So, I have had problems with VPNs breaking certain websites quite enough. Some sites just won’t work when they detect VPN traffic, and at this point I’ve learned that running everything through Mullvad with default setting isn’t practical for daily use.
In this article I show my current setup on Zorin OS 18: three browsers with different purposes, Mullvad VPN covering everything except one browser that’s excluded for those problematic sites.
- Operating system: Zorin OS 18 (Ubuntu-based)
- VPN: Mullvad VPN (Paid to use, deb package)
- Browsers: Brave (multimedia), Firefox (general use), Waterfox (VPN-excluded sites)
- Setup date: August 2026
Why Three Browsers?
The idea isn’t to collect browsers for fun. Each one has a specific role:
Brave: Multimedia use only. YouTube, streaming sites, video content. Has built-in ad/tracker blocking but I’m not relying on that alone.
Firefox: Everything else that works fine with VPN. Reading, forums, shopping, general browsing. This is the default for most traffic.
Waterfox: Sites that break with VPN. Some banking sites and government services that block VPN IP ranges entirely. Waterfox is configured to bypass Mullvad completely.
The goal: maximum privacy without losing access to sites that demand real IP addresses.
1. Installing Mullvad VPN
First, get Mullvad installed. You can download the .deb package from their website or use wget if you have another machine with VPN already:
The Fix:
1. Download: wget --trust-server-names https://mullvad.net/download/app/deb/latest
2. Install: sudo apt install ./MullvadVPN-YYYY.N_amd64.deb
3. Open Mullvad and enter your account code
4. Set as favorite in Zorin for quick access
For updates, add the repository:
sudo curl -fsSLo /usr/share/keyrings/mullvad-keyring.asc https://repository.mullvad.net/deb/mullvad-keyring.asc
echo "deb [signed-by=/usr/share/keyrings/mullvad-keyring.asc arch=$(dpkg --print-architecture)] https://repository.mullvad.net/deb/stable stable main" | sudo tee /etc/apt/sources.list.d/mullvad.list
sudo apt update
sudo apt install mullvad-vpn
2. Setting Up Brave for Multimedia
Brave comes with default privacy settings, but I tightened them further:
The Fix:
1. Go to Settings β Privacy and Security
2. Set Shields to “Strict” mode
3. Disable Brave Rewards (it’s telemetry-adjacent)
4. Turn off “Private Window with Tor” if you’re not using it (reduces attack surface)
5. Set default search to DuckDuckGo or Startpage
Brave handles all video content. If a site needs Widevine DRM, it’s isolated here rather than in your main browsing profile.
3. Setting Up Firefox for General Use
Firefox gets the most traffic, so it needs the hardest settings:
The Fix:
1. Go to Settings β Privacy & Security
2. Enable “Strict” Enhanced Tracking Protection
3. Disable Firefox Home content (telemetry)
4. Turn off “Allow Firefox to send technical and interaction data to Mozilla”
5. Disable “Allow Firefox to install and run studies”
6. Set DNS to “Secure DNS” β “Choose provider” β Cloudflare or NextDNS
For even stricter hardening, you can modify about:config, but the default strict mode covers most threats without breaking everyday sites.
4. Setting Up Waterfox as VPN Exemption
This is the critical part. Waterfox runs outside the Mullvad tunnel, so its traffic uses your real IP. Only use it for sites that actually require this.
Step 1: Install Waterfox as Flatpak
On Zorin 18, Waterfox installs as Flatpak by default:
flatpak install flathub net.waterfox.waterfox
Verify installation:
flatpak list | grep -i waterfox
Should return: net.waterfox.waterfox
Step 2: Test the Exclusion Command
Before modifying launchers, verify the exclusion works:
mullvad-exclude flatpak run net.waterfox.waterfox
Waterfox should open. Its traffic now bypasses Mullvad.
