DNS locked to the ship. Tailscale management active.
PRIVACY LEVEL
💀
Double Hop
Dead Man's Route
All LAN traffic through WireGuard. Tailscale stays up for management.
PRIVACY LEVEL
🏴☠️
Z-HOP
Davy Jones
Maximum stealth. WireGuard + DNS lockdown. Tailscale management only.
PRIVACY LEVEL
▸ TUNNEL STATUS
WireGuard
--
wg0
DATA TUNNEL
Tailscale
--
tailscale0
MANAGEMENT
OFF
Pi-hole
UP
DNS filter
ALWAYS ON
▸ SUPPORT
▸ REPAIR TOOLS
⚠ DNS LEAK DETECTED — Your DNS queries are being exposed to your ISP.
⚙Pi-hole Setup Required
Connect the Command Deck to Pi-hole to manage blocklists, domain filtering, and ad blocking stats. Enter your Pi-hole admin password below.
▸ ARSENAL
🛡Kill Switch
Blocks all traffic if VPN drops or DNS leaks are detected, preventing your traffic from leaking to your ISP.
Protects you from: DNS leaks and VPN tunnel failures
OFF
Auto-trip on DNS leak
🔒Encrypted DNS
Routes all DNS queries through Cloudflare's DNS-over-HTTPS (DoH) instead of cleartext. Your ISP can't see what sites you look up.
Protects you from: ISP snooping on your DNS queries and DNS spoofing attacks
OFF
🚫QUIC Block
Blocks the QUIC protocol (UDP port 443) on all privacy modes. Forces browsers to fall back to standard HTTPS, which ensures Pi-hole DNS filtering can't be bypassed.
Protects you from: Browsers using QUIC to bypass DNS-based ad blocking and privacy filters
BLOCKING
🔍DNS Leak Test
Checks if your DNS queries are leaking outside your VPN tunnel by comparing what resolver Cloudflare sees for local vs direct requests.
Protects you from: Unknowingly exposing your browsing to your ISP while on VPN
🎲MAC Randomization
Generates a random MAC address for the WiFi AP on each reboot. Uses locally-administered (02:xx) prefix. Takes effect on next reboot.
Protects you from: Device fingerprinting and network tracking across locations
OFF
🖥️Terminal Mode
Boots the Pi into a CLI-only terminal instead of the graphical desktop. Frees up RAM and CPU for routing. Takes effect on next reboot.
Benefit: Reduced attack surface and lower resource usage — ideal for headless operation
OFF
📋Blocklist Manager
Controls how often Pi-hole updates its ad/tracker blocklists. Daily catches new threats faster; weekly is lighter on resources.
Protects you from: Ads, trackers, and malicious domains across all devices on your network
Block or Allow a Domain
📡Connected Clients0 devices
Shows all devices currently connected to GhostPort's WiFi network via DHCP.
Loading...
⏰Scheduled Modes
Automatically switch security modes on a schedule. For example, switch to Z-HOP every night and back to ISP in the morning.
⚡Speed Test
Measures download/upload speed and latency through your current tunnel. Shows the real-world performance impact of your privacy mode.
📡Ping Test
Checks latency to your gateway, local DNS, and the internet. Helps pinpoint where connectivity issues are happening.
🌐IP Leak Test
Checks if your real IP address is leaking outside the VPN tunnel by comparing your public IP against the WireGuard endpoint.
Protects you from: VPN misconfigurations that expose your real IP address
🛡Security Scan
Full system security audit powered by Lynis. Checks firewall, SSH, permissions, kernel hardening, authentication, and 200+ security controls.