π‘οΈ VPN gateway for your LAN with kill switch, port forwarding and auto-follow for TorGuard & Proton VPN (NAT-PMP keep-alive). Live terminal dashboard.
Shell
0
4 commits
updated Oct 6, 2026
π‘οΈ VPN gateway for your LAN with kill switch, port forwarding and auto-follow for TorGuard & Proton VPN (NAT-PMP keep-alive). Live terminal dashboard.
Turn an Ubuntu box into a VPN gateway for your LAN, with a kill switch, port forwarding and automatic provider detection.
TorGuard and Proton VPN, auto-detected. A live terminal dashboard. Zero hand-written iptables.
Features β’ How it works β’ Quick start β’ The dashboard β’ Proton VPN β’ Testing β’ Troubleshooting
You want one machine on your LAN, such as a seedbox, web server or game server, to reach the internet only through your VPN. You also want the ports your VPN provider forwards to you to land straight on that machine.
vpn-gateway.sh builds the whole setup from a single colourful terminal dashboard: routing, NAT, port forwarding and a kill switch. Then it keeps it running. Switch from TorGuard to Proton VPN and the gateway reconfigures itself. Proton hands you a random port, and the gateway keeps it open and follows it when it changes.
π‘ Kill switch, in one line: if the VPN goes down, your LAN client gets no internet at all. It never falls back to your ISP.
| Feature | What it does for you | |
|---|---|---|
| π | Auto-detect VPN | Recognises TorGuard and Proton VPN and configures the gateway for whichever one is online |
| π | Auto-follow | Switch VPN provider and the gateway rebuilds itself within seconds, even with the script closed |
| π | Kill switch | LAN clients can only reach the internet through the VPN tunnel |
| π | Port forwarding | Forwarded ports go straight to your LAN client (TCP, UDP or both) |
| π£ | Proton keep-alive | Renews Proton's NAT-PMP port lease, so your port stays the same while connected |
| π― | Port follower | Proton reconnect or new server? The new port is applied automatically |
| πͺ | On-change hook | Run your own command when the Proton port changes (e.g. update qBittorrent) |
| π₯οΈ | Live dashboard | Black-background terminal UI that refreshes every 5 seconds |
| π§ͺ | Kill switch test | Counts the packets the gateway blocks to prove the kill switch works |
| π§± | Gateway shielding | Nothing on the VPN side can open connections to the gateway itself |
| π« | Leak protection | Blocks IPv6 forwarding and ICMP redirects, two classic VPN leaks |
| π | MSS clamping | Fixes the "some websites just hang" problem over WireGuard |
| πΎ | Persistent rules | Survives reboots, and the saved copy stays in sync when the provider switches |
| π§― | Fail-closed | If anything fails, forwarding stays blocked, so nothing leaks |
| π€ | Headless mode | --apply and --detect for scripts and SSH sessions |
flowchart LR
C["π» LAN client<br/>192.168.0.186"] -->|default gateway| G["π‘οΈ VPN Gateway<br/>Ubuntu 24.04"]
G -->|WireGuard / OpenConnect| V{"π Active VPN<br/>auto-detected"}
V --> TG["TorGuard"]
V --> PR["Proton VPN"]
TG --> I(("π Internet"))
PR --> I
I -.->|forwarded port| V
V -.->|DNAT to client| G
G -.->|port| C
G -->|kill switch β| ISP["π« ISP router<br/>(blocked)"]
W["ποΈ Watcher service<br/>every 10 s"] -.->|follows provider<br/>keeps port alive| G
style G fill:#1f6feb,color:#fff,stroke:#1f6feb
style V fill:#2da44e,color:#fff,stroke:#2da44e
style ISP fill:#cf222e,color:#fff,stroke:#cf222e
style W fill:#6e40c9,color:#fff,stroke:#6e40c9
| Provider | Detection | Port forwarding | Port changes |
|---|---|---|---|
| TorGuard | Interface name, OpenConnect, WireGuard config | Static, from the TorGuard portal | Only when you change it in the portal |
| Proton VPN | Interface name, NetworkManager connection, tunnel address | Dynamic, via NAT-PMP | On reconnect or server change, followed automatically |
| Generic | Any WireGuard or tun interface | Static | Manual |
Detection is based on the interface your traffic actually leaves through. Leftover tunnels from a provider you just disconnected can't confuse it, and a switch is only made after the same VPN has been seen twice in a row.
