This workaround is not bad indeed and saves me, too. But it has
drawbacks that people need to know

1) In newer Ubuntu versions, "dnsmasq" is the default DNS option, so the
config does not have this option to comment out. Instead you have to set
"dns=default" there.

2) With this workaround, some applications need a restart to recognize
the new DNS servers after you started VPN. Browsers are a prominent
example of reading resolv.conf setup at start and then caching this
until restart.

3) The VPN DNS servers are used then, but they are on top of the
underlying DNS servers coming from your local DHCP. They are just added
to the top of the list. As long as the VPN DNS servers are working, data
security is intact. As soon as these stop working, your system might
send DNS queries (that maybe should be confidential) to the underlying
DNS server.

Issues 2 and 3 are the most dangerous as they can compromise VPN
confidentiality.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1688018

Title:
  DNS server from vpn connection is not being used after network-manager
  upgrade to 1.2.6

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/network-manager/+bug/1688018/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to