[SOLVED]How To Push DNS Server To OpenVPN Clients?

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
gil_happy
DD-WRT User


Joined: 24 Sep 2009
Posts: 139

PostPosted: Fri Jun 04, 2021 20:27    Post subject: [SOLVED]How To Push DNS Server To OpenVPN Clients? Reply with quote
Hello,

I am having difficulty trying to figure out how to configure OpenVPN server on my DDWRT (r45632) to push the DNS server to the clients which connect to the server.

To explain, if you look at the attached diagram, I am connecting via TUN from a Windows 10 PC with OpenVPN GUI (2.5.0.21). When my laptop connects to the VPN sever, its public IP is the same as the VPN server (which is correct), but when I run dnsleaktest.com, my PC is using my local ISP provider DNS instead of the DNS from the ISP at the server location.

Does anyone know how to configure so that when the OpenVPN clients connect to the server, they use the DNS from the server location?

Thanks in advance!


Last edited by gil_happy on Fri Jun 04, 2021 20:50; edited 1 time in total
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12884
Location: Netherlands

PostPosted: Fri Jun 04, 2021 20:45    Post subject: Reply with quote
Please adhere to the forum guidelines and scale your pictures back to no more than 768 pixels width:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

To answer your question, why not read the manual?
link in my signature at the bottom.
See page 19 and 23

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
gil_happy
DD-WRT User


Joined: 24 Sep 2009
Posts: 139

PostPosted: Fri Jun 04, 2021 20:56    Post subject: Reply with quote
My apologies.... I just resized the jpeg.

In terms of guide(s), I assume you mean "DDWRT OpenVPN Server Setup Public v1.98.pdf"?

If so, I'll take another look at pages 19 and 23, but that is where I got stuck when trying to configure as there were a few gotchas. Stay tuned.
gil_happy
DD-WRT User


Joined: 24 Sep 2009
Posts: 139

PostPosted: Sat Jun 05, 2021 2:48    Post subject: Reply with quote
Update:

In the Primary Home(router2) which has the OpenVPN server config, in the Services then the VPN tab, in the 'Additional Config' section I added:

push "dhcp-option DNS 192.168.1.2" [from the pic, this is the IP of my VPN router]
push "dhcp-option DOMAIN home5" [under the Services, Sevices of the VPN router, Used Domain=LAN&WAN, LAN Domain=home5, then save and reboot router]

At this point, when I use my Windows 10 PC and open the OpenVPN client to connect to the OpenVPN server and run https://dnsleaktest.com/, the DNS is pushed to the client and it does work (thanks for this)!

The only thing that I might add is that when I run this DNS leak test when connected to the VPN server, 3 of the 6 returned DNS servers are from the remote end or OpenVPN server location (which is good), but 3 out of the 6 are the local DNS servers. From a service point of view everything is working, but the 3 out 6 local DNS servers 'could' cause a problem down the road.
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6437
Location: UK, London, just across the river..

PostPosted: Sat Jun 05, 2021 8:59    Post subject: Reply with quote
some where in that guide its explained very well how to ignore and how to push you DNS

start with that rule to ignore the DNS pushed by the VPN provider

pull-filter ignore "dhcp-option DNS"

just re-read the guide that egc suggested.. Laughing

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
gil_happy
DD-WRT User


Joined: 24 Sep 2009
Posts: 139

PostPosted: Tue Jun 08, 2021 14:56    Post subject: Reply with quote
Thanks so much! When I add the [push "block-outside-dns"], all DNS entries are sent from the primary location.


Consider this thread closed.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum