- Enable VPN kill switch so it blocks all traffic when the tunnel is down
- Set the VPN as default route before network comes up (always on VPN)
- Disable OS fallback DNS and captive portal probes if possible
- Push DNS through the tunnel explicitly (VPN provided DNS or your own over the tunnel)
- Possibly overkill but useful for peace of mind. Block port 53 outside the tunnel with firewall rules
If DNS can’t reach anything unless the VPN interface is up, then it’s working.
I’ve covered this a couple of times but the confusion is making me think this is one of those times when I think I’m being clear but I’m actually not. I might have to write a guide just for this question.
Login to reply
Replies (2)
Yeah a lot of this is going over my head. A guide would be helpful because idk what most of these things are.
@MAHDOOD
I wrote the guide covering why you should care, how to do it, and how to test it.
It ended up being longer than I expected (roughly 40 pages). Too long for an article and even too long for a field manual. I decided to sale it to try and recoup some operating expenses.
Since you inspired the guide you will get a free copy. I’ll DM you a link once it goes live.