| Requirement | Notes |
|---|---|
| π§ Ubuntu 24.04 | Desktop or Server (other Debian-based distros will probably work) |
| π Root access | Run with sudo |
| π A VPN connection | TorGuard (WireGuard / OpenConnect) and/or Proton VPN (app or WireGuard config) |
| π§ Static LAN IPs | For both the gateway and the client that receives the forwarded ports |
| π£ Proton port forwarding | Needs a paid plan, a P2P server and port forwarding / NAT-PMP enabled |
| π¦ Packages | natpmpc and iptables-persistent are installed automatically when needed |
| π curl (optional) | Shows your public IP through the tunnel in the status screen |
# 1. Download
git clone https://github.com/MorphyDK/vpn-gateway.git
cd vpn-gateway
# 2. Make it executable
chmod +x vpn-gateway.sh
# 3. Connect your VPN, then run
sudo ./vpn-gateway.sh
Follow the setup order shown on the dashboard:
βΆ Setup order: 1 Detect β 2 Settings β 3 Ports β 4 Build
On the LAN client (e.g. 192.168.0.186), set:
A live terminal UI with a black background and colour-coded status. It refreshes every 5 seconds, and menus react to a single keypress.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββ V P N G A T E W A Y v1.0 // kill switch Β· port forwarding
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
VPN β UP Proton VPN proton0 10.2.0.2
PORT 51234 NAT-PMP keep-alive Β· active Β· renewed 12 s ago
KILL SWITCH β ARMED protects LAN clients only - not this machine
CLIENT 192.168.0.186 via ens18 192.168.0.10
DETECTED proton0 β Proton VPN (carries traffic)
WATCHER β running checks every 10 s Β· screen refreshes every 5 s
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SETUP
[1] Detect VPN provider
[2] Settings
[3] Proton port & keep-alive
[4] Build / rebuild gateway
MONITOR
[5] Status & tunnel check
[6] Test kill switch
[7] View active rules
[8] View log
MAINTENANCE
[9] Save rules persistently
[R] Remove gateway rules
[Q] Quit
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
vpngw β― _
| Key | Option | Description |
|---|---|---|
| 1 | π Detect VPN provider | Scans the tunnels, identifies the provider and tests Proton's NAT-PMP |
| 2 | βοΈ Settings | LAN card, provider, interfaces, client IP, port mode and protections |
| 3 | π Ports | TorGuard: change forwarded ports. Proton: port status, client port, hook |
| 4 | ποΈ Build / rebuild | Shows a summary, then builds every rule with a live β step list |
| 5 | π Status & tunnel check | Tunnel state, public IP through the tunnel, client reachability, ports |
| 6 | π§ͺ Test kill switch | 20-second test that counts the packets the gateway blocks |
| 7 | π View active rules | Built-in pager with colours: ACCEPT green, DROP red, NAT magenta |
| 8 | π View log | The last 300 lines of the log |
| 9 | πΎ Save rules | Installs iptables-persistent and saves the rules |
| R | π§Ή Remove | Clean removal of all rules, the watcher and IP forwarding |
β BUILDING GATEWAY
[ 1/10] Enabling IP forwarding β OK
[ 2/10] Flushing old rules β OK
[ 3/10] Setting default policies β OK
[ 4/10] Shielding gateway from VPN side β OK
[ 5/10] Adding VPN forwarding rules β OK
[ 6/10] Adding NAT masquerade β OK
[ 7/10] Setting up port forwarding β OK
[ 8/10] Arming kill switch β OK
[ 9/10] IPv6 block + MSS clamp β OK
[10/10] VPN watcher service β OK
β Proton port received: 51234
There's nothing to do. Just switch:
β VPN CHANGE DETECTED
ONLINE NOW Proton VPN on proton0
CONFIGURED TorGuard Β· torguard-wg tun0
β Settings switched to Proton VPN
...
β Proton port received: 51234
You can turn this off under Settings β A (Auto-follow VPN).
