Interruttore di emergenza VPN — blocca le perdite se il tunnel si interrompe
Un kill switch ferma tutto il traffico nel momento in cui la tua VPN si disconnette, quindi il tuo IP reale non perde mai. Configurazioni da copiare e incollare per Linux, macOS e Windows — oltre a un blocco delle perdite IPv6.
Cosa fa un kill switch
A kill switch blocks your device's internet the instant the VPN tunnel drops, so nothing ever exits over your real connection. Without one, a brief reconnect can leak your true IP to whatever you were doing. The rules below allow traffic only through the s4m WireGuard interface (plus the handshake to our server), and drop everything else.
Replace <WG_ENDPOINT_IP> with your s4m server IP and the interface name (wg0 / utun3 / s4m) with yours from the config you downloaded.
Linux (nftables)
Persistente, moderno e l'opzione più pulita sulle attuali distribuzioni.
#!/usr/sbin/nft -f
# s4m kill-switch: drop all output unless it goes through the s4m tunnel.
flush ruleset
table inet s4m_ks {
chain out {
type filter hook output priority 0; policy drop;
oifname "lo" accept
oifname "wg0" accept # s4m WireGuard interface
ip daddr <WG_ENDPOINT_IP> udp dport 51820 accept # handshake to s4m
ct state established,related accept
meta nfproto ipv6 drop # kill IPv6 leaks (exit is IPv4)
}
}
# apply: sudo nft -f s4m-killswitch.nft revert: sudo nft flush rulesetmacOS (pf)
Utilizza il filtro pacchetti integrato — nessun software extra.
# /etc/pf.s4m.conf — load: sudo pfctl -f /etc/pf.s4m.conf -e set block-policy drop block out all pass out on lo0 all pass out on utun3 all # your s4m WireGuard interface pass out proto udp to <WG_ENDPOINT_IP> port 51820 # handshake block out inet6 all # kill IPv6 leaks # disable: sudo pfctl -d
Windows (PowerShell, esegui come Admin)
Regole del firewall di Windows Defender; limitate all'adattatore s4m.
# Block all outbound, then allow only the s4m WireGuard adapter + handshake. New-NetFirewallRule -DisplayName "s4m-ks-block" -Direction Outbound -Action Block -Enabled True New-NetFirewallRule -DisplayName "s4m-ks-allow-wg" -Direction Outbound -Action Allow -InterfaceAlias "s4m" -Enabled True New-NetFirewallRule -DisplayName "s4m-ks-handshake" -Direction Outbound -Action Allow -Protocol UDP -RemoteAddress <WG_ENDPOINT_IP> -RemotePort 51820 -Enabled True # Stop IPv6 leaks: Disable-NetAdapterBinding -Name "*" -ComponentID ms_tcpip6 # Remove later: Get-NetFirewallRule -DisplayName "s4m-ks-*" | Remove-NetFirewallRule
Perché bloccare l'IPv6
La nostra uscita è IPv4, quindi qualsiasi richiesta IPv6 bypasserebbe il tunnel e rivelerebbe il tuo vero indirizzo IPv6 — una fuga classica. Ogni configurazione sopra blocca completamente l'IPv6. Puoi confermare di essere pulito nel nostro test IP e di fuga.
Domande, risposte
Ho davvero bisogno di un kill switch?
Se fai affidamento sulla VPN per la privacy, sì — senza di essa, un calo momentaneo espone silenziosamente il tuo vero IP. Le regole qui falliscono in chiusura: nessun tunnel, nessun traffico.
Sopravvivrà a un riavvio?
I file nftables e pf possono essere caricati all'avvio (systemd o un demone di avvio); le regole di Windows persistono fino a quando non le rimuovi. Vedi le righe di applicazione/ripristino di ciascun frammento.
Ottieni un tunnel da proteggere
WireGuard, senza log per design, registrazione anonima.
Le persone hanno trovato questa pagina cercando
- interruttore di emergenza VPN
- Impostazioni proxy socks5
- proxy socks5 abbonamento
- scraping di Amazon
- come controllare openvpn
- openvpn passo dopo passo
- fingerprinting del browser
- come controllare se un proxy è anonimo
- vpn kill switch confronto
- lista di proxy gratuiti spiegato
- configurazione del proxy per android
- è proxy http sicuro
Frasi di ricerca reali a cui questa pagina risponde — i collegamenti aprono la pagina che le tratta in dettaglio.