Just for posterity:
One reason the Mullvad-generated .conf
file would stop working on 4.2 is that the PostUp
and PreDown
fields include non-custom iptables
commands if “Enable kill switch (Linux only)” is enabled during generation (https://mullvad.net/account/wireguard-config/). The user might not know what these iptables
commands are for if they’re just following instructions- that they’re optional, that they’re for the killswitch, and that they can instead be implemented through other means with nftables.