VMs and Connections

Hello everyone. I’m am completely new to qubes and I’m trying to play around in it to create safeguards for myself as I have had my identity taken but I’m come to a roadblock. Any who I’m trying to route my NetVM to the FirewallVM. From there, route the traffic to the VPN VM then setup my VPN VM to route all traffic to the VPN tunnel and restrict all non-VPN connections with iptables rules. Someone please help as the github that shows this is gone.

Hi @SafteyFirst, welcome to the Community! I’m glad you are intereseted in Qubes OS.

What do you mean here? Any links?

Do you get any errors? Do you have no connection, or leaks? I’m no expert here, but maybe one of these posts could be relevant:

and more.

Thanks so much. This is a great start. I’m also new on the forum so forgive me if I am a little slow.

off-topic

Ẁhy apologize? Slow don’t mean bad… You don’t have to be quick and fast/smart. Don’t apologize for being slow, i’m also slow. :slight_smile:
Time do not exist, it’s a human construct and an invention… Be slow and analyze. You might get it eventually, better then not trying at all. I know i know nothing. Ask whatever you want and try to get it. It’s not easy for anyone i bet. Maybe a few…
What do we all really know… It’s exploration. I have learnt a bit with qubes, not that much yet, but more then when i first used it. Still don’t understand it, but a bit better. :slight_smile: I just like it. Peace

edit: haha i gotta add this when i wrote “i just like it.” I just like how it feeels…
https://www.youtube.com/watch?v=TAD7Gz2f3Hs

I think I’m trying to do the same thing did you ever find a solution to this?

No actually. Never got it figured out unfortunately.

As explained in some links shared above, the easiest way is:

  • to make a qube dedicated to VPN and check it’s providing network
  • enable network-manager service in it
  • use the firewall tab to only allow reaching the VPN server
  • assign this VPN qube to all the other qubes

that’s 100% GUI configuration and the only traffic allowed from the qubes and the vpn qube is reaching the vpn server on a given port.

Hello friends. For Qubes 4.1, either of the two settings, ProxyVM as a VPN gateway using NetworkManager or ProxyVM as a VPN gateway using iptables and CLI scripts, work.

@solene’s suggestion also works. And in 4.2, solene’s instructions are the ONLY ones that work pending updated of the instructions. As @solene explained, you need to setup ProxyVM as a VPN gateway using NetworkManager, and use the ProxyVM firewall to limit Internet access to the VPN IP address. Here are a couple of screenshots. The IP address needs to be your VPNs, not what’s in the screenshot.


Thank you all. Y’all are awesome!