Proton gives you a random port through NAT-PMP, and it disappears if nobody renews it. The watcher handles that for you:
| Situation | What the gateway does |
|---|---|
| β Connected | Renews the lease about every 40 s, so the port stays the same |
| π Disconnect | Closes the old port right away |
| π Reconnect or new server | Fetches the new port and updates the rules automatically |
| πͺ Port changed | Runs your on-change hook with the new port as $1 |
Two ways to handle the random port on your client:
8080 on your client. This is perfect for web servers.# Example hook: tell qBittorrent about the new port
#!/bin/bash
curl -s -X POST "http://192.168.0.186:8080/api/v2/app/setPreferences" \
--data-urlencode "json={\"listen_port\": $1}"
β οΈ The kill switch protects your LAN clients, not the gateway itself. A speedtest on the gateway still works with the VPN off, and that's by design: the gateway must always be able to reconnect the tunnel.
ping -c 5 1.1.1.1
curl -4 -m 5 https://ifconfig.me
β KILL SWITCH TEST - RESULT
Tunnel: DOWN | via VPN: 0 pkts | blocked: 143 pkts
KILL SWITCH WORKS: 143 packets from the LAN were blocked.
| Result | Meaning |
|---|---|
| β KILL SWITCH WORKS | The gateway blocked everything. If pages still load on the client, that's IPv6 going around the gateway |
| β οΈ NO traffic reached this gateway | The client isn't using the gateway: check its default gateway, IPv6, or whether you tested on the gateway itself |
| βΉοΈ Traffic is flowing through the VPN | The VPN was still connected. Disconnect it and test again |
Your router probably hands out IPv6 directly to the client. That traffic never touches the gateway, so it bypasses the VPN and the kill switch, even while the tunnel is up. Disable IPv6 on the client or the router:
| Client | How |
|---|---|
| πͺ Windows | Network adapter β Properties β untick Internet Protocol Version 6 |
| π§ Linux | sudo sysctl -w net.ipv6.conf.all.disable_ipv6=1 (make it permanent in /etc/sysctl.d/) |
Check it: curl -6 ifconfig.me on the client must fail.
If the client uses your router as DNS, those lookups go straight across the LAN to your ISP. Set the client's DNS to a public resolver or your VPN's DNS, so DNS also goes through the tunnel and the kill switch.
FORWARD on DROP.The script replaces all iptables rules on the gateway. It warns you first if it finds:
iptables-persistent also removes UFW, and you're asked before that happens.| Command | Description |
|---|---|
sudo ./vpn-gateway.sh | Live interactive dashboard |
sudo ./vpn-gateway.sh --apply | Rebuild from saved settings without menus |
sudo ./vpn-gateway.sh --detect | List the detected VPN tunnels |
./vpn-gateway.sh --help | Show usage |
$ sudo ./vpn-gateway.sh --detect
INTERFACE TYPE ADDRESS PROVIDER
proton0 wireguard 10.2.0.2 Proton VPN
| Path | Purpose |
|---|---|
/etc/vpn-gateway.conf | Your saved settings (root only, 600) |
/etc/sysctl.d/99-vpn-gateway.conf | IP forwarding and leak protection |
/etc/iptables/rules.v4 / rules.v6 | Persistent rules (once saved) |
/etc/systemd/system/vpn-gateway-keeper.service | The background watcher |
/usr/local/sbin/vpn-gateway.sh | Copy of the script used by the watcher (updated on every build) |
/run/vpn-gateway/keeper.state | Live watcher state: port, tunnel, last renewal |
/var/log/vpn-gateway.log | Full log of every action, switch and port change |
yes.sudo grep "Auto-follow" /var/log/vpn-gateway.logss -tlnp on Linux or netstat -an on Windows.That's an MTU problem. Make sure Settings β M (MSS clamp) is yes, then rebuild.
curl -6 ifconfig.me on the client return an IP? Then it's IPv6.Use 9 Save rules persistently. The status screen shows whether, and when, the rules were last saved.
sudo ./vpn-gateway.sh β R Remove gateway rules
This flushes all rules, resets the policies to ACCEPT, turns IP forwarding off, removes the watcher service and optionally clears the saved rules. To remove everything else:
sudo rm /etc/vpn-gateway.conf /usr/local/sbin/vpn-gateway.sh /var/log/vpn-gateway.log
--status --json and more CLI commands for automation| Version | Changes |
|---|---|
| 1.0 | π First public release: auto-detect and auto-follow for TorGuard and Proton VPN, Proton NAT-PMP keep-alive with a port follower, kill switch, port forwarding, live terminal dashboard, kill switch test, leak protection, watcher service |
Released under the MIT License. Β© 2026 MorphyDK
Disclaimer: This project is not affiliated with or endorsed by TorGuard or Proton AG. Use at your own risk, and always test your kill switch before relying on it.
