Blame
| 0bbb7e | Samuli Seppänen | 2025-02-27 12:58:58 | 1 | # Using DNS servers pushed to clients |
| 2 | This page describes how to use pushed DNS servers in the client. |
|||
| 3 | ||||
| 4 | ## Using DNS servers pushed to a Linux client |
|||
| 5 | ||||
| 6 | Linux must use an external script to update the DNS servers in `/etc/resolve.conf` |
|||
| 7 | ||||
| 8 | <span style=color:#0000FF>Blue-pill</span> or <span style=color:#FF0000>Red-pill</span>? |
|||
| 9 | * https://github.com/jonathanio/update-systemd-resolved |
|||
| 10 | * https://github.com/alfredopalhares/openvpn-update-resolv-conf |
|||
| 11 | You are getting <span style=color:#0000FF>Blue-pill</span>'d, regardless... |
|||
| 12 | ||||
| 13 | ## Using DNS servers pushed to a Windows client |
|||
| 14 | ||||
| 15 | OpenVPN 2.5+: |
|||
| 16 | * Windows uses the OpenVPN built-in DHCP server to update the TAP adapter's DNS servers and no additional steps are required. |
|||
| 17 | * This does require that the client is run using the [OpenVPN-GUI](https://community.openvpn.net/openvpn/wiki/OpenVPN-GUI-New) and that the OpenVPN `InteractiveService` for Windows is started. |
|||
| 18 | * To prevent DNS leaks at the client use `--block-outside-dns`. |
|||
| 19 | ||||
| 20 | OpenVPN 2.4: |
|||
| 21 | ||||
| 22 | * See: 2.5+ |
|||
| 23 | * **Upgrade Now! ** |
|||
| 24 | ||||
| 25 | OpenVPN 2.3: |
|||
| 26 | ||||
| 27 | * Windows uses the OpenVPN built-in DHCP server to update the TAP adapter's DNS servers and no additional steps are required. |
|||
| 28 | * This **does require** that the client is run as an **administrator** user. |
|||
| 29 | * This version does **not** support `--block-outside-dns` |
|||
| 30 | * **Upgrade Now! ** |
|||
| 31 | ||||
| 32 | ## Additional notes |
|||
| 33 | ||||
| 34 | Linux notes: |
|||
| 35 | ||||
| 36 | * If the client is run using `--user` and `--group` to drop the process privileges then the `--down` script will fail and leave the client DNS in an undefined state. |
|||
| 37 | * The recommended way to resolve this is to use the [openvpn-down-root.so](https://github.com/OpenVPN/openvpn/blob/master/src/plugins/down-root/README.down-root) plugin module. |
