Beantwortet: Keine Verbindung nach UFW KillSwitch

minati88

Freshly Joined Member
Hallo zusammen,

Um meinen VMWare abzusichern und nur noch Traffic über tun0 zu erlauben hab ich ein Skript erstellt wie hier in der Anleitung Sektion angegeben erstellt
https://board.perfect-privacy.com/threads/killswitch-100-secure-für-alle-linux-systeme.4216/

Ich benutze Debian 10

Code:
#!/bin/bash

sudo ufw reset
sudo ufw default deny incoming
sudo ufw default deny outgoing
sudo ufw allow out on tun0 from any to any
sudo ufw enable


VPN verbindet sich aber nachdem überhaupt nicht mehr da folgende Errors kommen,.
Mon Aug 24 16:49:02 2020 us=160320 write UDP: Operation not permitted (code=1)
Mon Aug 24 16:49:03 2020 us=187801 write UDP: Operation not permitted (code=1)
Mon Aug 24 16:49:04 2020 us=19346 write UDP: Operation not permitted (code=1)
Mon Aug 24 16:49:05 2020 us=202045 write UDP: Operation not permitted (code=1)
Mon Aug 24 16:49:07 2020 us=161194 write UDP: Operation not permitted (code=1)
Mon Aug 24 16:49:08 2020 us=177521 write UDP: Operation not permitted (code=1)
Mon Aug 24 16:49:10 2020 us=193900 write UDP: Operation not permitted (code=1)




2. Versuch hab ich mit folgenden Skrip versucht, hier kommen zwar keine Errors und der VPN verbindet sich, aber bekomme auch hier keine Internet verbindung mehr...

Code:
#!/bin/bash

sudo ufw reset
sudo ufw default deny incoming
sudo ufw default deny outgoing

sudo ufw allow out on INTERFACE to 85.17.28.145
sudo ufw allow out on INTERFACE to 95.211.95.232
sudo ufw allow out on INTERFACE to 95.211.95.244
sudo ufw allow out on INTERFACE to 37.48.94.1
sudo ufw allow out on INTERFACE to 85.17.64.131
sudo ufw allow out on INTERFACE to 82.199.134.162
sudo ufw allow out on INTERFACE to 80.255.7.66
sudo ufw allow out on INTERFACE to 152.89.160.98
sudo ufw allow out on INTERFACE to 80.255.7.98
sudo ufw allow out on INTERFACE to 185.57.82.25
sudo ufw allow out on INTERFACE to 41.215.242.154
sudo ufw allow out on INTERFACE to 149.202.77.77
sudo ufw allow out on INTERFACE to 104.237.193.26
sudo ufw allow out on INTERFACE to 185.152.32.66
sudo ufw allow out on INTERFACE to 138.128.136.164
sudo ufw allow out on INTERFACE to 217.114.218.18
sudo ufw allow out on INTERFACE to 178.162.194.30
sudo ufw allow out on INTERFACE to 37.58.58.239
sudo ufw allow out on INTERFACE to 80.255.7.114
sudo ufw allow out on INTERFACE to 209.58.188.129
sudo ufw allow out on INTERFACE to 185.65.205.18
sudo ufw allow out on INTERFACE to 82.199.130.34
sudo ufw allow out on INTERFACE to 5.187.21.98
sudo ufw allow out on INTERFACE to 162.245.206.242
sudo ufw allow out on INTERFACE to 185.183.106.146
sudo ufw allow out on INTERFACE to 194.68.170.51
sudo ufw allow out on INTERFACE to 217.138.196.98
sudo ufw allow out on INTERFACE to 168.1.112.72
sudo ufw allow out on INTERFACE to 38.132.118.66
sudo ufw allow out on INTERFACE to 192.145.127.210
sudo ufw allow out on INTERFACE to 167.114.209.103
sudo ufw allow out on INTERFACE to 192.162.100.240
sudo ufw allow out on INTERFACE to 192.162.100.241
sudo ufw allow out on INTERFACE to 96.9.246.194
sudo ufw allow out on INTERFACE to 81.95.5.34
sudo ufw allow out on INTERFACE to 80.255.10.194
sudo ufw allow out on INTERFACE to 91.205.187.186
sudo ufw allow out on INTERFACE to 5.135.143.84
sudo ufw allow out on INTERFACE to 195.138.249.2
sudo ufw allow out on INTERFACE to 82.221.105.61
sudo ufw allow out on INTERFACE to 46.183.221.194
sudo ufw allow out on INTERFACE to 31.204.150.106
sudo ufw allow out on INTERFACE to 31.204.150.138
sudo ufw allow out on INTERFACE to 31.204.152.102
sudo ufw allow out on INTERFACE to 31.204.152.189
sudo ufw allow out on INTERFACE to 31.204.153.106
sudo ufw allow out on INTERFACE to 209.58.162.197
sudo ufw allow out on INTERFACE to 103.254.153.202
sudo ufw allow out on INTERFACE to 94.242.243.162
sudo ufw allow out on INTERFACE to 94.242.243.66
sudo ufw allow out on INTERFACE to 185.41.240.18
sudo ufw allow out on INTERFACE to 185.217.1.2
sudo ufw allow out on INTERFACE to 37.187.163.66
sudo ufw allow out on INTERFACE to 185.18.205.122
sudo ufw allow out on INTERFACE to 31.204.145.166
sudo ufw allow out on INTERFACE to 152.89.162.226
sudo ufw allow out on INTERFACE to 37.120.213.194
sudo ufw allow out on INTERFACE to 37.120.213.210

sudo ufw allow out on tun0 from any to any
sudo ufw enable

INTERFACE hab ich ersetzt mit ens33, denke das war richtig?

ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether scope global dynamic noprefixroute ens33 *ZENSIERTER TEIL*


Ich bin jetzt schon 2 tage dran und weiss nicht mehr was ich noch alles versuchen sollte :)
 
Mal hier ein Statusupdate, hatte davor DNSCrypt-Proxy installiert gehabt , habe Debian neu installiert und es funktioniert nun mit folgender Bash:


Code:
#!/bin/bash

sudo ufw reset
sudo ufw default deny incoming
sudo ufw default deny outgoing

sudo ufw allow out on INTERFACE to 85.17.28.145
sudo ufw allow out on INTERFACE to 95.211.95.232
sudo ufw allow out on INTERFACE to 95.211.95.244
sudo ufw allow out on INTERFACE to 37.48.94.1
sudo ufw allow out on INTERFACE to 85.17.64.131
sudo ufw allow out on INTERFACE to 82.199.134.162
sudo ufw allow out on INTERFACE to 80.255.7.66
sudo ufw allow out on INTERFACE to 152.89.160.98
sudo ufw allow out on INTERFACE to 80.255.7.98
sudo ufw allow out on INTERFACE to 185.57.82.25
sudo ufw allow out on INTERFACE to 41.215.242.154
sudo ufw allow out on INTERFACE to 149.202.77.77
sudo ufw allow out on INTERFACE to 104.237.193.26
sudo ufw allow out on INTERFACE to 185.152.32.66
sudo ufw allow out on INTERFACE to 138.128.136.164
sudo ufw allow out on INTERFACE to 217.114.218.18
sudo ufw allow out on INTERFACE to 178.162.194.30
sudo ufw allow out on INTERFACE to 37.58.58.239
sudo ufw allow out on INTERFACE to 80.255.7.114
sudo ufw allow out on INTERFACE to 209.58.188.129
sudo ufw allow out on INTERFACE to 185.65.205.18
sudo ufw allow out on INTERFACE to 82.199.130.34
sudo ufw allow out on INTERFACE to 5.187.21.98
sudo ufw allow out on INTERFACE to 162.245.206.242
sudo ufw allow out on INTERFACE to 185.183.106.146
sudo ufw allow out on INTERFACE to 194.68.170.51
sudo ufw allow out on INTERFACE to 217.138.196.98
sudo ufw allow out on INTERFACE to 168.1.112.72
sudo ufw allow out on INTERFACE to 38.132.118.66
sudo ufw allow out on INTERFACE to 192.145.127.210
sudo ufw allow out on INTERFACE to 167.114.209.103
sudo ufw allow out on INTERFACE to 192.162.100.240
sudo ufw allow out on INTERFACE to 192.162.100.241
sudo ufw allow out on INTERFACE to 96.9.246.194
sudo ufw allow out on INTERFACE to 81.95.5.34
sudo ufw allow out on INTERFACE to 80.255.10.194
sudo ufw allow out on INTERFACE to 91.205.187.186
sudo ufw allow out on INTERFACE to 5.135.143.84
sudo ufw allow out on INTERFACE to 195.138.249.2
sudo ufw allow out on INTERFACE to 82.221.105.61
sudo ufw allow out on INTERFACE to 46.183.221.194
sudo ufw allow out on INTERFACE to 31.204.150.106
sudo ufw allow out on INTERFACE to 31.204.150.138
sudo ufw allow out on INTERFACE to 31.204.152.102
sudo ufw allow out on INTERFACE to 31.204.152.189
sudo ufw allow out on INTERFACE to 31.204.153.106
sudo ufw allow out on INTERFACE to 209.58.162.197
sudo ufw allow out on INTERFACE to 103.254.153.202
sudo ufw allow out on INTERFACE to 94.242.243.162
sudo ufw allow out on INTERFACE to 94.242.243.66
sudo ufw allow out on INTERFACE to 185.41.240.18
sudo ufw allow out on INTERFACE to 185.217.1.2
sudo ufw allow out on INTERFACE to 37.187.163.66
sudo ufw allow out on INTERFACE to 185.18.205.122
sudo ufw allow out on INTERFACE to 31.204.145.166
sudo ufw allow out on INTERFACE to 152.89.162.226
sudo ufw allow out on INTERFACE to 37.120.213.194
sudo ufw allow out on INTERFACE to 37.120.213.210

sudo ufw allow out on tun0 from any to any
sudo ufw enable

Übrigens wer Kaskadierung benutzt sollte noch

Code:
sudo ufw allow out on tun1 from any to any
 
Back
Top