Configure & Lock Down
Configure an OpenVPN connection on Linux and lock the firewall so nothing leaks outside the VPN tunnel.
A Linux machine or VM running a systemd-free distribution. This walkthrough assumes systemd is not managing DNS, since systemd-resolved will overwrite the DNS configuration on restart and break this setup. Basic terminal familiarity is assumed.
STEP-BY-STEP LAB PROCEDURE
The source walkthrough uses RiseUp VPN as its free example. Work through these in order.
STEP 1 Install dependencies
Install the OpenVPN package and its dependency iproute2 using your distro's package manager, along with the UFW firewall package.
STEP 2 Get a config file
Obtain a .conf configuration file from your VPN provider and place it in /etc/openvpn. For RiseUp, run its generate.sh script, then edit the resulting config file to remove any duplicate "remote" lines.
STEP 3 Allow the VPN server through the firewall
Open the config file and find the "remote" line, which lists the VPN server's IP address and port. Run:
sudo ufw allow out to [SERVER_IP] port [PORT]
STEP 4 Name the tunnel interface
In the config file, change the "dev tun" line to something identifiable, such as "tun_myvpn," so you can reference it in firewall rules.
STEP 5 Allow traffic on the tunnel interface
sudo ufw allow in on tun_myvpn sudo ufw allow out on tun_myvpn
STEP 6 Allow your local router
Find your local router's IP address with sudo ifconfig, and allow it explicitly:
sudo ufw allow out to [LOCAL_ROUTER_IP]
STEP 7 Switch to the VPN's DNS servers
Replace your ISP's DNS servers with the VPN's own DNS servers. Run sudo resolvconf -l to see current settings, then edit /etc/resolv.conf to insert the VPN's nameserver (the RiseUp example given is nameserver 172.27.0.1).
STEP 8 Lock the DNS file
Make that DNS configuration file immutable so nothing silently overwrites it later, either with chattr +i on the file, or by adding the line nohook resolv.conf wpa_supplicant to /etc/dhcpcd.conf.
STEP 9 Allow each DNS server individually
sudo ufw allow out to [DNS_SERVER_IP]
STEP 10 Deny everything else by default
sudo ufw default deny incoming sudo ufw default deny outgoing
STEP 11 Reapply the firewall on every boot
Add startup code to /etc/rc.d/rc.local so this firewall configuration is automatically reapplied every time the machine boots.
STEP 12 Start the VPN connection
cd /etc/openvpn; sudo openvpn [your_config_file.conf]&
BROWSER LEAK FIX (DO THIS IN THE SAME SESSION)
WebRTC, a browser technology, can leak your real IP address even while a VPN is active. In Firefox, disable it by going to about:config and setting media.peerconnection.enabled to false. In Chrome-based browsers, install a WebRTC-blocking extension such as WebRTC Control. Pale Moon users don't need to do anything, since it doesn't implement WebRTC the same way.
IPv6 LEAK FIX, IF NEEDED
If testing (see Part 5: Test, Glossary & Resources) reveals an IPv6 leak, disable IPv6 system-wide: blacklist the IPv6 kernel module from the terminal, then edit /etc/sysctl.conf to add disable rules for all IPv6 interfaces, and apply the change with sudo sysctl -p.
MAINTENANCE NOTE: FREE RISEUP CERTIFICATES
RiseUp's VPN certificates expire roughly monthly. When the connection stops working: rename your current working config file, run generate.sh again to get a fresh one, copy just the new certificate block (the content between the <ca> tags) out of the new file, paste it into the renamed old file in place of the expired certificate, then delete the newly generated file and rename your edited file back to its original name.