指南 · 1 分钟阅读

VPN杀开关 - 如果隧道断开则阻止泄漏

杀死开关在您的 VPN 断开连接的瞬间停止所有流量,因此您的真实 IP 永远不会泄露。复制粘贴适用于 Linux、macOS 和 Windows 的配置——加上 IPv6 泄漏阻止。

杀死开关的作用

A kill switch blocks your device's internet the instant the VPN tunnel drops, so nothing ever exits over your real connection. Without one, a brief reconnect can leak your true IP to whatever you were doing. The rules below allow traffic only through the s4m WireGuard interface (plus the handshake to our server), and drop everything else.

将<WG_ENDPOINT_IP>替换为您的s4m服务器IP和接口名称(wg0 / utun3 / s4m),使用您从下载的配置中获得的名称。

Linux (nftables)

持久、现代,并且是当前发行版中最干净的选项。

bash
#!/usr/sbin/nft -f
# s4m kill-switch: drop all output unless it goes through the s4m tunnel.
flush ruleset
table inet s4m_ks {
  chain out {
    type filter hook output priority 0; policy drop;
    oifname "lo" accept
    oifname "wg0" accept                         # s4m WireGuard interface
    ip daddr <WG_ENDPOINT_IP> udp dport 51820 accept  # handshake to s4m
    ct state established,related accept
    meta nfproto ipv6 drop                        # kill IPv6 leaks (exit is IPv4)
  }
}
# apply:  sudo nft -f s4m-killswitch.nft     revert: sudo nft flush ruleset

macOS (pf)

使用内置的数据包过滤器——无需额外软件。

bash
# /etc/pf.s4m.conf   —  load:  sudo pfctl -f /etc/pf.s4m.conf -e
set block-policy drop
block out all
pass out on lo0 all
pass out on utun3 all                      # your s4m WireGuard interface
pass out proto udp to <WG_ENDPOINT_IP> port 51820   # handshake
block out inet6 all                        # kill IPv6 leaks
# disable:  sudo pfctl -d

Windows(PowerShell,以管理员身份运行)

Windows Defender 防火墙规则;作用于 s4m 适配器。

powershell
# Block all outbound, then allow only the s4m WireGuard adapter + handshake.
New-NetFirewallRule -DisplayName "s4m-ks-block" -Direction Outbound -Action Block -Enabled True
New-NetFirewallRule -DisplayName "s4m-ks-allow-wg" -Direction Outbound -Action Allow -InterfaceAlias "s4m" -Enabled True
New-NetFirewallRule -DisplayName "s4m-ks-handshake" -Direction Outbound -Action Allow -Protocol UDP -RemoteAddress <WG_ENDPOINT_IP> -RemotePort 51820 -Enabled True
# Stop IPv6 leaks:
Disable-NetAdapterBinding -Name "*" -ComponentID ms_tcpip6
# Remove later:  Get-NetFirewallRule -DisplayName "s4m-ks-*" | Remove-NetFirewallRule

为什么要阻止IPv6

我们的出口是IPv4,因此任何IPv6请求都会绕过隧道并暴露您的真实IPv6地址——这是一种经典的泄漏。上述每个配置都完全阻止IPv6。您可以在我们的IP和泄漏测试上确认您是干净的。

Share this page
FAQ

问题,已解答

我真的需要一个杀开关吗?

如果您依赖VPN来保护隐私,是的——没有VPN时,瞬间掉线会悄悄暴露您的真实IP。这里的规则是失败关闭:没有隧道,就没有流量。

这会在重启后存活吗?

nftables 和 pf 文件可以在启动时加载(systemd 或启动守护进程);Windows 规则在您删除它们之前会持续存在。请参见每个代码片段的应用/还原行。

获取一个值得保护的隧道

WireGuard,设计上无日志,匿名注册。

人们通过搜索找到此页面

此页面回答的真实搜索短语 — 链接的短语打开详细覆盖它们的页面。