The --dns option routes all DNS requests over the VPN connection. This means that you can't connect to a work VPN and (e.g.) browser porn on your lunch break. A cool option would be to route specific DNS requests over the connection (e.g. just requests for an internal DNS domain).