Blame

0bbb7e Samuli Seppänen 2025-02-27 12:58:58 1
# Using DNS servers pushed to clients
2
This page describes how to use pushed DNS servers in the client.
3
4
## Using DNS servers pushed to a Linux client
5
6
Linux must use an external script to update the DNS servers in `/etc/resolve.conf`
7
8
<span style=color:#0000FF>Blue-pill</span> or <span style=color:#FF0000>Red-pill</span>?
9
* https://github.com/jonathanio/update-systemd-resolved
10
* https://github.com/alfredopalhares/openvpn-update-resolv-conf
11
You are getting <span style=color:#0000FF>Blue-pill</span>'d, regardless...
12
13
## Using DNS servers pushed to a Windows client
14
15
OpenVPN 2.5+:
16
* Windows uses the OpenVPN built-in DHCP server to update the TAP adapter's DNS servers and no additional steps are required.
17
* This does require that the client is run using the [OpenVPN-GUI](https://community.openvpn.net/openvpn/wiki/OpenVPN-GUI-New) and that the OpenVPN `InteractiveService` for Windows is started.
18
* To prevent DNS leaks at the client use `--block-outside-dns`.
19
20
OpenVPN 2.4:
21
22
* See: 2.5+
23
* **Upgrade Now! **
24
25
OpenVPN 2.3:
26
27
* Windows uses the OpenVPN built-in DHCP server to update the TAP adapter's DNS servers and no additional steps are required.
28
* This **does require** that the client is run as an **administrator** user.
29
* This version does **not** support `--block-outside-dns`
30
* **Upgrade Now! **
31
32
## Additional notes
33
34
Linux notes:
35
36
* If the client is run using `--user` and `--group` to drop the process privileges then the `--down` script will fail and leave the client DNS in an undefined state.
37
* The recommended way to resolve this is to use the [openvpn-down-root.so](https://github.com/OpenVPN/openvpn/blob/master/src/plugins/down-root/README.down-root) plugin module.