{"id":3350,"date":"2023-02-03T06:53:14","date_gmt":"2023-02-03T11:53:14","guid":{"rendered":"https:\/\/dft.wiki\/?p=3350"},"modified":"2026-06-08T17:03:34","modified_gmt":"2026-06-08T21:03:34","slug":"how-to-install-whonix-gateway-cli-on-proxmox","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=3350","title":{"rendered":"How to Install Whonix Gateway CLI on Proxmox"},"content":{"rendered":"<p><strong>Whonix<\/strong> is a privacy-focused operating system designed to provide the highest level of privacy and security possible.<\/p>\n<p>It is designed to be used with the Tor network, a decentralized network that protects users&#8217; online privacy by routing internet traffic through multiple servers.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3352 aligncenter\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/whonix.png\" alt=\"\" width=\"588\" height=\"327\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/whonix.png 588w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/whonix-300x167.png 300w\" sizes=\"auto, (max-width: 588px) 100vw, 588px\" \/><\/p>\n<p>Why Proxmox and not VirtualBox?<\/p>\n<ul>\n<li>Proxmox does not require a host operating system such as Windows, Mac, or Linux. It runs directly on bare metal as a headless host.<\/li>\n<\/ul>\n<p>Why Whonix CLI and not the GUI version?<\/p>\n<ul>\n<li>There is no reason to have a GUI on a gateway that will be headless 100% of the time. It reduces RAM and CPU overhead.<\/li>\n<\/ul>\n<p>Why Whonix and not OpenWRT or pfSense?<\/p>\n<ul>\n<li>Whonix enforces all traffic through the Tor network and is specifically designed to minimize (and potentially eliminate) the risk of leaks.<\/li>\n<\/ul>\n<hr \/>\n<p><strong>BASIC STEPS<\/strong><\/p>\n<ul>\n<li>Download Whonix<\/li>\n<li>Import to VirtualBox<\/li>\n<li>Complete installation and test<\/li>\n<li>Export only the Gateway<\/li>\n<li>Copy the disk to Proxmox<\/li>\n<li>Configure Proxmox networks (create vmbr2)<\/li>\n<li>Manually create a VM in Proxmox<\/li>\n<li>Convert and attach the disk to the VM<\/li>\n<li>Attach the second network to the VM (vmbr2)<\/li>\n<li>Configure the VM boot sequence<\/li>\n<li>Configure Whonix network interfaces (vmbr0)<\/li>\n<li>Run a client VM or container on vmbr2<\/li>\n<\/ul>\n<hr \/>\n<p><strong>DOWNLOAD<\/strong><\/p>\n<p>Download the OVA (Open Virtualization Format) file from the official repository [<a href=\"https:\/\/www.whonix.org\/wiki\/VirtualBox_Testers_Only_Version\/CLI\">Link<\/a>].<\/p>\n<p>The GUI version can also be downloaded if preferred.<\/p>\n<hr \/>\n<p><strong>IMPORT TO VIRTUALBOX<\/strong><\/p>\n<p>This step is not mandatory but provides an opportunity to complete the installation, accept the terms of service, run tests, and so on.<\/p>\n<p>Go to <strong>VirtualBox Manager &gt; File &gt; Import Appliance&#8230;<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3356 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-30-36-1024x257.png\" alt=\"\" width=\"640\" height=\"161\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-30-36-1024x257.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-30-36-300x75.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-30-36-768x193.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-30-36.png 1065w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Click <strong>Next<\/strong>, then <strong>Import<\/strong>.<\/p>\n<p>Accept both terms of service.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3357 size-medium\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-33-50-273x300.png\" alt=\"\" width=\"273\" height=\"300\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-33-50-273x300.png 273w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-33-50.png 379w\" sizes=\"auto, (max-width: 273px) 100vw, 273px\" \/><\/p>\n<p>Both VMs will be deployed automatically. Start them.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3358\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-37-11.png\" alt=\"\" width=\"392\" height=\"126\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-37-11.png 392w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-37-11-300x96.png 300w\" sizes=\"auto, (max-width: 392px) 100vw, 392px\" \/><\/p>\n<hr \/>\n<p><strong>COMPLETE INSTALLATION AND TEST<\/strong><\/p>\n<p>Log in to both VMs. Some recommend starting with the Gateway before the Workstation, but the order is up to you.<\/p>\n<p>The default credentials are <strong>user<\/strong> and <strong>changeme<\/strong>. Change the password as soon as possible.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3359 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-43-15-1024x752.png\" alt=\"\" width=\"640\" height=\"470\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-43-15-1024x752.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-43-15-300x220.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-43-15-768x564.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-43-15.png 1252w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>On the Gateway VM, select the option that fits your setup. For most users, option 1 is the right choice.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3360\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-44-37.png\" alt=\"\" width=\"774\" height=\"258\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-44-37.png 774w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-44-37-300x100.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-09-44-37-768x256.png 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><\/p>\n<p>Setup may take several minutes to complete.<\/p>\n<p>Testing the Gateway:<\/p>\n<pre>curl http:\/\/ip.me<\/pre>\n<p>The output should be an IP different from your real IP, since traffic is routed through a random Tor exit node.