LAN lost dns when adding NordVPN

Started by Phreak61, December 11, 2024, 10:31:58 PM

Previous topic - Next topic
I am having an issue with every other device on the LAN after adding NordVPN connection. I was trying to get it so only devices added to an alias would go out the VPN. When doing so the devices in the list work great out the VPN but every other device "has no internet" but can ping out to ip but not DNS.

Versions
OPNsense 24.7.10_2-amd64
FreeBSD 14.1-RELEASE-p6
OpenSSL 3.0.15

im sure there are Lots of ways to address this..
if you are using isc>  services > isc4>  lan >  add a public Dns server like 9.9.9.9 and the Nord dns server and the 2nd dns

reboot your devices

DNS servers configured either via DHCP or statically are not a prioritized list. Resolver libraries use all of them in round-robin fashion. So it's important to use a single consistent set of recursive servers. Quad9 has malware and other filtering in place, don't know what NordVPN does. But if they don't, then every second request will have Quad9's filtering applied and every other one won't. Good luck debugging "strange" lookup problems.

Same for e.g. active directory environments. Never configure your DCs and OPNsense as resolvers for your client machines.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)