DNS requests leak
Posted: Wed Sep 29, 2010 10:29 pm
I've set up a new (dev) OpenVPN on a linux server. I've configured it to push googles 8.8.8.8 DNS server to the clients.
I'm on a windows box. nslookup shows that it's using the 8.8.8.8 DNS server just fine.
When I do a packet capture I see that all traffic, including DNS is going through the VPN (I go to a random website to ensure DNS is called, also nslookup's don't show any traffic outside of the VPN).
There is a case, however, where DNS requests are going through my local DNS server, I think it's when a flash app comes up.
I'm racking my brain trying to figure out how or why there are any exceptions. Does anyone have a thought on what I might do to track down exactly what's happening here? How can I understand the routing logic going on behind the scenes for the odd case here?
Thoughts? Thank you!
David
I'm on a windows box. nslookup shows that it's using the 8.8.8.8 DNS server just fine.
When I do a packet capture I see that all traffic, including DNS is going through the VPN (I go to a random website to ensure DNS is called, also nslookup's don't show any traffic outside of the VPN).
There is a case, however, where DNS requests are going through my local DNS server, I think it's when a flash app comes up.
I'm racking my brain trying to figure out how or why there are any exceptions. Does anyone have a thought on what I might do to track down exactly what's happening here? How can I understand the routing logic going on behind the scenes for the odd case here?
Thoughts? Thank you!
David