Skip to content

Split-DNS with another VPN — don't intercept/block DNS to excluded subnets or to a user-defined resolver #1237

Description

@gilberg-vrn

Issue Details

Environment. AdGuard VPN for Windows 2.10.0 (2148), Windows 11 Pro 24H2. Reproduced in General mode with Wintun on, with Wintun off (WFP driver) and in Selective mode.

Scenario. A corporate OpenVPN client runs alongside AdGuard VPN. It pushes routes to the company's private networks and a DNS server that serves an internal (split-horizon) view of the company zones: internal hostnames resolve to private addresses reachable only through the corporate tunnel. Public resolvers return public addresses (or NXDOMAIN) for the same names. Employees want AdGuard VPN for everything else.

Actual.

  1. AdGuardVpnSvc intercepts every UDP/TCP port 53 flow regardless of destination and answers from its own DNS proxy (service log: DNS_HANDLER on_dns_request: ... -> :53 ... -> DNS proxy). Adding the resolver's subnet to Subnet exclusions changes nothing: the routes on the AdGuard adapter and the "AdGuard VPN restrict DNS" WFP filters stay the same, and the forwarder still intercepts.
  2. With the corporate resolver set as a custom DNS server, the forwarder connects to it through the AdGuard tunnel (TUNNEL listener_handler: New client connection request: 127.0.0.1:x -> :53), so the resolver sees the exit-node IP and refuses the query (it only accepts clients from the corporate VPN).
  3. If the corporate resolver has a private address (e.g. 10.0.0.0/8, which is excluded by default), port 53 to it is blocked outright by the "restrict DNS" WFP filter: connect() fails immediately with "An attempt was made to access a socket in a way forbidden by its access permissions", while other ports to the same host work. So a private resolver cannot be used at all.

Proposed solution

A way to keep DNS for the corporate names on the corporate resolver: either DNS queries addressed to a server inside an excluded subnet (Settings → Advanced → Subnet exclusions) are left alone and follow the system route, or a "resolve these domains via this server, outside the tunnel" option.

Please honour Subnet exclusions for DNS (skip interception and the port-53 block for destinations inside excluded subnets), or add per-domain DNS routing with the upstream sent outside the tunnel.

Related: #108, #1081, #1192.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions