@@ -908,10 +908,13 @@ The VPN traffic shall be encrypted between the VPN client and the designated end
#### 5.7.7.1 Requirement
Unless DNS traffic is routed exclusively through the VPN at all times, the VPN client shall offer a configuration option to route all DNS queries using well-known ports through the VPN connection.
1.**REQ-CON-07 (MI-DNSL-2)-1** The VPN client shall offer a configuration option to route all DNS queries that use well-known ports through the VPN connection, or
2.**REQ-CON-07 (MI-DNSL-2)-2** the VPN client shall route DNS queries exclusively through the VPN at all times.
#### 5.7.7.2 Applicability
Products within the following use cases shall fulfill **at least one** of the above sub-requirements, REQ-CON-07 (MI-DNSL-2)-1, **or** REQ-CON-07 (MI-DNSL-2)-2.
* UC-1: not required
* UC-2: required
* UC-3: required
@@ -924,7 +927,7 @@ Unless DNS traffic is routed exclusively through the VPN at all times, the VPN c
#### 5.7.8.1 Requirement
By default, the VPN client shall route all DNS queries using well-known ports through the VPN connection.
The VPN client shall route all requests that use well-known DNS query ports through the VPN connection.