I have this problem too. I think there is a simple work-around. Just move tun* down in /etc/resolvconf/interface-order. This will put the VPN's nameservers at the end of /etc/resolv.conf, so your "normal" nameserver will be used first.
In fact, I think that's a better default for /etc/resolvconf/interface-order, so I filed a wishlist bug: http://bugs.debian.org/612351 Andrew -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org