How do you firewall your connection from any traffic not to your VPN provider?
servers=( ip1 ip2 ip3 ... )
# Can fwd over internal network
iptables -A OUTPUT -s 192.168.0.0/16 -d 192.168.0.0/16 -j ACCEPT
# Can fwd over loopback
iptables -A OUTPUT -o lo -j ACCEPT
# Can fwd over the tunnel
iptables -A OUTPUT -o tun0 -j ACCEPT
# Can send packets to VPN
for server in "${servers[@]}"; do
echo "Installing rules for $server"
iptables -A OUTPUT -d $server -j ACCEPT
done
# Otherwise drop
iptables -A OUTPUT -j DROP
Use it with a package like iptables-persistent so you don't have to run this every time at boot.Works like a charm, and hard as hell to detect using standard windows tools.
I have been meaning for a while now to make a mini distribution of Linux that works well for VPN usage out of the box. If people are interested in this sort of thing, maybe I could try to make time for it.
I would love to see a VM that I can just spin up that allows for an IPSec tunnel to terminate to it in a road-warrior config.
FWIW, here is what I have so far. http://superuser.com/questions/553193/how-do-i-configure-dd-...