What is missing is patching the "/etc/resolv.conf" file so that nameserver queries also go through the VPN tunnel. But that is for another day
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
|