Easy Qubes firewall for VMs connected to sys-whonix

Original forum link
https://forum.qubes-os.org/t/33827
Original poster
gasull
Created at
2025-05-08 09:38:56
Last wiki edit
2025-05-08 11:35:29
Revisions
1 revision
Posts count
18
Likes count
3

I've noticed that the rules set in the Qubes firewall for VMs connected to sys-whonix are completely ignored. All traffic goes through. The Whonix wiki warns about it:

https://www.whonix.org/wiki/Qubes/Firewall#Whonix-Workstation_Firewall

Easy solution: create named disposable sys-whonix-fw based on Debian or Fedora (just like sys-firewall or sys-vpn-fw), then connect your VMs to sys-whonix-fw insteaad of sys-whonix. Now all traffic with be filtered by the Qubes firewall.

EDIT: This even allows for filtering .onion addresses in the Qubes VM firewall (if you don't mind painstakingly typing an Onion v3 address, since copypasting to dom0 is disabled and discouraged).