# How to disable NAT for DNS routes?

**URL:** <https://forum.pritunl.com/t/how-to-disable-nat-for-dns-routes/3225>\
**Category:** Pritunl VPN\
**Tags:** pritunl\
**Created:** [April 10, 2025, 8:14am UTC](https://forum.pritunl.com/t/how-to-disable-nat-for-dns-routes/3225 "2025-04-10T08:14:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrii](https://forum.pritunl.com/user_avatar/forum.pritunl.com/andrii/32/1194_2.png) [@andrii](https://forum.pritunl.com/u/andrii)\
**Post date:** [April 10, 2025, 8:14am UTC](https://forum.pritunl.com/t/how-to-disable-nat-for-dns-routes/3225/1 "2025-04-10T08:14:46Z")

</div>

Hi!

We found that the default behavior for dealing with DNS servers is to NAT them. For our on-prem setup it does not work as we rely on client IP being directly routed and further firewalled on network firewall. For the reference, the rules are:

table ip nat {  
chain POSTROUTING {  
type nat hook postrouting priority srcnat; policy accept;  
…  
ip saddr _NET1_ ip daddr _DNS1_ counter packets 4598 bytes 319594 masquerade  
ip saddr _NET1_ ip daddr _DNS2_ counter packets 14737 bytes 1124645 masquerade  
…

By trial and error we found we can disable these DNS routes altogether by  
“pritunl set vpn.dns\_route false”

Is there a better way to deal with this? Like just disable masquerade and do accept instead?

And more generic question: I didn’t manage to find any documentation on all this config parameters not available in WebUI. Is there any place they exists and documented to some extend? Like some place in source code maybe that I can use as a reference?

Best regards,  
Andrii

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [April 11, 2025, 11:06pm UTC](https://forum.pritunl.com/t/how-to-disable-nat-for-dns-routes/3225/2 "2025-04-11T23:06:43Z")

</div>

Run `pritunl set vpn.dns_route false` then add the DNS servers with `/32` to the routes manually and disable the NAT option. The route options including the NAT option do require an enterprise subscription.

There isn’t any reference to the internal settings, they can be found in the source code in the directory [**pritunl/settings**](https://github.com/pritunl/pritunl/tree/master/pritunl/settings).
