PFsense Split tunnel DNS

Hi,

I setup mullvad wireguard on my PFsense box, it is working totally fine.

My issue is DNS leaks, I am curious if it is possible to assign DNS to an alias group so that the VPN out assigned devices have the mullvad preferred DNS and do not leak, while the non VPN devices will still have the regular 1.1.1.1 DNS and will be routed out the WAN.

I do realize I could manually assign DNS through the DHCP to the devices going out the VPN and simply do an edit whenever I need to take them off VPN, but I am wondering if there is a way to assign that to the alias grouping.

Thanks

I just do a NAT rule to redirect the DNS to Mullvads DNS. Much easier than messing with DNS settings IMO

To actually send traffic over it I use an alias with a group of devices and an allow to go over Mullvad, but deny anywere else below that. I use that same alias above to redirect DNS

Comes up perfect

1 Like

That does seem like a nice and simple solution.

I might be misunderstanding something though. Is that running all the DNS through the VPN?

I live with other people and some of them need to have the proper geo-location for services/games etc. Will this still provide that?

1 Like