From Whonix

< Dev


Authoring Notes:

  • Start with a general description below each headline. Be as general as possible and try to avoid using terms like 'Tor'.
  • Next, carefully describe the Whonix Example Implementation. Show exactly how Whonix implements the goals stated above.
  • See Dev/Documentation_Guidelines for the preferred formatting style and grammatical considerations.

List of installed Packages[edit]

Whonix ™-Example-Implementation:




An application to anonymize network traffic, called anonymizer, is required. The application to anonymize network traffic has to be obtained from a safe download source. Increase file maximum, if required by the anonymizer.

Whonix ™-Example-Implementation:

Network Configuration[edit]

The Gateway needs two network interfaces. An external interface to communicate with clearnet for Tor and an internal interface to communicate with the Workstation.

Disable IPv6, if not supported by the anonymity network.

Disable IP forwarding, if it is not required due to the firewall rules (such as in case of Tor, which offers a TransPort and a DNSPort).

Configure the system resolver to use the anonymity network to resolve DNS. - This is not required to anonymize traffic of the Workstation. The system resolver of the Gateway should not get used by any applications anyway, because they are explicitly configured to use the anonymity network. Useful as defence in depth. DNS and other traffic from the Workstation gets forced by the Gateway's firewall to use the anonymity network. The Gateways's own traffic gets anonymized with the purpose of hiding the existence of the Gateway from the ISP, as it is expected that most users do not want to announce the existence of a Gateway, which may indicate that they run onion services or other applications over Tor. The Gateway could alternatively fetch its own operating system updates over clearnet, but since package selection is unique clearnet traffic may imply Gateway. And, as package downloads are only authenticated, not encrypted, it is better to download the updates over the already to hand anonymity network. As an anonymity network, such as Tor, with changing exit relays (and thus exit ISPs) is getting used, this also makes it even harder for an adversary to interfere with the update process. The last sentence gets elaborated on the Design Shared page in chapter about "Operating System Updates".

Prevent DHCP from updating the system resolver.

Whonix ™-Example-Implementation:


Add a firewall, which permits only the anonymizer's traffic to reach the internet.

Whonix ™-Example-Implementation:


Firewall Removal[edit]


Include a command to easily remove all firewall rules, which can not be run by accident without editing the file with root rights.

Whonix ™-Example-Implementation:

Leaktest script[edit]


Have a script to try to produce a leak and check if there are any leaks.

Whonix ™-Example-Implementation:

Clearnet User[edit]


To have a user account "clearnet" on the Gateway may be helpful for debugging, an "unsafe" browser (which can be used to register public hotspots).

Whonix ™-Example-Implementation:


Tor Controller[edit]


Whonix ™-Example-Implementation:

Help file[edit]


When the user types a short and easy command, the most important and most asked commands should be listed.

Whonix ™-Example-Implementation:

Marker file[edit]


Add a marker file so scripts you write can find out, whether they are running on the Gateway or inside the Workstation. There are probably different implementations possible to reach that goal.

Whonix ™-Example-Implementation:


Changes from Dev/Design-Shared also have to be added to the Gateway.

text=Jobs in USA
Jobs in USA

Search engines: YaCy | Qwant | ecosia | MetaGer | peekier | Whonix ™ Wiki

Follow: 1024px-Telegram 2019 Logo.svg.png Iconfinder Apple Mail 2697658.png Twitter.png Facebook.png Rss.png Reddit.jpg 200px-Mastodon Logotype (Simple).svg.png

Support: 1024px-Telegram 2019 Logo.svg.png Discourse logo.png Matrix logo.svg.png

Donate: Donate Bank Wire Paypal Bitcoin accepted here Monero accepted here Contriute

Whonix donate bitcoin.png Monero donate Whonix.png United Federation of Planets 1000px.png

Twitter-share-button.png Facebook-share-button.png Telegram-share.png Iconfinder Apple Mail 2697658.png Reddit.jpg 200px-Mastodon Logotype (Simple).svg.png

Please contribute by helping to answer Whonix ™ questions.

https link onion link

This is a wiki. Want to improve this page? Help is welcome and volunteer contributions are happily considered! Read, understand and agree to Conditions for Contributions to Whonix ™, then Edit! Edits are held for moderation. Policy of Whonix Website and Whonix Chat and Policy On Nonfreedom Software applies.

Copyright (C) 2012 - 2021 ENCRYPTED SUPPORT LP. Whonix ™ is a trademark. Whonix ™ is a licensee [archive] of the Open Invention Network [archive]. Unless otherwise noted, the content of this page is copyrighted and licensed under the same Freedom Software license as Whonix ™ itself. (Why?)

The personal opinions of moderators or contributors to the Whonix ™ project do not represent the project as a whole.

Whonix ™ is a derivative of and not affiliated with Debian [archive]. Debian is a registered trademark [archive] owned by Software in the Public Interest, Inc [archive].

Whonix ™ is produced independently from the Tor® [archive] anonymity software and carries no guarantee from The Tor Project [archive] about quality, suitability or anything else.

By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent. Whonix ™ is provided by ENCRYPTED SUPPORT LP. See Imprint, Contact.

By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent.