This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (e).
As confidentiality protection is a fundamental aspect of any VPN’s functionality regardless of use case, the requirements in this clause are extensive. Some of these requirements fall into subcategories; the existence of subcategories is purely informative—applicability is detailed along with each requirement as well as being mapped out at the end of 5.7 just as any other clause.
From the moment the user activates the VPN connection until the user knowingly deactivates the VPN connection, no network traffic intended for the VPN connection should exit the endpoint via anything other than the VPN connection, regardless of whether the VPN connection is functioning.
Out of scope for routing-related requirements are other software on the user’s endpoint with elevated privileges, users with administrator privileges, as well as the operating system itself that could change relevant network configuration (network interfaces, routes, DNS) or circumvent the VPN tunnel due to elevated privileges.
As confidentiality protection is a fundamental aspect of any VPN’s functionality regardless of use case, the requirements in this clause are extensive.
Special attention to DNS queries is required because DNS requests are usually transmitted in plaintext. These requests could be eavesdropped on by an attacker on the wire or the DNS server itself, which could disclose the domains to which the user is trying to connect.
DNS leaks occur if the client does not or only partially tunnels cleartext DNS traffic through the VPN connection. This could either happen due to misconfiguration, system overwrites, or by design—for example in case only partial traffic is tunnelled, so-called split tunnelling.
Further, the user might want to set special DNS configuration, either configured by the enterprise or custom configured in a consumer context. The VPN provider then must honour this DNS configuration.
A DNS server is authorized if:
For the purpose of the present clause's requirements, a DNS server is authorized if:
1. the DNS server is configured by administrating user, or
2. the DNS server is provided by the VPN manufacturer.
> NOTE: networks and devices are evolving away from plaintext DNS to “secure DNS”, with platforms, browsers and/or applications increasingly making DNS queries via TLS or HTTPS requests. Unlike cleartext DNS that uses port 53, use of secure DNS can be harder to identify, inhibiting the enforcement of specific policies to use a specifically configured DNS server.
The following requirements apply to DNS traffic intended for the VPN connection. DNS queries for connection establishment, maintenance or restoration of the VPN tunnel are excluded.
> NOTE 1: Networks and devices are evolving away from plaintext DNS to “secure DNS”, with platforms, browsers, and applications increasingly making DNS queries via TLS or HTTPS requests. Unlike cleartext DNS that uses port 53, use of secure DNS can be harder to identify, inhibiting the enforcement of specific policies to use a specifically configured DNS server.
> NOTE: The network configuration of a system is frequently changed by multiple different pieces of software, many of which the VPN client has no control over or insight into.
> NOTE 2: The network configuration of a system is frequently changed by multiple different pieces of software, many of which the VPN client has no control over or insight into.
### 5.7.2 REQ-CON-02 (MI-ROUT-1) VPN routing stays in effect until VPN connection deactivated