DNS Issue When Tunneling a Single App with WireSock

Tagged: 

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • #14007
    Shanpo
    Participant

      Hey, I’m newb here!

      I’m using WireSock and set it up to tunnel only one application through the VPN, which works great. However, I’ve noticed that my DNS is now being routed through the VPN for all applications, not just the one I tunneled.

      Is there a way to configure it so that only the tunneled app uses the VPN DNS, and the rest of the system uses the regular DNS?

      Thanks in advance!

      #14008
      Vadim Smirnov
      Keymaster

        Hey! Great to hear you’ve got WireSock working for per-app tunneling!

        What you’re seeing with DNS is actually expected behavior on Windows due to how the system handles DNS resolution. Here’s a quick breakdown:

        How DNS works on Windows:

        • Windows uses a system service called DNS Client Service (also known as dnscache), which acts as a central resolver.
        • All applications send their DNS queries to this service, which performs the actual DNS resolution on behalf of all apps.
        • Because of this, the DNS request isn’t directly tied to the application that originally needed it — once it’s handed off to dnscache, the link to the original app is lost.

        Why it’s hard to isolate DNS per app:

        • Since dnscache is the one making the DNS queries, any per-app VPN filtering based on the source application doesn’t apply to those DNS packets — they all appear to come from the system service.
        • That’s why, even if you route only one app through the VPN, its DNS request (handled by dnscache) might still go through the VPN if the system DNS is set to use the VPN interface.
        #14354
        gilshehbaz9
        Participant

          Yeah, this is a bit confusing with WireSock because the application split-tunneling and DNS handling work differently on Windows. WireSock can restrict the VPN tunnel to a specific application, but Windows DNS resolution is handled at the system level, so DNS queries aren’t automatically separated by application.

          If your WireGuard profile has a DNS = entry, that resolver can be used while the tunnel is active, even though only one application is configured for the VPN. WireSock’s documentation confirms that DNS is system-wide on Windows and isn’t currently split per application.

          You could try removing the DNS = line from the WireGuard configuration and let Windows continue using its normal DNS resolver. Just keep in mind that this also means the tunneled application won’t automatically get a separate VPN DNS server. If you need a separate DNS resolver for a particular application, you’d likely need an additional DNS/proxy solution rather than WireSock’s normal per-app split tunneling.

          For anyone looking for more information about the game side of things, I also came across this website while researching related topics. The important part with WireSock, though, is that the application routing and DNS routing are two separate things.

        Viewing 3 posts - 1 through 3 (of 3 total)
        • You must be logged in to reply to this topic.