VPN杀开关 - 如果隧道断开则阻止泄漏
杀死开关在您的 VPN 断开连接的瞬间停止所有流量,因此您的真实 IP 永远不会泄露。复制粘贴适用于 Linux、macOS 和 Windows 的配置——加上 IPv6 泄漏阻止。
杀死开关的作用
A kill switch blocks your device's internet the instant the VPN tunnel drops, so nothing ever exits over your real connection. Without one, a brief reconnect can leak your true IP to whatever you were doing. The rules below allow traffic only through the s4m WireGuard interface (plus the handshake to our server), and drop everything else.
将<WG_ENDPOINT_IP>替换为您的s4m服务器IP和接口名称(wg0 / utun3 / s4m),使用您从下载的配置中获得的名称。
Linux (nftables)
持久、现代,并且是当前发行版中最干净的选项。
#!/usr/sbin/nft -f
# s4m kill-switch: drop all output unless it goes through the s4m tunnel.
flush ruleset
table inet s4m_ks {
chain out {
type filter hook output priority 0; policy drop;
oifname "lo" accept
oifname "wg0" accept # s4m WireGuard interface
ip daddr <WG_ENDPOINT_IP> udp dport 51820 accept # handshake to s4m
ct state established,related accept
meta nfproto ipv6 drop # kill IPv6 leaks (exit is IPv4)
}
}
# apply: sudo nft -f s4m-killswitch.nft revert: sudo nft flush rulesetmacOS (pf)
使用内置的数据包过滤器——无需额外软件。
# /etc/pf.s4m.conf — load: sudo pfctl -f /etc/pf.s4m.conf -e set block-policy drop block out all pass out on lo0 all pass out on utun3 all # your s4m WireGuard interface pass out proto udp to <WG_ENDPOINT_IP> port 51820 # handshake block out inet6 all # kill IPv6 leaks # disable: sudo pfctl -d
Windows(PowerShell,以管理员身份运行)
Windows Defender 防火墙规则;作用于 s4m 适配器。
# Block all outbound, then allow only the s4m WireGuard adapter + handshake. New-NetFirewallRule -DisplayName "s4m-ks-block" -Direction Outbound -Action Block -Enabled True New-NetFirewallRule -DisplayName "s4m-ks-allow-wg" -Direction Outbound -Action Allow -InterfaceAlias "s4m" -Enabled True New-NetFirewallRule -DisplayName "s4m-ks-handshake" -Direction Outbound -Action Allow -Protocol UDP -RemoteAddress <WG_ENDPOINT_IP> -RemotePort 51820 -Enabled True # Stop IPv6 leaks: Disable-NetAdapterBinding -Name "*" -ComponentID ms_tcpip6 # Remove later: Get-NetFirewallRule -DisplayName "s4m-ks-*" | Remove-NetFirewallRule
为什么要阻止IPv6
我们的出口是IPv4,因此任何IPv6请求都会绕过隧道并暴露您的真实IPv6地址——这是一种经典的泄漏。上述每个配置都完全阻止IPv6。您可以在我们的IP和泄漏测试上确认您是干净的。
问题,已解答
我真的需要一个杀开关吗?
如果您依赖VPN来保护隐私,是的——没有VPN时,瞬间掉线会悄悄暴露您的真实IP。这里的规则是失败关闭:没有隧道,就没有流量。
这会在重启后存活吗?
nftables 和 pf 文件可以在启动时加载(systemd 或启动守护进程);Windows 规则在您删除它们之前会持续存在。请参见每个代码片段的应用/还原行。
人们通过搜索找到此页面
- VPN杀开关 - 如果隧道断开则阻止泄漏
- 什么是 VPN杀开关 - 如果隧道断开则阻止泄漏
- VPN杀开关 - 如果隧道断开则阻止泄漏设置
- 抓取亚马逊:代理、头部和速率限制
- VPN杀开关 - 如果隧道断开则阻止泄漏 的工作原理
- 什么是 wireguard
- 浏览器指纹识别:Canvas、WebGL 和字体解释
- 如何检查代理是否匿名
- openvpn
- wireguard
- 用于抓取的代理
- 免费代理列表 解释
此页面回答的真实搜索短语 — 链接的短语打开详细覆盖它们的页面。