- Newest
- Most votes
- Most comments
See this documentation; specifically this section: Scenario #2: Split-tunnel with the "DNS Server IP address" parameter enabled
https://aws.amazon.com/premiumsupport/knowledge-center/client-vpn-how-dns-works-with-endpoint/
Also, please note below from the documentation:
Routing considerations
When you enable split-tunnel mode, all the routes in the Client VPN endpoint's route table are added to the client's route table when the VPN connection is established. This operation is different from the default behavior, which overwrites the client's route table with the entry 0.0.0.0/0 to route all traffic over the VPN.
It is not recommended to add a 0.0.0.0/0 route to the Client VPN endpoint's route table when using split-tunnel mode.
From your screenshots I see that you have Split tunnel enabled as well as 0.0.0.0/0 route added which is not recommended.
Lastly, you seem to have setup DNS server as 10.0.0.2 which looks correct (VPC CIDR +2); when you are connected to the ClientVPN is the client machine able to ping the DNS server?
Once connected to VPN, can you ping / telnet/ ssh any machine in your VPC ? IF yes, that means connectivity over tunnel is working fine.
Start with troubleshooting with these commands.
dig www.google.com nslookup www.google.com
it will confirm if DNS is reachable or not.
Some time problem is where system OS prefer locally network interface configured DNS server instead VPN pushed DNS server, but since traffic is going to tunnel, it cant reach local DNS server which will be 192.168.x.x in your case and fails.
its been discussed here https://docs.aws.amazon.com/vpn/latest/clientvpn-user/linux-troubleshooting.html https://aws.amazon.com/premiumsupport/knowledge-center/client-vpn-fix-dns-query-forwarding/
Relevant content
- Accepted Answerasked a year ago
- asked 3 years ago
- AWS OFFICIALUpdated 3 years ago
- AWS OFFICIALUpdated 9 months ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 2 years ago
Hi Tushar, thanks for the help. even when i disable split tunnel the case is same and it doesn't connect to internet. I will check if i am able to ping 10.0.0.2 as dns server
I just tested i am not able to ping the dns server 10.0.0.2 though i am able to ping 8.8.8.8. so something is wrong with my dns server in vpc?