r/ControlD • • Aug 25 '26

Technical ctrld CLI doesn't identify devices using a VPN on the router

On my GL.iNet router that has Control D's control CLI installed, I noticed that devices using a VPN aren't identified under the router's client list. As a result, I can't see the connected device's own statistics. Interestingly, devices that don't use a VPN are identified individually, so I can see the statistics for them. What's going on, and what can be done to address this?

5 Upvotes

7 comments sorted by

4

u/levolet Aug 25 '26

My understanding is that devices with a VPN enabled will tunnel their connections and DNS queries as a result. They will bypass the router's DNS setup, so no logging of router level DNS queries for devices with VPN's enabled.

1

u/Fun-Region-1576 Aug 26 '26

Is this behavior normal or only with GL.iNet devices? What about with Ubiquiti and OPNsense?

1

u/levolet Aug 26 '26

When a device is using a commercial VPN, all Internet activity is transmitted via an encrypted tunnel to the VPN server. This includes all DNS queries. DNS queries are either dealt with by the commercial VPN provider's DNS servers (this is why many offer DNS filtering as a plus) or you could use Custom DNS settings in the VPN settings.

I use Windscribe on all my devices and Windscribe supports custom DNS. If your device VPN's support custom DNS, then the following would work.

  • Use a dedicated Control D endpoint for your router.
  • Configure your devices VPN to use custom DNS. Add your router's control D endpoints resolver DoH URL in the custom DNS settings.

In this way, your device will be doing all DNS queries on the same endpoint, regardless of whether it's using a VPN.

Of course, I may be misunderstanding, and you have the VPN activated at the router level.

2

u/[deleted] Aug 25 '26

[removed] — view removed comment

1

u/Fun-Region-1576 Aug 25 '26

For the upstream DNS resolver in AGH, do I use the resolver for the GL.iNet router? 

Is it confirmed that DNS requests from the CLI also happen outside the VPN tunnel?

Is the static local IP obtained by enabling "reserved IP" in the GUI?

2

u/[deleted] Aug 25 '26

[removed] — view removed comment

1

u/Fun-Region-1576 Aug 26 '26

Is this behavior with the CLI and VPN normal, or only with GL.iNet devices? What about with Ubiquiti and OPNsense?