Three-Browser VPN Setup on Zorin OS: Privacy Without Breaking Functionality

So, I have had problems with VPNs breaking certain websites quite enough. Some sites just won’t work when they detect VPN traffic, and at this point I’ve learned that running everything through Mullvad with default setting isn’t practical for daily use.

In this article I show my current setup on Zorin OS 18: three browsers with different purposes, Mullvad VPN covering everything except one browser that’s excluded for those problematic sites.

  • Operating system: Zorin OS 18 (Ubuntu-based)
  • VPN: Mullvad VPN (Paid to use, deb package)
  • Browsers: Brave (multimedia), Firefox (general use), Waterfox (VPN-excluded sites)
  • Setup date: August 2026

Why Three Browsers?

Brave: Multimedia use only. YouTube, streaming sites, video content. Has built-in ad/tracker blocking but I’m not relying on that alone.

Firefox: Everything else that works fine with VPN. Reading, forums, shopping, general browsing. This is the default for most traffic.

Waterfox: Sites that break with VPN. Some banking sites and government services that block VPN IP ranges entirely. Waterfox is configured to bypass Mullvad completely.

The goal: maximum privacy without losing access to sites that demand real IP addresses.

1. Installing Mullvad VPN

First, get Mullvad installed. You can download the .deb package from their website or use wget if you have another machine with VPN already:

The Fix:

1. Download: wget --trust-server-names https://mullvad.net/download/app/deb/latest
2. Install: sudo apt install ./MullvadVPN-YYYY.N_amd64.deb
3. Open Mullvad and enter your account code
4. Set as favorite in Zorin for quick access

sudo curl -fsSLo /usr/share/keyrings/mullvad-keyring.asc https://repository.mullvad.net/deb/mullvad-keyring.asc
echo "deb [signed-by=/usr/share/keyrings/mullvad-keyring.asc arch=$(dpkg --print-architecture)] https://repository.mullvad.net/deb/stable stable main" | sudo tee /etc/apt/sources.list.d/mullvad.list
sudo apt update
sudo apt install mullvad-vpn

2. Setting Up Brave for Multimedia

Brave comes with default privacy settings, but I tightened them further:

1. Go to Settings β†’ Privacy and Security
2. Set Shields to “Strict” mode
3. Disable Brave Rewards (it’s telemetry-adjacent)
4. Turn off “Private Window with Tor” if you’re not using it (reduces attack surface)
5. Set default search to DuckDuckGo or Startpage

Brave handles all video content. If a site needs Widevine DRM, it’s isolated here rather than in your main browsing profile.

3. Setting Up Firefox for General Use

Firefox gets the most traffic, so it needs the hardest settings:

1. Go to Settings β†’ Privacy & Security
2. Enable “Strict” Enhanced Tracking Protection
3. Disable Firefox Home content (telemetry)
4. Turn off “Allow Firefox to send technical and interaction data to Mozilla”
5. Disable “Allow Firefox to install and run studies”
6. Set DNS to “Secure DNS” β†’ “Choose provider” β†’ Cloudflare or NextDNS

For even stricter hardening, you can modify about:config, but the default strict mode covers most threats without breaking everyday sites.

4. Setting Up Waterfox as VPN Exemption

This is the critical part. Waterfox runs outside the Mullvad tunnel, so its traffic uses your real IP. Only use it for sites that actually require this.

flatpak install flathub net.waterfox.waterfox
flatpak list | grep -i waterfox

Should return: net.waterfox.waterfox

Before modifying launchers, verify the exclusion works:

mullvad-exclude flatpak run net.waterfox.waterfox

Waterfox should open. Its traffic now bypasses Mullvad.

