Monitor a VPN connection on Linux and kill a process upon disconnect
Clone or download
Type Name Latest commit message Commit time
Failed to load latest commit information.
screenshots Added and screenshots. Aug 26, 2014 Added installer. Aug 26, 2014 Updated readme. Aug 27, 2014 Added VPN disconnect check for 'uint32 6 ' Oct 26, 2015


for Linux

VPNDemon monitors your VPN connection and kills a target program upon disconnect. It's the safest and easiest way to help prevent DNS leaks and enhance your security while connected over a VPN.

Screenshot 1

It's as simple as this:

  • Run
  • Enter the name of the target process to kill when the VPN disconnects.

That's it!


  1. Download and place it in a folder, such as ~/Documents/vpndemon.
cd ~/Documents/vpndemon
  1. Enter the name of a program to kill when the VPN disconnects. This can be a substring of the name, such as "chrome", "firefox", etc.

Enter a target process to kill upon VPN disconnect

  1. Click OK to start monitoring.

Monitoring VPN connection

  1. VPNDemon is now monitoring your VPN connection. If your not already connected to your VPN, go ahead and connect now.

Detecting a VPN connection

  1. Try disconnecting your VPN. VPNDemon will detect the disconnect, kill all instances of the target program, and update its status.

Detecting a VPN disconnect

Installing as an Application

  1. Download and Run
cd ~/Documents/vpndemon
sudo bash
  1. After installing, open the start menu and search for VPNDemon. Right-click the result and select "Add to Panel" or "Add to Desktop".

Technical Details

VPNDemon monitors the VPN connection by listening to events from the linux NetworkManager. When a VPN connect/disconnect event is received, the signal is checked to see which state it relates to. If it's a connect state, the status is simply displayed in the main window. If it's a disconnect state, VPNDemon immediately issues a kill command for all processes that match the target process name:

for i in `pgrep $killProgramName`
    kill $i

Since the NetworkManager is being listened to, directly via the dbus-monitor, disconnect events are detected almost instantly. Likewise, the target process is killed almost instantly.

VPNDemon should be compatible with any linux system that uses NetworkManager for VPN connections.


  1. A log file is saved to /tmp/vpndemon, which contains the list of VPN connect/disconnect events and a list of processes terminated. The log is cleared each time the app is run. However, you can review the log during or after running the app, to help determine any troubleshooting issues.

Preventing DNS Leaks with IPv6

If you want even tighter privacy, you can disable IPv6. This is easy to do. IPv6 incorporates hardware MAC addresses, and since many VPN services do not yet route IPv6 traffic, it creates a potential leak for network activity.

To disable IPv6, edit the file /etc/sysctl.conf and add the following lines:

net.ipv6.conf.all.disable_ipv6 = 1
net.ipv6.conf.default.disable_ipv6 = 1
net.ipv6.conf.lo.disable_ipv6 = 1

After making these changes, refresh the file by running:

sudo sysctl -p

To verify IPv6 is actually disabled, run ifconfig and verify that "inet6" is not present in the output:

ifconfig | grep inet6




Kory Becker