I understand. For now, just go ahead and run it as described above: On your laptop with the above commands, first with VPN disabled, then with it enabled.
Since the behavior you described (working with VPN enabled, indirect without) we want to see the DNS lookup results in both of those cases. Using both your configured DNS servers and forcing CloudFlare (1.1.1.1, which is known to work) Hopefully that makes sense.
bare in mind my dns is different on different devices and I get SD quality when I use my smart TV even though the file is 1080P and then I seen the indirect message
Actually it is unique to your user accocunt. The various servers (IF there is more than one) only vary in the part before it, which is simply their IP.
Can you re-run the commands, post the image, but redact that long string of numbers/letters? And make sure youâre running the command for the local=â1â connectionâs FQDN. You should be running it a total of four times:
Without VPN, no DNS server specified (leave the 1.1.1.1 off the command line).
Without VPN, with 1.1.1.1 specified as the DNS server.
With VPN, no DNS server specified (leave the 1.1.1.1 off the command line).
With VPN, with 1.1.1.1 specified as the DNS server.
You donât need to redact the IP addresses from the results as long as it is the private IP addresses.
Dâoh! Thatâs my fault. Itâs because I told you to use the local=â0â connection and I should have said use the local=â1â connection. My apologies; Iâll correct the relevant posts above.
Please run as described in my last post, with the local=â1â connection.
There is a DNS resolution problem when the VPN is not connected. It appears that the lookup requests are not even making it to the DNS server (neither the default one nor 1.1.1.1) or that the replies arenât making it back.
Do you have any rules in pfSense which might explain this? Itâs not immediately obvious to me your laptop is unable to reach either DNS server when the VPN is disconnected.
What is the laptopâs private IP address when not connected to the VPN? Is it on the same network as the pi-hole (192.168.x.x) or the 10.84.x.x network?
And that 10.84.x.x network looks a bit out of place, given that you mentioned that youâve not configured VLANsâŠ
While I was out taking care of things, I had an opportunity to compare this configuration with my configuration.
Would it be OK to share my thoughts on this?
Asking because if my configuration can serve as foundation, it would allow you to augment to add all the other requirements which the current configuration is struggling & failing to provide.