Lynx
Senior Member
What is the best way to ensure that DNS queries that arise via DNSFilter such as:
Global Filter Mode: CleanBrowsing (Family)
Get routed through the VPN thereby to safeguard against exposing DNS queries to ISP?
The only way I managed to achieve this before was to specify:
Force Internet traffic through VPN: Yes
But this breaks things like spdMerlin that want to be able to run speed tests over WAN.
Is there a way to use:
Force Internet traffic through VPN: Policy Based Routing (Strict)
such that DNSFilter queries go through the VPN rather than over WAN?
One problem seems to be the difficulty in specifying any route over VPN having the origin as the router. It seems desirable to be able to have router traffic directed to WAN or VPN depending on destination.
Is the situation the same with the VPN Director? Take the very first line 'DNS through WAN' in in the screenshot provided here:
If the first entry were to instead 'DNS through OVPM1', with Iface set to OVPN1, the user would surely expect traffic originating from the router IP to the DNS IP to go over OVPN1, right?
Or is it as for PBR that even if rules require ought to mean traffic from router goes over VPN, in practice all traffic with origin set to router IP goes over WAN regardless?
Global Filter Mode: CleanBrowsing (Family)
Get routed through the VPN thereby to safeguard against exposing DNS queries to ISP?
The only way I managed to achieve this before was to specify:
Force Internet traffic through VPN: Yes
But this breaks things like spdMerlin that want to be able to run speed tests over WAN.
Is there a way to use:
Force Internet traffic through VPN: Policy Based Routing (Strict)
such that DNSFilter queries go through the VPN rather than over WAN?
One problem seems to be the difficulty in specifying any route over VPN having the origin as the router. It seems desirable to be able to have router traffic directed to WAN or VPN depending on destination.
Is the situation the same with the VPN Director? Take the very first line 'DNS through WAN' in in the screenshot provided here:
VPN Director
Third party firmware for Asus routers (newer codebase) - RMerl/asuswrt-merlin.ng
github.com
If the first entry were to instead 'DNS through OVPM1', with Iface set to OVPN1, the user would surely expect traffic originating from the router IP to the DNS IP to go over OVPN1, right?
Or is it as for PBR that even if rules require ought to mean traffic from router goes over VPN, in practice all traffic with origin set to router IP goes over WAN regardless?
Last edited: