Configure & Lock Down

READ TIME 10 MIN
OBJECTIVE

Configure an OpenVPN connection on Linux and lock the firewall so nothing leaks outside the VPN tunnel.

PREREQUISITES

A Linux machine or VM running a systemd-free distribution. This walkthrough assumes systemd is not managing DNS, since systemd-resolved will overwrite the DNS configuration on restart and break this setup. Basic terminal familiarity is assumed.

STEP-BY-STEP LAB PROCEDURE

The source walkthrough uses RiseUp VPN as its free example. Work through these in order.

STEP 1 Install dependencies

Install the OpenVPN package and its dependency iproute2 using your distro's package manager, along with the UFW firewall package.

STEP 2 Get a config file

Obtain a .conf configuration file from your VPN provider and place it in /etc/openvpn. For RiseUp, run its generate.sh script, then edit the resulting config file to remove any duplicate "remote" lines.

STEP 3 Allow the VPN server through the firewall

Open the config file and find the "remote" line, which lists the VPN server's IP address and port. Run:

sudo ufw allow out to [SERVER_IP] port [PORT]
STEP 4 Name the tunnel interface

In the config file, change the "dev tun" line to something identifiable, such as "tun_myvpn," so you can reference it in firewall rules.

STEP 5 Allow traffic on the tunnel interface
sudo ufw allow in on tun_myvpn
sudo ufw allow out on tun_myvpn
STEP 6 Allow your local router

Find your local router's IP address with sudo ifconfig, and allow it explicitly:

sudo ufw allow out to [LOCAL_ROUTER_IP]
STEP 7 Switch to the VPN's DNS servers

Replace your ISP's DNS servers with the VPN's own DNS servers. Run sudo resolvconf -l to see current settings, then edit /etc/resolv.conf to insert the VPN's nameserver (the RiseUp example given is nameserver 172.27.0.1).

STEP 8 Lock the DNS file

Make that DNS configuration file immutable so nothing silently overwrites it later, either with chattr +i on the file, or by adding the line nohook resolv.conf wpa_supplicant to /etc/dhcpcd.conf.

STEP 9 Allow each DNS server individually
sudo ufw allow out to [DNS_SERVER_IP]
STEP 10 Deny everything else by default
sudo ufw default deny incoming
sudo ufw default deny outgoing
STEP 11 Reapply the firewall on every boot

Add startup code to /etc/rc.d/rc.local so this firewall configuration is automatically reapplied every time the machine boots.

STEP 12 Start the VPN connection
cd /etc/openvpn; sudo openvpn [your_config_file.conf]&

BROWSER LEAK FIX (DO THIS IN THE SAME SESSION)

WebRTC, a browser technology, can leak your real IP address even while a VPN is active. In Firefox, disable it by going to about:config and setting media.peerconnection.enabled to false. In Chrome-based browsers, install a WebRTC-blocking extension such as WebRTC Control. Pale Moon users don't need to do anything, since it doesn't implement WebRTC the same way.

IPv6 LEAK FIX, IF NEEDED

If testing (see Part 5: Test, Glossary & Resources) reveals an IPv6 leak, disable IPv6 system-wide: blacklist the IPv6 kernel module from the terminal, then edit /etc/sysctl.conf to add disable rules for all IPv6 interfaces, and apply the change with sudo sysctl -p.

MAINTENANCE NOTE: FREE RISEUP CERTIFICATES

RiseUp's VPN certificates expire roughly monthly. When the connection stops working: rename your current working config file, run generate.sh again to get a fresh one, copy just the new certificate block (the content between the <ca> tags) out of the new file, paste it into the renamed old file in place of the expired certificate, then delete the newly generated file and rename your edited file back to its original name.