Guía · 1 min de lectura

Interruptor de apagado de VPN — bloquea fugas si el túnel se cae

Un interruptor de corte detiene todo el tráfico en el momento en que tu VPN se desconecta, por lo que tu IP real nunca se filtra. Configuraciones para copiar y pegar para Linux, macOS y Windows, además de un bloqueo de fuga de IPv6.

Lo que hace un interruptor de corte

A kill switch blocks your device's internet the instant the VPN tunnel drops, so nothing ever exits over your real connection. Without one, a brief reconnect can leak your true IP to whatever you were doing. The rules below allow traffic only through the s4m WireGuard interface (plus the handshake to our server), and drop everything else.

Replace <WG_ENDPOINT_IP> with your s4m server IP and the interface name (wg0 / utun3 / s4m) with yours from the config you downloaded.

Linux (nftables)

Persistente, moderno y la opción más limpia en las distribuciones actuales.

bash
#!/usr/sbin/nft -f
# s4m kill-switch: drop all output unless it goes through the s4m tunnel.
flush ruleset
table inet s4m_ks {
  chain out {
    type filter hook output priority 0; policy drop;
    oifname "lo" accept
    oifname "wg0" accept                         # s4m WireGuard interface
    ip daddr <WG_ENDPOINT_IP> udp dport 51820 accept  # handshake to s4m
    ct state established,related accept
    meta nfproto ipv6 drop                        # kill IPv6 leaks (exit is IPv4)
  }
}
# apply:  sudo nft -f s4m-killswitch.nft     revert: sudo nft flush ruleset

macOS (pf)

Utiliza el filtro de paquetes integrado — sin software adicional.

bash
# /etc/pf.s4m.conf   —  load:  sudo pfctl -f /etc/pf.s4m.conf -e
set block-policy drop
block out all
pass out on lo0 all
pass out on utun3 all                      # your s4m WireGuard interface
pass out proto udp to <WG_ENDPOINT_IP> port 51820   # handshake
block out inet6 all                        # kill IPv6 leaks
# disable:  sudo pfctl -d

Windows (PowerShell, ejecutar como Administrador)

Reglas del firewall de Windows Defender; limitadas al adaptador s4m.

powershell
# Block all outbound, then allow only the s4m WireGuard adapter + handshake.
New-NetFirewallRule -DisplayName "s4m-ks-block" -Direction Outbound -Action Block -Enabled True
New-NetFirewallRule -DisplayName "s4m-ks-allow-wg" -Direction Outbound -Action Allow -InterfaceAlias "s4m" -Enabled True
New-NetFirewallRule -DisplayName "s4m-ks-handshake" -Direction Outbound -Action Allow -Protocol UDP -RemoteAddress <WG_ENDPOINT_IP> -RemotePort 51820 -Enabled True
# Stop IPv6 leaks:
Disable-NetAdapterBinding -Name "*" -ComponentID ms_tcpip6
# Remove later:  Get-NetFirewallRule -DisplayName "s4m-ks-*" | Remove-NetFirewallRule

¿Por qué bloquear IPv6?

Nuestra salida es IPv4, por lo que cualquier solicitud IPv6 eludiría el túnel y revelaría tu verdadera dirección IPv6 — una fuga clásica. Cada configuración anterior bloquea IPv6 por completo. Puedes confirmar que estás limpio en nuestra prueba de IP y fugas.

Share this page
FAQ

Preguntas, respondidas

¿Realmente necesito un interruptor de corte?

Si dependes del VPN para privacidad, sí — sin uno, una caída momentánea expone silenciosamente tu IP real. Las reglas aquí fallan cerradas: sin túnel, sin tráfico.

¿Sobrevivirá esto a un reinicio?

Los archivos nftables y pf pueden cargarse al inicio (systemd o un demonio de lanzamiento); las reglas de Windows persisten hasta que las eliminas. Consulta las líneas de aplicar/revertir de cada fragmento.

Consigue un túnel que vale la pena proteger

WireGuard, sin registros por diseño, registro anónimo.

Las personas encontraron esta página buscando

Frases de búsqueda reales que esta página responde — los enlaces abren la página que las cubre en profundidad.