1
20.1 Legacy Series / Controlling outbound routing of DNS forwards from opnsense box
« on: July 08, 2020, 03:56:53 am »
Hi,
I have a VPN that, when up, I want all traffic to flow over. When the VPN is down, traffic should flow across the WAN like usual.
I achieve this normally with a Gateway Group. It works fine for the NAT traffic from the LAN.
However, with unbound, it's a challenge. It wants to send traffic out the WAN interface. I can specify multiple nameservers, but it will always send queries to each one, creating a data leak when the VPN is up.
How can I force the DNS queries out the VPN - but only when it's up? I've tried various rules and none of them have done the right thing.
Thanks!
I have a VPN that, when up, I want all traffic to flow over. When the VPN is down, traffic should flow across the WAN like usual.
I achieve this normally with a Gateway Group. It works fine for the NAT traffic from the LAN.
However, with unbound, it's a challenge. It wants to send traffic out the WAN interface. I can specify multiple nameservers, but it will always send queries to each one, creating a data leak when the VPN is up.
How can I force the DNS queries out the VPN - but only when it's up? I've tried various rules and none of them have done the right thing.
Thanks!