DNS leak on Openwrt (OpenVPN, Unbound)

I've recently installed an autoritative DNS server (Unbound) and OpenVPN server on my VPS and wanted to use them with OpenWrt. After exporting my .ovpn to the router, the VPN tunnel is working fine... my IP changed, but I'm still using my ISP's DNS.

Here are the different configuration files :

Server.conf (OpenVPN)

local xxx.xxx.xxx
port xxx
proto udp
dev tun
ca ca.crt
cert server.crt
key server.key
dh dh.pem
auth SHA512
tls-crypt tc.key
topology subnet
push "redirect-gateway def1 bypass-dhcp"
ifconfig-pool-persist ipp.txt
push "dhcp-option DNS"
keepalive 10 120
cipher AES-256-CBC
user nobody
group nogroup
status openvpn-status.log
verb 0
crl-verify crl.pem

Openvpn client (.ovpn)

dev tun
proto udp
remote xxx.xxx.xxx.xxx xxx
resolv-retry infinite
remote-cert-tls server
auth SHA512
cipher AES-256-CBC
ignore-unknown-option block-outside-dns
verb 0


Unbound.conf server (partial)

interface: ::1

access-control: allow
access-control: allow
access-control: allow
access-control: ::1 allow


What can I do to avoid DNS leak ? If you need more information from me (or running some tests), don't hesitate to ask !

Did you find out what the cause for the leak was?

I haven't find yet :confused: But since DNS request directly made on the VPS are working fine, I believe that there are probably options in OpenWRT to forward the DNS request through the VPN tunnel...

Don't leave it up to to your vpn client to set dns. Just use iptables rules, like:

iptables -t nat -A PREROUTING -p udp --dport 53 -j DNAT --to $addr
iptables -t nat -A PREROUTING -p tcp --dport 53 -j DNAT --to $addr

I'm following this thread, having the same problem. small question;
How do you define $addr ? i'm getting an error that $addr is not defined.

(i'm using a script to change outgoing dns, when vpn is up. But with a dnsleak check the one I use for vpn is on top, but the other is still in the list, so something is leaking)

Disable peer DNS and configure a VPN-routed upstream DNS provider:

If the issue persists, set up DNS hijacking:


you should set the IP of DNS servers from your VPN provider for your lan. See attached picture.

If Unbound is performing all of your exit recursion, then you can add a forward-zone: either conf or by UCI. Require that you intranet domain is forwarded to the VPN servers and UCI fallback is disabled or conf forward-first: no (won't try the universe on fail). Rare case, but if your VPN servers are actually authoritative servers (NSD, bind, active directory), then it is a stub-zone:.