Best option would be VPN --> Sys-whonix--> Residential proxy, and make sure to not use a proprietary anti-detect browser
Hacking / Opsec
Routing vpn+proxy through whonix/TOR on Qubes?
Started by junkinthetrunk · Jun 24, 2026
Isnt it recommened not to use VPN with Qubes/Whonix?
This idea makes sense, at least I'm hiding TOR usage from any ISP first, then routing through TOR, and going through another proxy
mullvad should be a standalone VM, whos net qube is sys-firewall which you could ditch for Mirage Firewall. Was a little complicated to setup for me but some people may not have trouble with it. Not sure if you're aware but Mullvad removed support for OpenVPN so you need scripts in place to make sure Mullvad is routing internet to other qubes. Your Windows RDP qube and any other qube should be using Mullvad as its net qube.
To add to this, solene has a post on qubes os forums that shows you how to set this up. they explain it pretty well
Many people say no but I do not see why not. If the tor nodes you connected to were compromised, the VPN can be a last line of defense instead of going straight to your ip. If you are using public WiFi then it is not recommended, but for home wifi, vpn will be better.
but doesnt Qubes/WHonix protect your ip even though TOR getting compromised?
Also, you can use bridges
Im by no means any expert in this, thats why im asking and trying to get a better understand for better OPSEC
Also, you can use bridges
Im by no means any expert in this, thats why im asking and trying to get a better understand for better OPSEC
Is there any reason to not set the net qube to be sys-whonix? Other than latency is there any problems with running mullvad and TOR on the same chain?
The issue is this, if you want to hide tor usage from your ISP you're gonna need a VPN upfront, and even if not. You're gonna need a VPN + Proxies after Whonix. Assuming you have all the protective settings on Mullvad on, you're hopping through 6+ locations before reaching your RDP. Theres different routes you can take if you want to avoid this like a burner laptop on public wifi. But assuming you're doing this from home and don't want to be on the move, Whonix is just overkill and ultimately is gonna cause bad latency. What you should ask yourself is do you trust Mullvad? If not, make your own VPN and put other measures in place.
Also Mullvad is pretty trusted however adding Whonix is useless in the case that LE subpeonas your VPN company. Better be sure that no DNS leaks happen between all the locations you're hopping through.
Members-only continuation
This discussion contains more posts.
Create an account or sign in to continue reading the full conversation. 3 additional posts await inside.