com when wireguard is off, but when it's on, nslookup doesn't resolve x.com.

Has anyone else had this issue and know how to resolve?
Title: Re: Wireguard Road Warrior - Some iPhone Apps/Services are not resolving DNS
Post by: foss-johnny on February 22, 2025, 01:03:13 PM
I've noticed when checking Reporting > Unbound DNS > Details tab, that all the services/apps on the iphone that are not resolving DNS have a "Return Code" as "NXDOMAIN" and are highlighted yellow in this log.

It's definately twitter/x and some apple services that I can see so far.
Title: Re: Wireguard Road Warrior - Some iPhone Apps not loading content
Post by: foss-johnny on February 24, 2025, 10:02:13 PM
After further fiddling, when I disable DNS over TLS and tick "Use system nameservers", then in System > Settings > General add 1.1.1.1 to the DNS servers list, DNS resolution is working.

Does anyone know why DNS over TLS resolution does not work for all domains?