Am 07.12.2015 um 15:56 schrieb Pádraig Brady:
On 01/12/15 15:59, Randy Barlow wrote:
This sounds overall pretty neat to me! One detail came to my mind: how
would this interact with VPN DNS servers? In my experience with VPNs,
it's common for them to provide a DNS server that allows internal host
resolution to work. Would this local resolver be notified by NM of a new
VPN connection so that it knows to use the VPN-provided DNS server for
hosts on that particular domain, rather than the usual external records
for that same domain?

That split DNS setup has been working well for me since Fedora 21,
which I enabled using:

   dnf install crudini
   crudini --set /etc/NetworkManager/conf.d/99-split-dns.conf main dns dnsmasq

Details of that setting are in man NetworkManager.conf
Not sending general DNS queries over the VPN
improves speed and avoids stalls when the VPN drops

depends on the VPN - if my company VPN drops i have to take a taxi anyways because it only drops when houston has a problem

given we have some hundret domains the whole point of the VPN is working from home the same way as if i would be in the office and make *anything which is possible* through the DHE-4096 connection and avoid as much as possible network contact bypassing the tunnel

Attachment: signature.asc
Description: OpenPGP digital signature

--
devel mailing list
devel@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/devel@lists.fedoraproject.org

Reply via email to