summaryrefslogtreecommitdiffstats
path: root/src/usr/local
diff options
context:
space:
mode:
authorjim-p <jimp@pfsense.org>2016-08-17 15:41:41 -0400
committerjim-p <jimp@pfsense.org>2016-08-17 15:41:41 -0400
commit13ac08b8c500cd05f2a351d0d0d37f0d00514a55 (patch)
treeb681aefa5302f649ee2bf3a6518b3bbba8d3c309 /src/usr/local
parent4b1b6bed60f634985341bfc60f60d4dd3dbbd72a (diff)
downloadpfsense-13ac08b8c500cd05f2a351d0d0d37f0d00514a55.zip
pfsense-13ac08b8c500cd05f2a351d0d0d37f0d00514a55.tar.gz
Add an option to push "block-outside-dns" to clients of an RA OpenVPN. Fixes #6719
Diffstat (limited to 'src/usr/local')
-rw-r--r--src/usr/local/www/vpn_openvpn_server.php11
1 files changed, 11 insertions, 0 deletions
diff --git a/src/usr/local/www/vpn_openvpn_server.php b/src/usr/local/www/vpn_openvpn_server.php
index e7b2af3..6a750bb 100644
--- a/src/usr/local/www/vpn_openvpn_server.php
+++ b/src/usr/local/www/vpn_openvpn_server.php
@@ -268,6 +268,7 @@ if ($_GET['act'] == "edit") {
$pconfig['verbosity_level'] = 1; // Default verbosity is 1
}
+ $pconfig['push_blockoutsidedns'] = $a_server[$id]['push_blockoutsidedns'];
$pconfig['push_register_dns'] = $a_server[$id]['push_register_dns'];
}
}
@@ -534,6 +535,9 @@ if ($_POST) {
$server['dns_server4'] = $pconfig['dns_server4'];
}
+ if ($pconfig['push_blockoutsidedns']) {
+ $server['push_blockoutsidedns'] = $pconfig['push_blockoutsidedns'];
+ }
if ($pconfig['push_register_dns']) {
$server['push_register_dns'] = $pconfig['push_register_dns'];
}
@@ -1066,6 +1070,13 @@ if ($act=="new" || $act=="edit"):
));
$section->addInput(new Form_Checkbox(
+ 'push_blockoutsidedns',
+ 'Block Outside DNS',
+ 'Make Windows 10 Clients Block access to DNS servers except across OpenVPN while connected, forcing clients to use only VPN DNS servers.',
+ $pconfig['push_blockoutsidedns']
+ ))->setHelp('Requires Windows 10 and OpenVPN 2.3.9 or later. Only Windows 10 is prone to DNS leakage in this way, other clients will ignore the option as they are not affected.');
+
+ $section->addInput(new Form_Checkbox(
'push_register_dns',
'Force DNS cache update',
'Run "net stop dnscache", "net start dnscache", "ipconfig /flushdns" and "ipconfig /registerdns" on connection initiation.',
OpenPOWER on IntegriCloud