Wireguard Site-to-Site VPN Mandatory Setting to Prevent IP or DNS Leak

I am using a Wireguard Site-to-Site VPN setup using two Glinet routers (Flint 2 & Slate AX).

Could someone please help me what are the options I should disable/enable to prevent IP or DNS Leaks on both Server and Client routers, I see the below options.

Server

Wireguard Server Options:
Remote Access LAN - On
IP Masquerading - On
MTU - 1420
Client to Client - Off

Security Settings
HTTPS Remote Access - Disabled
SSH Remote Access - Disabled

DNS
DNS Rebinding Attack Protection - Off
Override DNS Settings of All Clients - Off
Allow Custom DNS to Overrise VPN DNS - On

Client:

Global Options:
Block Non VPN Traffic - On
Allow Access WAN - Off
Services from Glinet use VPN - Off

Wireguard Client Options:
Remote Access LAN - Off
IP Masquerading - On
MTU - 1420

One of those devices needs to „leak“ DNS (mostly the server) because it must use DNS. What is your use case?

1 Like

The "DNS Leak" issue is only an issue for VPN client. There should not such thing for the server side.

my use case:

i work in the USA, using my employer's laptop. But sometimes I may have to travel to some other countries like Canada, India, etc., and for the same reason I have made the Wireguard Site-to-Site VPN using two routers (Server and Client) to use my home ISP IP wherever I am and my other country IP or location should not be visible.

Wireguard Site-to-Site VPN setup is working fine and I am using my USA home IP from another country. I have enabled the block Non-VPN traffic option on my Wireguard Client router.

Just want to make sure if I am missing anything or if is there any other option I have to disable or enable so that it seems like my connection is always from the USA with my home IP.

OK. We can forget about the "Site-to-Site" concept because you are doing a Clinet-Server setup.

As you have set up the vpn client and server so let's omit the setup.

Flint 2 is the vpn server at your home, and
Slate AX is the vpn client with you when travel.

On the server nothing need to worry. Just remember what is your home IP address.

On the client (Slate AX), first make sure you upgrade to firmware 4.6.4 because it fixed some DNS leaks.

After vpn is connected, check the following. Better not on your work laptop.

  1. Your IP address. Make sure it is your home IP, e.g. google, ipleak or whatismyipaddress etc.
  2. Check dns leaks using www.dnsleaktest.com or other website. All the dns should be the dns from your ISP. You can see the dns server locations. Should not have and dns server from the location where you are
2 Likes

alzhao, thanks for ur reply.

i did the below DNS leak test for both cases directly on my USA home internet, from Comporium ISP, and using wireguard client from different using my USA home IP config.

USA home internet - DNSLeaktest results

WIreguard Client with USA Home IP Config

It shows that I am using dnsservice. How can I avoid this, as my home IP is DHCP? I enabled Dynamic DNS on the Glnet Flint 2 router (Wireguard Server) and used the DNS entry name given by the Glnet router ending with glddns.com on the Wireguard client config file instead of IP, as IP can change.

Is this bad instead of showing my home ISP, it shows ISP as Security Services, how can I prevent this, also which setup is the best one for my use case Site-to-Site VPN or Server/Client Setup? I am under the impression both are the same.

if different how can I make a Site-to-Site VPN setup to use my USA home IP wherever I travel?

See this thread Flint - which DNS IP in Wireguard Server conf to use Adguard? and replace the DNS line inside your WireGuard client config accordingly.

(Or just replace it with 8.8.8.8 for Google)

this helped now DNS leak test shows ISP as my home ISP I kept home ISP DNS server on the config file DNS section.

Is there anything I need to look for.

I think it looks fine now.

now i am down with another problem with ny setup.

I am getting very bad speeds when use wireguard client in slate glnet routers in USA & India. In USA it was working great, but same config file if i use on router in India i am getting only 5–10 mbps speed

created new topic for speed issue

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.