iPhone 11 stops working if DNS enabled


I’m using the latest client on iPhone 11. If a network added without any DNS configuration - everything is routed fine.

If I set “Custom DNS” - iPhone’s VPN it stops working. On the local box I can only see ARP traffic:

22:47:03.904745 ARP, Request who-has tell, length 28
22:47:03.904767 ARP, Reply is-at 5a:90:83:7e:80:b6, length 28

where .51 is local box and .38 is zt IP of iPhone.

If I set “Network DNS” - nothing works either and network config on iPhone doesn’t show any DNS servers.

Any ideas how to troubleshoot this? DNS server is on my local network. The EC2 instance (which IPs is used as a default route) can resolve names though local box without issues.

Any ideas where to dig (no pun intended)?

