Commit 0bbb7e

2025-02-27 12:58:58 Samuli Seppänen: Add Pushing-DNS-to-clients page
/dev/null .. Pages/Pushing-DNS-to-clients.md
@@ 0,0 1,37 @@
+ # Using DNS servers pushed to clients
+ This page describes how to use pushed DNS servers in the client.
+
+ ## Using DNS servers pushed to a Linux client
+
+ Linux must use an external script to update the DNS servers in `/etc/resolve.conf`
+
+ <span style=color:#0000FF>Blue-pill</span> or <span style=color:#FF0000>Red-pill</span>?
+ * https://github.com/jonathanio/update-systemd-resolved
+ * https://github.com/alfredopalhares/openvpn-update-resolv-conf
+ You are getting <span style=color:#0000FF>Blue-pill</span>'d, regardless...
+
+ ## Using DNS servers pushed to a Windows client
+
+ OpenVPN 2.5+:
+ * Windows uses the OpenVPN built-in DHCP server to update the TAP adapter's DNS servers and no additional steps are required.
+ * This does require that the client is run using the [OpenVPN-GUI](https://community.openvpn.net/openvpn/wiki/OpenVPN-GUI-New) and that the OpenVPN `InteractiveService` for Windows is started.
+ * To prevent DNS leaks at the client use `--block-outside-dns`.
+
+ OpenVPN 2.4:
+
+ * See: 2.5+
+ * **Upgrade Now! **
+
+ OpenVPN 2.3:
+
+ * Windows uses the OpenVPN built-in DHCP server to update the TAP adapter's DNS servers and no additional steps are required.
+ * This **does require** that the client is run as an **administrator** user.
+ * This version does **not** support `--block-outside-dns`
+ * **Upgrade Now! **
+
+ ## Additional notes
+
+ Linux notes:
+
+ * If the client is run using `--user` and `--group` to drop the process privileges then the `--down` script will fail and leave the client DNS in an undefined state.
+ * The recommended way to resolve this is to use the [openvpn-down-root.so](https://github.com/OpenVPN/openvpn/blob/master/src/plugins/down-root/README.down-root) plugin module.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9