mirror of
https://github.com/XTLS/Xray-core.git
synced 2026-10-01 05:25:43 +00:00
With strictRoute, only port 53 was kept inside the TUN. But Windows' DNS Client service sends the queries for an interface's DNS servers out through that interface, whatever the routes say, and since Windows 11 and Server 2022 it may send them over HTTPS or TLS, when that is set up for the interface (as Windows Settings does) or for the server. Those left through the physical link. On those versions, the DNS Client service may now only connect through the TUN, except for its mDNS and LLMNR. The filters recognize the service by its SID in the token of its process, as Windows Firewall's own rules for it do. Earlier versions only query port 53, and may run the service in one process with others, so they get no such filters. The port 53 rule stays, for the programs that query a resolver on the local network themselves, and for those earlier versions. Tested on Windows 11, elevated: with DoH set on Wi-Fi per adapter, per network profile or by global auto-upgrade, none of the DNS Client's connections left through Wi-Fi (WFP logged the drops by the new filter), names still resolved through the TUN, mDNS and LLMNR still went out, and other programs were unaffected, also in a real Xray run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>