On Wed, 2014-04-23 at 10:36 +0100, Burton, Ross wrote: > I'd guess that this list is being searched in order, so OSX is always > using my local DNS? > > If I uncomment this scutil argument in vpnc-script then the VPN name > servers are always used: > > # next line overrides the default gateway and breaks split routing > #d.add Router $INTERNAL_IP4_ADDRESS Hm, odd. Did you ever come up with a coherent solution to this? Arguably, it's OK to do something which "breaks split DNS" in the case when you weren't using split DNS, so we could make that line conditional. But isn't DNS still going to be broken in the 'split' case, and never give you answers for hosts on the VPN? Might be worth filing this as a bug in macports, where this vpnc-script is also shipped. There might be a little more OSX clue there. -- dwmw2 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 5745 bytes Desc: not available URL: <http://lists.infradead.org/pipermail/openconnect-devel/attachments/20140703/b56db3b4/attachment.bin>