Windows 10下未连接OpenVPN时禁止Chrome访问互联网的方案求助
远程Windows 10设备实现Chrome仅在OpenVPN连接时联网的方案
我之前帮客户处理过完全相同的远程设备场景,这套方案不需要物理接触设备,全程通过远程PowerShell和OpenVPN配置就能搞定,核心是Windows防火墙规则+OpenVPN连接/断开触发脚本,分步走:
1. 先配置默认阻止Chrome出站的防火墙规则
远程登录设备的PowerShell(可以用Enter-PSSession远程连接,前提是设备开启了WinRM),执行以下命令创建默认阻止规则:
# 注意:如果是32位Chrome,路径换成"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" New-NetFirewallRule -DisplayName "Block Chrome by Default" -Direction Outbound -Program "C:\Program Files\Google\Chrome\Application\chrome.exe" -Action Block -Enabled True -Priority 200
这里设置优先级200是为了让后面的允许规则能优先匹配。
2. 创建仅允许Chrome通过OpenVPN接口的规则(默认禁用)
首先得确认OpenVPN的网卡别名,执行命令查看:
Get-NetAdapter | Where-Object {$_.InterfaceDescription -like "*OpenVPN*"} | Select-Object Name
假设输出的网卡名是OpenVPN TAP-Windows6,用这个名称创建允许规则:
New-NetFirewallRule -DisplayName "Allow Chrome Over OpenVPN" -Direction Outbound -Program "C:\Program Files\Google\Chrome\Application\chrome.exe" -Action Allow -Enabled False -InterfaceAlias "OpenVPN TAP-Windows6" -Priority 100
优先级设为100,确保它比阻止规则先被匹配。
3. 编写OpenVPN触发的PowerShell脚本
先创建存放脚本的文件夹:
New-Item -Path C:\Scripts -ItemType Directory -Force
然后创建两个脚本:
连接成功时启用允许规则的脚本(EnableChromeFirewallRule.ps1)
# 以管理员身份执行(避免UAC弹窗,远程设备无人操作时必须) if (-not ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { Start-Process powershell.exe "-File `"$PSCommandPath`"" -Verb RunAs exit } Set-NetFirewallRule -DisplayName "Allow Chrome Over OpenVPN" -Enabled True
断开连接时禁用允许规则的脚本(DisableChromeFirewallRule.ps1)
if (-not ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { Start-Process powershell.exe "-File `"$PSCommandPath`"" -Verb RunAs exit } Set-NetFirewallRule -DisplayName "Allow Chrome Over OpenVPN" -Enabled False
4. 修改OpenVPN配置文件触发脚本
找到远程设备上的OpenVPN配置文件(通常在C:\Program Files\OpenVPN\config或用户的OpenVPN\config目录下),在文件末尾添加以下两行:
script-security 2 up "C:\Scripts\EnableChromeFirewallRule.ps1" down "C:\Scripts\DisableChromeFirewallRule.ps1"
script-security 2是允许OpenVPN执行外部脚本,确保这条命令在所有路由、DNS配置之后。
5. 远程验证规则生效
- 断开OpenVPN连接:尝试用Chrome访问任意网站,应该会被阻止(显示无法连接)
- 连接OpenVPN:Chrome可以正常加载网页
注意事项
- 确保OpenVPN以管理员身份运行,否则脚本无法修改防火墙规则;可以在OpenVPN快捷方式的属性里勾选“以管理员身份运行此程序”
- 如果远程设备WinRM未开启,先在设备上执行
Enable-PSRemoting -Force开启(需要管理员权限) - 如果Chrome有多个版本(比如beta、dev),需要给每个版本的exe都添加对应的防火墙规则
内容的提问来源于stack exchange,提问作者Andrii Vasyliev
相关产品推荐
相关产品推荐

