Description
In some scenarios, you may want to preserve a VPN client’s IP address in DNS queries instead of using network address translation (NAT) to translate the traffic to the IP address of OpenVPN Access Server. Preserving the client IP address can help you track DNS queries for monitoring or troubleshooting. For example, if a threat detection system flags a DNS lookup as malicious, you can identify the client that sent the query.
Important: The domain routing feature, introduced in Access Server 3.1.0, affects how VPN clients interact with DNS. Domain routing uses a DNS proxy mechanism that forwards client DNS queries through Access Server to an upstream DNS server.
To preserve a client IP address in DNS queries, ensure the user doesn’t have domain routing rules in their configuration or rules inherited from a group or the global configuration.
Instructions
- Sign in to the Admin Web UI.
- Go to Access Controls > Global Access Rules > Global Subnet Routing Overrides.
- Click Add new subnet routing override, and enter the IP address of your DNS server.
- Repeat the previous step for each additional DNS server.
- Click Save, and then click Restart.
- Ensure the DNS servers can route traffic back to the VPN subnet IP addresses through Access Server.
If you can’t configure routing for DNS traffic, you can identify the original source IP address for specific DNS traffic by running a packet capture (tcpdump) on Access Server. Check the source IP address of the packet as it arrives at the tunnel interface, before NAT translates the traffic and it egresses Access Server.
Need help?
If you have questions, submit a support ticket.
Comments
0 comments
Please sign in to leave a comment.