Coming soon! The Kael'Nyrin Scrolls: The Atlas Edict

Captain Walker

NordVPN Installation Guide for BigLinux

AI, biglinux, CPanel, installation, linux, logouts, NordVPN, persistence

Estimated reading time at 200 wpm: 8 minutes

I undertook this because on trying to login to CPanel – a portal from where I manage my websites – I was getting logouts and messages saying “Your IP Address has changed” after a few seconds of logging in. There was actually no apparent change of my IP Address or one that I could see. I consulted with my hosting provider and they identified that I was using a mobile network for internet access (which is true). They advised that in the background mobile internet providers give a ‘short lease’ on IP Addresses, but don’t necessarily change them. But secure sites like the CPanel will pick up the expiry of the ‘lease’ and throw a wobbly.

Whether or not you agree our Fat Disclaimer applies

The hosting provider suggested using a VPN for a stable lease on IP Addresses. Fortunately I had a subscription to NordVPN already. But VPNs are free in many places anyway. I just happen to like Nord because of their very secure NordLynx connection plus Post-Quantum Encryption. On W11 this would have been easy cuz I had a Nord Windows app but on Linux there was no official app.

BigLinux, derived from Manjaro and Arch Linux, lacks direct support from NordVPN’s official installer script, which targets Debian/Ubuntu or Fedora derivatives. This leads to several hurdles, including package manager mismatches, snapd integration quirks, PATH environment issues, and connection failures due to DNS resolver conflicts. All of this was with Grok AI assistance.

I don’t know or understand what it all means. I don’t need to, just like I don’t need to understand ‘How computers work‘ to use them!! But in a free and democratic society everybody has choice! Therefore some may wish to spend their lives understanding how aeroplanes and cars work before they get into them. Yuh know, ‘If I don’t understand it; that’s dangerous!‘. Innit! The following is what happened – my notes; because I will need to replicate on my other BigLinux installations.

This is not a tutorial! No warranties supplied. If you brick your computer, sue yourself!

The first attempt initially seemed good but failed on restart. That led to a full clear out of what was installed.

Prerequisites

  • Active NordVPN subscription with credentials.
  • Internet connection (e.g., Three UK hotspot).
  • Update your system first:

The initial approach focused on installing NordVPN using the Snap package manager, as it promised cross-distribution compatibility for BigLinux (an Arch/Manjaro derivative). The process began with enabling Snap support and installing the NordVPN snap.

Key Steps and Code

  1. Install Snapd:
   sudo pacman -S snapd

This command installs the Snap daemon, which manages self-contained packages like NordVPN, allowing them to run independently of the system’s package manager.

  1. Enable Snapd socket:
   sudo systemctl enable --now snapd.socket

This activates the background service for Snap, ensuring it starts automatically and handles package communications.

  1. Create symlink:
   sudo ln -s /var/lib/snapd/snap /snap

This creates a symbolic link, making Snap packages accessible in standard system paths.

  1. Install NordVPN:
   sudo snap install nordvpn

This downloads and installs the NordVPN snap, bundling the client, daemon, and GUI.

  1. Group and permissions:
   sudo groupadd nordvpn
   sudo usermod -aG nordvpn walker

These add a group for NordVPN and include your user in it, allowing secure daemon access.

   sudo snap connect nordvpn:network-control

(And similar for other interfaces like network-observe, firewall-control, etc.) These grant the snap permissions to manage network and firewall settings.

  1. Login:
   nordvpn login

This initiates authentication, providing a URL to log in via browser.

  1. Connect:
   nordvpn connect United_Kingdom

This establishes a VPN tunnel to a UK server.

Problems Encountered

  • PATH issues: nordvpn commands were not found until sourcing /etc/profile.d/snapd.sh manually.
  • Snap confinement errors: AppArmor not enabled caused snap-confine refusals, blocking CLI and GUI after reboots.
  • DNS conflicts: Connections failed until restarting systemd-resolved, but reboots led to “limited connection” on the hotspot.
  • GUI unreliability: Icon appeared but would not launch or respond post-reboot.

The installation initially seemed successful, with stable connections and 340 Mbps speeds, but reboots exposed fragility, breaking internet access and indirectly affecting rclone mounts due to DNS disruptions.

Lessons Learned

  • Snap packages can introduce confinement issues on Arch-based systems like BigLinux, where AppArmor is not standard.
  • Reboots are essential for testing endurance, revealing hidden state problems in network managers.
  • Manual PATH sourcing and service restarts are workarounds, not solutions, signalling an unsuitable method.
  • DNS resolvers (systemd-resolved) can clash with VPN daemons, causing “limited connection” symptoms that mimic hotspot failures.
  • rclone is sensitive to DNS interruptions; always test it after changes.
  • Avoid snap for critical tools on non-Ubuntu distributions; native AUR packages are more reliable.