If this saved you some iptables headaches, consider giving it a β
Made with β and a healthy fear of IP leaks
Built by MorphyDK with help from Claude by Anthropic. π€
π‘οΈ VPN gateway for your LAN with kill switch, port forwarding and auto-follow for TorGuard & Proton VPN (NAT-PMP keep-alive). Live terminal dashboard.
Shell
0
4 commits
updated Oct 6, 2026
π‘οΈ VPN gateway for your LAN with kill switch, port forwarding and auto-follow for TorGuard & Proton VPN (NAT-PMP keep-alive). Live terminal dashboard.
Turn an Ubuntu box into a VPN gateway for your LAN, with a kill switch, port forwarding and automatic provider detection.
TorGuard and Proton VPN, auto-detected. A live terminal dashboard. Zero hand-written iptables.
Features β’ How it works β’ Quick start β’ The dashboard β’ Proton VPN β’ Testing β’ Troubleshooting
You want one machine on your LAN, such as a seedbox, web server or game server, to reach the internet only through your VPN. You also want the ports your VPN provider forwards to you to land straight on that machine.
vpn-gateway.sh builds the whole setup from a single colourful terminal dashboard: routing, NAT, port forwarding and a kill switch. Then it keeps it running. Switch from TorGuard to Proton VPN and the gateway reconfigures itself. Proton hands you a random port, and the gateway keeps it open and follows it when it changes.
π‘ Kill switch, in one line: if the VPN goes down, your LAN client gets no internet at all. It never falls back to your ISP.
| Feature | What it does for you | |
|---|---|---|
| π | Auto-detect VPN | Recognises TorGuard and Proton VPN and configures the gateway for whichever one is online |
| π | Auto-follow | Switch VPN provider and the gateway rebuilds itself within seconds, even with the script closed |
| π | Kill switch | LAN clients can only reach the internet through the VPN tunnel |
| π | Port forwarding | Forwarded ports go straight to your LAN client (TCP, UDP or both) |
| π£ | Proton keep-alive | Renews Proton's NAT-PMP port lease, so your port stays the same while connected |
| π― | Port follower | Proton reconnect or new server? The new port is applied automatically |
| πͺ | On-change hook | Run your own command when the Proton port changes (e.g. update qBittorrent) |
| π₯οΈ | Live dashboard | Black-background terminal UI that refreshes every 5 seconds |
| π§ͺ | Kill switch test | Counts the packets the gateway blocks to prove the kill switch works |
| π§± | Gateway shielding | Nothing on the VPN side can open connections to the gateway itself |
| π« | Leak protection | Blocks IPv6 forwarding and ICMP redirects, two classic VPN leaks |
| π | MSS clamping | Fixes the "some websites just hang" problem over WireGuard |
| πΎ | Persistent rules | Survives reboots, and the saved copy stays in sync when the provider switches |
| π§― | Fail-closed | If anything fails, forwarding stays blocked, so nothing leaks |
| π€ | Headless mode | --apply and --detect for scripts and SSH sessions |
flowchart LR
C["π» LAN client<br/>192.168.0.186"] -->|default gateway| G["π‘οΈ VPN Gateway<br/>Ubuntu 24.04"]
G -->|WireGuard / OpenConnect| V{"π Active VPN<br/>auto-detected"}
V --> TG["TorGuard"]
V --> PR["Proton VPN"]
TG --> I(("π Internet"))
PR --> I
I -.->|forwarded port| V
V -.->|DNAT to client| G
G -.->|port| C
G -->|kill switch β| ISP["π« ISP router<br/>(blocked)"]
W["ποΈ Watcher service<br/>every 10 s"] -.->|follows provider<br/>keeps port alive| G
style G fill:#1f6feb,color:#fff,stroke:#1f6feb
style V fill:#2da44e,color:#fff,stroke:#2da44e
style ISP fill:#cf222e,color:#fff,stroke:#cf222e
style W fill:#6e40c9,color:#fff,stroke:#6e40c9
| Provider | Detection | Port forwarding | Port changes |
|---|---|---|---|
| TorGuard | Interface name, OpenConnect, WireGuard config | Static, from the TorGuard portal | Only when you change it in the portal |
| Proton VPN | Interface name, NetworkManager connection, tunnel address | Dynamic, via NAT-PMP | On reconnect or server change, followed automatically |
| Generic | Any WireGuard or tun interface | Static | Manual |
Detection is based on the interface your traffic actually leaves through. Leftover tunnels from a provider you just disconnected can't confuse it, and a switch is only made after the same VPN has been seen twice in a row.
