Is it possible to define a domain to always resolve through the tunnel? Can I set a policy to always resolve "example.com" through the VPN? >>>No; setting device DNS first is your best bet Any other ideas on how to make this work? I could, I suppose, impose restrictions on the DNS server for requests coming from the VPN pool, but I'm not sure if that would just cause a lookup to fail or would it actually fall back to the client's DNS? >>>As long as it is not an authoritative answer, yes, it should work just fine
... View more