WireGuard Client – Custom DNS Support and DoH Compliance When "Allow DNS" Is Enabled
Hello TP-Link team and community,
I'd like to submit a feature request related to WireGuard client DNS handling on the Deco BE13000, though I suspect this applies equally to other TP-Link devices with WireGuard client support.
---
Background
When "Allow DNS" is toggled on in the WireGuard client settings, the router automatically assigns the tunnel's gateway IP (e.g., 10.5.5.1) as the DNS server. While that default is reasonable, it introduces two issues that I'd like to see addressed.
Issue 1 – No UI Option to Override the DNS Server
There is currently no way to specify a custom DNS IP through the interface. The only workaround is to manually edit the .conf file, which is neither persistent across firmware updates nor a practical option for most users.
Issue 2 – The VPN Gateway DNS Bypasses DoH Settings
When the tunnel's gateway IP is used as the DNS server, the router ignores any DoH (DNS-over-HTTPS) configuration set at the router level and falls back to the WAN DNS instead. This silently undermines privacy and filtering rules that users have deliberately configured — without any indication that it's happening.
Proposed Solutions
Two improvements would address both issues:
1. Add an optional custom DNS IP field that becomes available when "Allow DNS" is toggled on. This gives users the flexibility to specify any DNS server they choose — for example, the router's own LAN gateway IP — so that router-level DoH and DNS filtering remain in effect even when tunneling traffic through WireGuard.
2. When no custom DNS is specified and the tunnel's gateway IP is used by default, the router should route that DNS traffic through its configured DoH resolver rather than falling back to the WAN DNS. This would make the default behavior consistent with the rest of the router's DNS policy.
Together, these changes would close a meaningful gap for users who rely on router-level DNS filtering and encryption, and bring WireGuard DNS handling in line with the router's broader DNS configuration.
Thank you for considering this request.