| Requirement | Notes |
|---|---|
| π§ Ubuntu 24.04 | Desktop or Server (other Debian-based distros will probably work) |
| π Root access | Run with sudo |
| π A VPN connection | TorGuard (WireGuard / OpenConnect) and/or Proton VPN (app or WireGuard config) |
| π§ Static LAN IPs | For both the gateway and the client that receives the forwarded ports |
| π£ Proton port forwarding | Needs a paid plan, a P2P server and port forwarding / NAT-PMP enabled |
| π¦ Packages | natpmpc and iptables-persistent are installed automatically when needed |
| π curl (optional) | Shows your public IP through the tunnel in the status screen |
# 1. Download
git clone https://github.com/MorphyDK/vpn-gateway.git
cd vpn-gateway
# 2. Make it executable
chmod +x vpn-gateway.sh
# 3. Connect your VPN, then run
sudo ./vpn-gateway.sh
Follow the setup order shown on the dashboard:
βΆ Setup order: 1 Detect β 2 Settings β 3 Ports β 4 Build
On the LAN client (e.g. 192.168.0.186), set:
A live terminal UI with a black background and colour-coded status. It refreshes every 5 seconds, and menus react to a single keypress.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββ V P N G A T E W A Y v1.0 // kill switch Β· port forwarding
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
VPN β UP Proton VPN proton0 10.2.0.2
PORT 51234 NAT-PMP keep-alive Β· active Β· renewed 12 s ago
KILL SWITCH β ARMED protects LAN clients only - not this machine
CLIENT 192.168.0.186 via ens18 192.168.0.10
DETECTED proton0 β Proton VPN (carries traffic)
WATCHER β running checks every 10 s Β· screen refreshes every 5 s
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SETUP
[1] Detect VPN provider
[2] Settings
[3] Proton port & keep-alive
[4] Build / rebuild gateway
MONITOR
[5] Status & tunnel check
[6] Test kill switch
[7] View active rules
[8] View log
MAINTENANCE
[9] Save rules persistently
[R] Remove gateway rules
[Q] Quit
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
vpngw β― _
| Key | Option | Description |
|---|---|---|
| 1 | π Detect VPN provider | Scans the tunnels, identifies the provider and tests Proton's NAT-PMP |
| 2 | βοΈ Settings | LAN card, provider, interfaces, client IP, port mode and protections |
| 3 | π Ports | TorGuard: change forwarded ports. Proton: port status, client port, hook |
| 4 | ποΈ Build / rebuild | Shows a summary, then builds every rule with a live β step list |
| 5 | π Status & tunnel check | Tunnel state, public IP through the tunnel, client reachability, ports |
| 6 | π§ͺ Test kill switch | 20-second test that counts the packets the gateway blocks |
| 7 | π View active rules | Built-in pager with colours: ACCEPT green, DROP red, NAT magenta |
| 8 | π View log | The last 300 lines of the log |
| 9 | πΎ Save rules | Installs iptables-persistent and saves the rules |
| R | π§Ή Remove | Clean removal of all rules, the watcher and IP forwarding |
β BUILDING GATEWAY
[ 1/10] Enabling IP forwarding β OK
[ 2/10] Flushing old rules β OK
[ 3/10] Setting default policies β OK
[ 4/10] Shielding gateway from VPN side β OK
[ 5/10] Adding VPN forwarding rules β OK
[ 6/10] Adding NAT masquerade β OK
[ 7/10] Setting up port forwarding β OK
[ 8/10] Arming kill switch β OK
[ 9/10] IPv6 block + MSS clamp β OK
[10/10] VPN watcher service β OK
β Proton port received: 51234
There's nothing to do. Just switch:
β VPN CHANGE DETECTED
ONLINE NOW Proton VPN on proton0
CONFIGURED TorGuard Β· torguard-wg tun0
β Settings switched to Proton VPN
...
β Proton port received: 51234
You can turn this off under Settings β A (Auto-follow VPN).