<\/p>\n<p>This is a good time to change your password and update the gateway.<\/p>\n<pre>passwd<\/pre>\n<pre>sudo apt update && sudo apt upgrade -y<\/pre>\n<p>Testing the Workstation:<\/p>\n<pre>curl http:\/\/ip.me<\/pre>\n<p>The same result is expected. Power off both VMs.<\/p>\n<pre>sudo shutdown now<\/pre>\n<hr \/>\n<p><strong>EXPORT WHONIX GATEWAY<\/strong><\/p>\n<p>Go to <strong>VirtualBox Manager &gt; File &gt; Export Appliance&#8230;<\/strong> and select <strong>Whonix-Gateway-CLI<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3364 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-05-30-1024x385.png\" alt=\"\" width=\"640\" height=\"241\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-05-30-1024x385.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-05-30-300x113.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-05-30-768x288.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-05-30.png 1193w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Click <strong>Next<\/strong>, then <strong>Export<\/strong>.<\/p>\n<p>Once done, both Whonix VMs can be removed and their files deleted.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3365\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-07-56.png\" alt=\"\" width=\"452\" height=\"270\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-07-56.png 452w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-02-10-07-56-300x179.png 300w\" sizes=\"auto, (max-width: 452px) 100vw, 452px\" \/><\/p>\n<hr \/>\n<p><strong>COPY THE DISK TO PROXMOX<\/strong><\/p>\n<p>An OVA file is similar to a TAR or ZIP archive. Extract its contents:<\/p>\n<pre>tar xvf Whonix-Gateway-CLI.ova<\/pre>\n<p>Start a temporary web server from the directory where the OVA was extracted:<\/p>\n<pre>python3 -m http.server 8080<\/pre>\n<p>Alternatively, <code>scp<\/code> can be used to copy the file over SSH.<\/p>\n<p>On the <strong>Proxmox Shell<\/strong>, download the disk file. Adjust the URL as needed.<\/p>\n<pre>wget http:\/\/<strong>10.10.10.10<\/strong>:8080\/Whonix-Gateway-CLI-disk001.vmdk<\/pre>\n<hr \/>\n<p><strong>PROXMOX NETWORKS<\/strong><\/p>\n<p>Go to <strong>Node (pve) &gt; System &gt; Network &gt; Create &gt; Linux Bridge<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3369\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-40-49.png\" alt=\"\" width=\"756\" height=\"449\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-40-49.png 756w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-40-49-300x178.png 300w\" sizes=\"auto, (max-width: 756px) 100vw, 756px\" \/><\/p>\n<p>Click <strong>Apply Configuration<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3370\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-41-45.png\" alt=\"\" width=\"1066\" height=\"179\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-41-45.png 1066w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-41-45-300x50.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-41-45-1024x172.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-41-45-768x129.png 768w\" sizes=\"auto, (max-width: 1066px) 100vw, 1066px\" \/><\/p>\n<p>Note that the new bridge has no gateway assigned and is not attached to any physical port.<\/p>\n<hr \/>\n<p><strong>CREATE VIRTUAL MACHINE<\/strong><\/p>\n<p>Click <strong>Create VM<\/strong> on the desired node. No special configuration is required when creating the VM.<\/p>\n<p>Since the VirtualBox export used a SATA disk, the same bus and device number should be used to avoid any mismatch.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3377\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-45-16.png\" alt=\"\" width=\"726\" height=\"363\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-45-16.png 726w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-45-16-300x150.png 300w\" sizes=\"auto, (max-width: 726px) 100vw, 726px\" \/><\/p>\n<p>As shown in the VM summary, no more than 512 MB of RAM and 2 CPU cores are needed.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3371\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-46-28.png\" alt=\"\" width=\"726\" height=\"517\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-46-28.png 726w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-46-28-300x214.png 300w\" sizes=\"auto, (max-width: 726px) 100vw, 726px\" \/><\/p>\n<p>Click <strong>Finish<\/strong>.<\/p>\n<hr \/>\n<p><strong>ATTACH THE DISK<\/strong><\/p>\n<p>On the <strong>Proxmox Shell<\/strong>, from the directory where the disk was downloaded, run the following command:<\/p>\n<pre>qm importdisk <strong>109<\/strong> Whonix-Gateway-CLI-disk001.vmdk <strong>local-lvm<\/strong> -format qcow2<\/pre>\n<p><strong>Note:<\/strong> Adjust the VM number and storage location as needed.<\/p>\n<p>The original VMDK file can now be deleted or kept for future use.<\/p>\n<p>Go to <strong>WhonixGateway &gt; Hardware<\/strong>, select <strong>Hard Disk (sata0)<\/strong>, click <strong>Detach<\/strong>, then <strong>Remove<\/strong>. Double-click <strong>Unused Disk 0<\/strong>, select <strong>SATA<\/strong>, and click <strong>Add<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3378\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-18-15.png\" alt=\"\" width=\"649\" height=\"269\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-18-15.png 649w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-18-15-300x124.png 300w\" sizes=\"auto, (max-width: 649px) 100vw, 649px\" \/><\/p>\n<hr \/>\n<p><strong>ATTACH SECOND NETWORK<\/strong><\/p>\n<p>In the same Hardware configuration, click <strong>Add &gt; Network Device<\/strong>, select <strong>vmbr2<\/strong>, and click <strong>Add<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3372\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-48-07.png\" alt=\"\" width=\"605\" height=\"262\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-48-07.png 605w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-48-07-300x130.png 300w\" sizes=\"auto, (max-width: 605px) 100vw, 605px\" \/><\/p>\n<p>The result should look like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3374\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-48-25.png\" alt=\"\" width=\"655\" height=\"327\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-48-25.png 655w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-48-25-300x150.png 300w\" sizes=\"auto, (max-width: 655px) 100vw, 655px\" \/><\/p>\n<hr \/>\n<p><strong>BOOT SEQUENCE<\/strong><\/p>\n<p>Go to <strong>Options &gt; Boot Order &gt; Edit<\/strong> and enable only <strong>sata0<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3376\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-51-16.png\" alt=\"\" width=\"803\" height=\"507\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-51-16.png 803w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-51-16-300x189.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-05-51-16-768x485.png 768w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/p>\n<p>Click <strong>OK<\/strong>.<\/p>\n<hr \/>\n<p><strong>CONFIGURE NETWORK INTERFACE<\/strong><\/p>\n<p>Start the VM and open the Console.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3379 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-24-37-1024x567.png\" alt=\"\" width=\"640\" height=\"354\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-24-37-1024x567.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-24-37-300x166.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-24-37-768x425.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-24-37.png 1287w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>If everything went correctly, the bootloader will appear and the VM will be up within a few seconds.<\/p>\n<pre>sudo nano \/etc\/network\/interfaces.d\/30_non-qubes-whonix<\/pre>\n<p>The <code>eth0<\/code> interface is the public (WAN) side of the Whonix gateway, and <code>eth1<\/code> is the private (LAN) side.<\/p>\n<p>No changes are needed on the private side. On the public side, a static IP must be set to an address not already in use on your local network.<\/p>\n<p>Whonix does not support DHCP, so make sure to choose an IP outside your LAN&#8217;s DHCP lease range.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3380 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-31-09-1024x682.png\" alt=\"\" width=\"640\" height=\"426\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-31-09-1024x682.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-31-09-300x200.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-31-09-768x512.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-31-09.png 1424w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Reboot the VM.<\/p>\n<pre>sudo reboot<\/pre>\n<p>Then test for internet connectivity.<\/p>\n<pre>sudo apt update<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3381 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-42-31-1024x232.png\" alt=\"\" width=\"640\" height=\"145\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-42-31-1024x232.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-42-31-300x68.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-42-31-768x174.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2023\/02\/Screenshot-from-2023-02-03-06-42-31.png 1048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p><strong>Note:<\/strong> The repositories are being reached through Tor. It works!<\/p>\n<hr \/>\n<p><strong>RUN A CLIENT ON THE SECONDARY NETWORK<\/strong><\/p>\n<p>Attach any client VM or container to the secondary isolated network <strong>vmbr2<\/strong> and start it.<\/p>\n<p>It will not work out of the box because the Whonix Gateway does not assign IPs to clients. This must also be configured manually.<\/p>\n<p>Use the <strong>Console<\/strong> to configure the network interface. In this example, a Debian container is used:<\/p>\n<pre>nano \/etc\/network\/interfaces<\/pre>\n<pre>auto lo\r\niface lo inet loopback\r\n\r\nauto eth0\r\niface eth0 inet <strong>static<\/strong>\r\n        address <strong>10.152.152.11\/18<\/strong>\r\n        gateway <strong>10.152.152.10<\/strong><\/pre>\n<pre>reboot<\/pre>\n<p>Test for connectivity. All traffic is now routed anonymously through Tor.<\/p>\n<hr \/>\n<p><strong>BONUS<\/strong><\/p>\n<p>Have you heard of <strong>Qubes OS<\/strong> [<a href=\"https:\/\/www.qubes-os.org\/\">Link<\/a>]? While Whonix focuses on privacy and routes all traffic through Tor, Qubes OS takes a security-first approach through strict compartmentalization between virtual machines.<\/p>\n<p>Qubes OS is a Type 1 hypervisor based on the Xen Project. It isolates workloads for maximum security and reliability, whether running separate production and development environments or safely analyzing malware without risking other systems.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Whonix is a privacy-focused operating system designed to provide the highest level of privacy and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,1],"tags":[],"class_list":["post-3350","post","type-post","status-publish","format-standard","hentry","category-hacking","category-ccna"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/3350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3350"}],"version-history":[{"count":14,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/3350\/revisions"}],"predecessor-version":[{"id":5652,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/3350\/revisions\/5652"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}