Step 3: Create User-Level Launcher Override
Zorin uses .desktop files for application launchers. We need to modify Waterfox’s launcher to always run with the exclusion command:
mkdir -p ~/.local/share/applications
cp /var/lib/flatpak/exports/share/applications/net.waterfox.waterfox.desktop \
~/.local/share/applications/
Edit your copy:
nano ~/.local/share/applications/net.waterfox.waterfox.desktop
Find the line starting with Exec=. It probably looks like:
Exec=flatpak run --branch=stable --arch=x86_64 --command=waterfox --file-forwarding net.waterfox.waterfox @@u %U @@
Replace only the Exec= line with:
Exec=mullvad-exclude flatpak run net.waterfox.waterfox
Save in nano:
- Ctrl+O
- Enter
- Ctrl+X
Step 4: Update Zorin Favorites
Important: If Waterfox is already pinned to your Favorites bar, remove it and add it again from the application menu. This makes Zorin pick up your modified launcher.
After this, clicking the Waterfox icon runs:
mullvad-exclude β flatpak run β Waterfox
Instead of the normal:
flatpak run β Waterfox
Step 5: Configure Waterfox Settings
Waterfox is Firefox-based, so settings are similar:
1. Go to Settings β Privacy & Security
2. Enable strict tracking protection
3. Disable telemetry and data collection
4. Set secure DNS (same as Firefox)
5. Do not install VPN extensions, the whole point is that this browser bypasses VPN
5. Verify the Setup
Before trusting this setup, verify it’s working:
For Brave and Firefox (should show VPN IP):
1. Connect Mullvad VPN
2. Visit https://amiunique.org/ or https://ipleak.net/
3. Check that the displayed IP matches Mullvad’s server location
4. Run DNS leak test, should show Mullvad or your DNS provider, not your ISP
For Waterfox (should show real IP):
1. Make sure Mullvad is connected
2. Open Waterfox via the modified launcher
3. Visit the same sites
4. IP should show your actual location (this is expected, Waterfox is excluded)
5. Run DNS leak test, confirms traffic isn’t tunneling
Phone Setup: Magic OS with Selective Exclusions
The same principle applies to phones. On Magic OS (Honor devices), I use the built-in VPN exclusion feature:
The Fix:
1. Go to Settings β Mobile Network β VPN
2. Select Mullvad VPN
3. Find “Excluded apps” or “VPN bypass” settings
4. Add specific apps that don’t work with VPN (banking apps, certain streaming apps)
5. Everything else routes through Mullvad
Most apps work fine with VPN. Only exclude what actually breaks.
Trade-offs and Limitations
This setup isn’t perfect, and I’m not recommending it as ideal. Here’s what you’re accepting:
What works:
- Most browsing happens through VPN (Firefox, Brave)
- Multimedia isolated to Brave with additional blocking
- Problematic sites accessible via Waterfox without disabling VPN system-wide
- Phone apps that need real IP can be excluded individually
What doesn’t:
- Waterfox traffic is unencrypted from ISP perspective (same as not using VPN)
- You need to remember which browser to use for which site
- Some sites still detect and block VPN even with strict settings
- Browser fingerprinting remains a risk regardless of VPN
The honest assessment: This is a practical compromise, not a perfect privacy solution. If a site requires real IP, using Waterfox means that site sees your actual location. That’s the whole point β but it’s also the limitation.
Why Not Just Use One Browser with Split Tunneling?
Mullvad’s split tunneling feature lets you exclude specific applications from VPN. I tested this with Firefox profiles, but ran into issues:
1. Firefox profiles don’t isolate network traffic, both profiles would need separate exclusion rules
2. Site compatibility changes, a site that works today might block VPN tomorrow
3. Easier to reason about: “Waterfox = no VPN, everything else = VPN”
4. For some users it’s too many steps to open excluded app from Mullvad menu, on my method you can open Waterfox from favories and it’s always excluded
Having a dedicated browser for non-VPN traffic creates a clear mental model. When a site doesn’t work with VPN, you know exactly where to open it.
Conclusion
This setup balances privacy with functionality. Most traffic goes through Mullvad. Sites that break with VPN get Waterfox. Multimedia stays isolated in Brave.
It’s not perfect, but it works for daily use on Zorin OS 18.
What do you think? Is three browsers too much, or does the separation make sense?
What’s your approach to handling sites that block VPNs?