Proton gives you a random port through NAT-PMP, and it disappears if nobody renews it. The watcher handles that for you:
| Situation | What the gateway does |
|---|---|
| β Connected | Renews the lease about every 40 s, so the port stays the same |
| π Disconnect | Closes the old port right away |
| π Reconnect or new server | Fetches the new port and updates the rules automatically |
| πͺ Port changed | Runs your on-change hook with the new port as $1 |
Two ways to handle the random port on your client:
8080 on your client. This is perfect for web servers.# Example hook: tell qBittorrent about the new port
#!/bin/bash
curl -s -X POST "http://192.168.0.186:8080/api/v2/app/setPreferences" \
--data-urlencode "json={\"listen_port\": $1}"
β οΈ The kill switch protects your LAN clients, not the gateway itself. A speedtest on the gateway still works with the VPN off, and that's by design: the gateway must always be able to reconnect the tunnel.
ping -c 5 1.1.1.1
curl -4 -m 5 https://ifconfig.me
β KILL SWITCH TEST - RESULT
Tunnel: DOWN | via VPN: 0 pkts | blocked: 143 pkts
KILL SWITCH WORKS: 143 packets from the LAN were blocked.
| Result | Meaning |
|---|---|
| β KILL SWITCH WORKS | The gateway blocked everything. If pages still load on the client, that's IPv6 going around the gateway |
| β οΈ NO traffic reached this gateway | The client isn't using the gateway: check its default gateway, IPv6, or whether you tested on the gateway itself |
| βΉοΈ Traffic is flowing through the VPN | The VPN was still connected. Disconnect it and test again |
Your router probably hands out IPv6 directly to the client. That traffic never touches the gateway, so it bypasses the VPN and the kill switch, even while the tunnel is up. Disable IPv6 on the client or the router:
| Client | How |
|---|---|
| πͺ Windows | Network adapter β Properties β untick Internet Protocol Version 6 |
| π§ Linux | sudo sysctl -w net.ipv6.conf.all.disable_ipv6=1 (make it permanent in /etc/sysctl.d/) |
Check it: curl -6 ifconfig.me on the client must fail.
If the client uses your router as DNS, those lookups go straight across the LAN to your ISP. Set the client's DNS to a public resolver or your VPN's DNS, so DNS also goes through the tunnel and the kill switch.
FORWARD on DROP.The script replaces all iptables rules on the gateway. It warns you first if it finds:
iptables-persistent also removes UFW, and you're asked before that happens.| Command | Description |
|---|---|
sudo ./vpn-gateway.sh | Live interactive dashboard |
sudo ./vpn-gateway.sh --apply | Rebuild from saved settings without menus |
sudo ./vpn-gateway.sh --detect | List the detected VPN tunnels |
./vpn-gateway.sh --help | Show usage |
$ sudo ./vpn-gateway.sh --detect
INTERFACE TYPE ADDRESS PROVIDER
proton0 wireguard 10.2.0.2 Proton VPN
| Path | Purpose |
|---|---|
/etc/vpn-gateway.conf | Your saved settings (root only, 600) |
/etc/sysctl.d/99-vpn-gateway.conf | IP forwarding and leak protection |
/etc/iptables/rules.v4 / rules.v6 | Persistent rules (once saved) |
/etc/systemd/system/vpn-gateway-keeper.service | The background watcher |
/usr/local/sbin/vpn-gateway.sh | Copy of the script used by the watcher (updated on every build) |
/run/vpn-gateway/keeper.state | Live watcher state: port, tunnel, last renewal |
/var/log/vpn-gateway.log | Full log of every action, switch and port change |
yes.sudo grep "Auto-follow" /var/log/vpn-gateway.logss -tlnp on Linux or netstat -an on Windows.That's an MTU problem. Make sure Settings β M (MSS clamp) is yes, then rebuild.
curl -6 ifconfig.me on the client return an IP? Then it's IPv6.Use 9 Save rules persistently. The status screen shows whether, and when, the rules were last saved.
sudo ./vpn-gateway.sh β R Remove gateway rules
This flushes all rules, resets the policies to ACCEPT, turns IP forwarding off, removes the watcher service and optionally clears the saved rules. To remove everything else:
sudo rm /etc/vpn-gateway.conf /usr/local/sbin/vpn-gateway.sh /var/log/vpn-gateway.log
--status --json and more CLI commands for automation| Version | Changes |
|---|---|
| 1.0 | π First public release: auto-detect and auto-follow for TorGuard and Proton VPN, Proton NAT-PMP keep-alive with a port follower, kill switch, port forwarding, live terminal dashboard, kill switch test, leak protection, watcher service |
Released under the MIT License. Β© 2026 MorphyDK
Disclaimer: This project is not affiliated with or endorsed by TorGuard or Proton AG. Use at your own risk, and always test your kill switch before relying on it.
If this saved you some iptables headaches, consider giving it a β
Made with β and a healthy fear of IP leaks
Built by MorphyDK with help from Claude by Anthropic. π€