Skip to content
DnsLister Forum

Where domain hunters compare notes

DoH over VPN instead of WAN

When VPN Client is active for my LAN devices, all their traffic rides the tunnel, but the box's own DNS-over-HTTPS resolver still egresses via the WAN. That means my complete DNS query history reaches my DoH provider stamped with my real home IP, even though every other packet those devices send is VPN-protected.

It also causes a geo mismatch: resolver answers are optimised for my WAN location while the content is then fetched through the VPN exit, worse CDN routing, and potentially more "your IP and your DNS disagree" bot-detection/CAPTCHA friction.

I have worked around this by running a DoH server (AdGuard Home) in my LAN whose upstream rides the VPN. It works, but the setup is fragile and is an overkill, adding another VM/docker container that I need to manage, SSL certificate renewal and overall yet another failure point.

Would firewalla consider an option to have the native DoH implementation ride the VPN?

submitted by /u/formbuddy to r/firewalla
[link] [comments]

Source: r/firewalla · by /u/formbuddy

Leave a Reply

Your email address will not be published. Required fields are marked *