Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #719 > unrolled thread

vpnc and resolv.conf

Started byblueparty <partner50449476@vansoftcorp.com>
First post2011-10-23 20:46 -0700
Last post2011-10-25 18:56 +0000
Articles 6 — 4 participants

Back to article view | Back to comp.os.linux.networking


Contents

  vpnc and resolv.conf blueparty <partner50449476@vansoftcorp.com> - 2011-10-23 20:46 -0700
    Re: vpnc and resolv.conf dk3uz@arrl.net (Edmund H. Ramm) - 2011-10-24 15:59 +0000
      Re: vpnc and resolv.conf blueparty <partner50449476@vansoftcorp.com> - 2011-10-25 06:51 -0700
        Re: vpnc and resolv.conf Chris Davies <chris-usenet@roaima.co.uk> - 2011-10-25 15:50 +0100
        Re: vpnc and resolv.conf buck <buck@private.mil> - 2011-10-25 15:32 +0000
        Re: vpnc and resolv.conf dk3uz@arrl.net (Edmund H. Ramm) - 2011-10-25 18:56 +0000

#719 — vpnc and resolv.conf

Fromblueparty <partner50449476@vansoftcorp.com>
Date2011-10-23 20:46 -0700
Subjectvpnc and resolv.conf
Message-ID<1479b035-b3c2-43d7-98b7-0c9089d5a644@s14g2000vbj.googlegroups.com>
I am using vpnc, which works fine, except it rewrites (temporarily) my
resolv.conf. I don't need DNS resolution with vpn, because I connect
to one and only one host using IP address. On the other hand I'd like
to use my network normally, access Internet, etc. Currently I am
solving the problem by overwriting vpnc generated resolv.conf with
backup of my original file. Everything works as desired, but the
solution look a little ... well, dumb. Is there any elegant way to
solve this ?

TIA

[toc] | [next] | [standalone]


#720

Fromdk3uz@arrl.net (Edmund H. Ramm)
Date2011-10-24 15:59 +0000
Message-ID<j8421l$5ov$1@dk3uz.ampr.org>
In reply to#719
In <1479b035-b3c2-43d7-98b7-0c9089d5a644@s14g2000vbj.googlegroups.com> blueparty <partner50449476@vansoftcorp.com> writes:

> I am using vpnc, which works fine, except it rewrites (temporarily) my
> resolv.conf.
> [...]
> Is there any elegant way to solve this ?

   Thankfully it's been 2 1/2 years since I needed to use vnpc, but IIRC
"DNSUpdate no" in /etc/vpnc/default.conf did the trick.

   Eddi ._._.
-- 
      e-mail: dk3uz AT arrl DOT net  |  AMPRNET: dk3uz@db0hht.ampr.org
               Linux/m68k, the best U**x ever to hit an Atari!

[toc] | [prev] | [next] | [standalone]


#721

Fromblueparty <partner50449476@vansoftcorp.com>
Date2011-10-25 06:51 -0700
Message-ID<55a02bf0-f9f5-4308-9dd9-4f2679a2b599@v28g2000vby.googlegroups.com>
In reply to#720
>    Thankfully it's been 2 1/2 years since I needed to use vnpc, but IIRC

I can see why you say that...

> "DNSUpdate no" in /etc/vpnc/default.conf did the trick.
>

That parameter does not exist in my version of vpnc. From Google I can
see that it stopped working in older versions, while it was still
present. Interesting, program totally ignores file permissions. I
tried to make resolv.conf unwritable, but, since vpnc must be run with
root privileges, it simply overrides that. That's strange, because
most source codes I examined checked if the file was writable in the
same time when the checked if the file exists.

Well, thanks for the answer, anyway.

[toc] | [prev] | [next] | [standalone]


#722

FromChris Davies <chris-usenet@roaima.co.uk>
Date2011-10-25 15:50 +0100
Message-ID<jvuin8xjv7.ln2@news.roaima.co.uk>
In reply to#721
blueparty <partner50449476@vansoftcorp.com> wrote:
> That parameter [DNSUpdate] does not exist in my version of vpnc. From
> Google I can see that it stopped working in older versions, while it was
> still present.

According to the README file included in the Debian distribution, this
parameter is indeed deprecated, but it was managed by the "vpnc-connect"
wrapper script anyway.

Taking a quick look through the new "vpnc-wrapper" script, it seems
to me that if you add this line as the second line of that script
(i.e. underneath the #!/bin/sh line), it will prevent updates to the
/etc/resolv.conf file:

    INTERNAL_IP4_DNS=


Personally, I'd rather the maintainers had kept the DNSUpdate parameter.
Sigh.

Chris

[toc] | [prev] | [next] | [standalone]


#723

Frombuck <buck@private.mil>
Date2011-10-25 15:32 +0000
Message-ID<j86kpg01ikr@news3.newsguy.com>
In reply to#721
blueparty <partner50449476@vansoftcorp.com> wrote in news:55a02bf0-f9f5-
4308-9dd9-4f2679a2b599@v28g2000vby.googlegroups.com:

>> "DNSUpdate no" in /etc/vpnc/default.conf did the trick.
>>
> 
> That parameter does not exist in my version of vpnc. From Google I can
> see that it stopped working in older versions, while it was still
> present. Interesting, program totally ignores file permissions. I
> tried to make resolv.conf unwritable, but, since vpnc must be run with
> root privileges, it simply overrides that. That's strange, because
> most source codes I examined checked if the file was writable in the
> same time when the checked if the file exists.

Make the resolv.conf you wish to preserve immutable.  man chattr
--
buck

[toc] | [prev] | [next] | [standalone]


#724

Fromdk3uz@arrl.net (Edmund H. Ramm)
Date2011-10-25 18:56 +0000
Message-ID<j870og$cj8$1@dk3uz.ampr.org>
In reply to#721
In <55a02bf0-f9f5-4308-9dd9-4f2679a2b599@v28g2000vby.googlegroups.com> blueparty <partner50449476@vansoftcorp.com> writes:

>> Thankfully it's been 2 1/2 years since I needed to use vnpc, but IIRC

> I can see why you say that...

   Not really. When I needed to use vpnc it was always preceeded by my
being dragged out of bed in the middle of the night because some
customer's dirtware was misbehaving.

>> "DNSUpdate no" in /etc/vpnc/default.conf did the trick.

> That parameter does not exist in my version of vpnc.
> [...]

   Well, then I regret being unable to help you.

   Eddi ._._.
-- 
      e-mail: dk3uz AT arrl DOT net  |  AMPRNET: dk3uz@db0hht.ampr.org
               Linux/m68k, the best U**x ever to hit an Atari!

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web