This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN DNS LEAK

Hi,

 

When connected with SSL VPN from a pc to the UTM my DNS is leaking.

Same thing i have when connected with a SITE TO SITE SSL VPN.

 

How to fix this?

 

grz



This thread was automatically locked due to age.
Parents
  • What do you mean by leaking? Do you mean there is split DNS mode used if you use the Sophos / OpenVPN client?

    -

  • Yes correctly.

    VPN remote access is config to do full tunneling.

    Site to site vpn act the same way

     

  • Is your DNS-Server in the Same Subnet, as your Computer is?

    Please send me Spam gueselkuebel@sg-utm.also-solutions.ch

  • Yes, 

    The UTM is full workring as DNS.

    The image below explain the situation. As you see when browse the internet from site B i get the ip from site a as aspected but the DNS is not forwarding.

     

    In my case is it both, so ssl sts and ssl vpn.

    Case1: when ssl remote access to site A i get the public ip of site A and the DNS of site B. I want both to be from site A. 

    Case2: when ssl sts from site A to site B the same thing happend.

     

    I just used a random dns leak test site to check this. In both cases the dns is going trhough the DNS from site B, but i want all traffice to travel trhough site B.

     

    I hoop you can help

  • It's not clear what you're showing us, so we can't suggest an answer.  perfect-privacy.com's test doesn't seem reliable to me.  It has no idea what public name servers we're using.  In any case, if you're setup is as suggested in DNS best practice, you should have no leaks.

    Cheers - Bob 

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • It's not clear what you're showing us, so we can't suggest an answer.  perfect-privacy.com's test doesn't seem reliable to me.  It has no idea what public name servers we're using.  In any case, if you're setup is as suggested in DNS best practice, you should have no leaks.

    Cheers - Bob 

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children