Zorin uses .desktop files for application launchers. We need to modify Waterfox’s launcher to always run with the exclusion command:

mkdir -p ~/.local/share/applications
cp /var/lib/flatpak/exports/share/applications/net.waterfox.waterfox.desktop \
   ~/.local/share/applications/

Edit your copy:

nano ~/.local/share/applications/net.waterfox.waterfox.desktop

Find the line starting with Exec=. It probably looks like:

Exec=flatpak run --branch=stable --arch=x86_64 --command=waterfox --file-forwarding net.waterfox.waterfox @@u %U @@

Replace only the Exec= line with:

Exec=mullvad-exclude flatpak run net.waterfox.waterfox

Save in nano:

  • Ctrl+O
  • Enter
  • Ctrl+X

Step 4: Update Zorin Favorites

Important: If Waterfox is already pinned to your Favorites bar, remove it and add it again from the application menu. This makes Zorin pick up your modified launcher.

After this, clicking the Waterfox icon runs:

mullvad-exclude β†’ flatpak run β†’ Waterfox

Instead of the normal:

flatpak run β†’ Waterfox

Waterfox is Firefox-based, so settings are similar:

1. Go to Settings β†’ Privacy & Security
2. Enable strict tracking protection
3. Disable telemetry and data collection
4. Set secure DNS (same as Firefox)
5. Do not install VPN extensions, the whole point is that this browser bypasses VPN

5. Verify the Setup

Before trusting this setup, verify it’s working:

1. Connect Mullvad VPN
2. Visit https://amiunique.org/ or https://ipleak.net/
3. Check that the displayed IP matches Mullvad’s server location
4. Run DNS leak test, should show Mullvad or your DNS provider, not your ISP

1. Make sure Mullvad is connected
2. Open Waterfox via the modified launcher
3. Visit the same sites
4. IP should show your actual location (this is expected, Waterfox is excluded)
5. Run DNS leak test, confirms traffic isn’t tunneling

Phone Setup: Magic OS with Selective Exclusions

The same principle applies to phones. On Magic OS (Honor devices), I use the built-in VPN exclusion feature:

1. Go to Settings β†’ Mobile Network β†’ VPN
2. Select Mullvad VPN
3. Find “Excluded apps” or “VPN bypass” settings
4. Add specific apps that don’t work with VPN (banking apps, certain streaming apps)
5. Everything else routes through Mullvad

Most apps work fine with VPN. Only exclude what actually breaks.

Trade-offs and Limitations

This setup isn’t perfect, and I’m not recommending it as ideal. Here’s what you’re accepting:

  • Most browsing happens through VPN (Firefox, Brave)
  • Multimedia isolated to Brave with additional blocking
  • Problematic sites accessible via Waterfox without disabling VPN system-wide
  • Phone apps that need real IP can be excluded individually
  • Waterfox traffic is unencrypted from ISP perspective (same as not using VPN)
  • You need to remember which browser to use for which site
  • Some sites still detect and block VPN even with strict settings
  • Browser fingerprinting remains a risk regardless of VPN

The honest assessment: This is a practical compromise, not a perfect privacy solution. If a site requires real IP, using Waterfox means that site sees your actual location. That’s the whole point β€” but it’s also the limitation.

Mullvad’s split tunneling feature lets you exclude specific applications from VPN. I tested this with Firefox profiles, but ran into issues:

1. Firefox profiles don’t isolate network traffic, both profiles would need separate exclusion rules
2. Site compatibility changes, a site that works today might block VPN tomorrow
3. Easier to reason about: “Waterfox = no VPN, everything else = VPN”
4. For some users it’s too many steps to open excluded app from Mullvad menu, on my method you can open Waterfox from favories and it’s always excluded

Having a dedicated browser for non-VPN traffic creates a clear mental model. When a site doesn’t work with VPN, you know exactly where to open it.

Conclusion

This setup balances privacy with functionality. Most traffic goes through Mullvad. Sites that break with VPN get Waterfox. Multimedia stays isolated in Brave.

It’s not perfect, but it works for daily use on Zorin OS 18.

What do you think? Is three browsers too much, or does the separation make sense?

What’s your approach to handling sites that block VPNs?

Related Video’s

Leave a Comment

Your email address will not be published. Required fields are marked *

πŸ“¬ Never miss an update! Subscribe via RSS: πŸ“‘ Subscribe Now What is RSS?