This attempt was abandoned and uninstalled via sudo snap remove nordvpn, restoring normal operation.

Rationale for the Second Attempt and Method

The second installation shifted to the AUR package nordvpn-bin, a native binary build tailored for Arch/Manjaro systems. This avoided Snap’s confinement and AppArmor dependencies, which caused the first failure. The AUR method uses pacman-like integration, placing binaries in standard paths (/usr/bin) for better compatibility with BigLinux’s KDE environment.

Rationale:

  • Native packages minimise dependency conflicts and eliminate PATH quirks.
  • AUR is community-vetted for Arch derivatives, with frequent updates to match NordVPN’s backend changes.
  • It separates daemon from GUI, allowing modular installation and easier troubleshooting.
  • Focus on manual testing post-install to ensure endurance, starting with idle daemon to protect rclone/hotspot.
  • Reversible: uninstall via yay -Rns nordvpn-bin returns to baseline in seconds.

This approach prioritised stability over convenience, drawing from the first attempt’s lessons on reboots and DNS. After the full clear out of the first installation:

Key Steps and Code

  1. Install nordvpn-bin:
   yay -S nordvpn-bin

This fetches, builds, and installs the binary client from the AUR, including daemon and CLI.

  1. Enable daemon:
   sudo systemctl enable --now nordvpnd

This starts the background service for NordVPN and sets it to launch on boot, but keeps it idle.

  1. Add group:
   sudo gpasswd -a [Linux username]  nordvpn

This adds your user to the NordVPN group for permission to control the daemon.

  1. Reboot:
   reboot

This applies group changes system-wide.

  1. Login:
   nordvpn login

This initiates browser authentication.

  1. Set kill switch:
   nordvpn set killswitch on

This configures the safety block for traffic if the VPN drops.

  1. Set protocol:
   nordvpn set technology nordlynx

This selects the WireGuard-based protocol for speed.

  1. Connect:
   nordvpn connect United_Kingdom

This establishes the tunnel to a UK server.

Detail of Testing

Testing emphasised incremental checks, reboots, and verification of rclone/hotspot stability.

Baseline Verification

  • Ping:
  ping -c 4 8.8.8.8

This sends packets to Google’s DNS to test basic connectivity; success showed stable hotspot.

  • IP check:
  curl ifconfig.me

This fetches your public IP; confirmed Three hotspot address.

  • rclone test:
  rclone ls onedrive:

This lists OneDrive files; confirmed access without issues.

Post-Install Testing

  • Daemon status after install:
  systemctl status nordvpnd

This checks the service is running; output confirmed active and no errors.

  • Group confirmation:
  groups

This lists user groups; verified nordvpn included.

  • Login confirmation:
  nordvpn account

This displays account details; confirmed active subscription.

  • Settings check:
  nordvpn settings

This lists configurations; verified kill switch enabled and NordLynx set.

  • Connect test:
  nordvpn connect Manchester

This connects to a specific city; success showed UK IP and 330 Mbps speeds.

  • Status:
  nordvpn status

This shows connection details; confirmed server, IP, protocol, and uptime.

  • IP verification:
  curl ifconfig.me

This confirmed NordVPN exit IP.

  • Reboot endurance:
    Multiple restarts tested daemon persistence; tray icon appeared white (idle), requiring manual Quick Connect for full access.
  • Disconnect test:
  nordvpn disconnect

This drops the tunnel; led to limited connection, resolved by hotspot reconnect.

Rclone remained functional throughout, with no DNS interruptions during connects.

GUI Installation and Testing

The GUI was added to provide visual control, as the AUR nordvpn-bin is CLI-focused. nordvpn-gui-bin was installed for binary simplicity.

Key Steps and Code

  1. Install GUI:
  yay -S nordvpn-gui-bin

This fetches and installs the graphical frontend from AUR.

Testing

  • Launch:
    Search menu for “NordVPN” and open; window appeared with settings, server list, and connect button.
  • Protocol options:
    Settings showed NordLynx selected, with alternatives like OpenVPN (TCP/UDP).
  • Connect:
    Used Quick Connect; icon turned blue, status showed connected to Manchester with NordLynx.
  • Disconnect:
    From GUI; led to limited connection, resolved by hotspot reconnect.
  • Reboot behaviour:
    Post-reboot, GUI launched from menu; showed disconnected state, allowing manual connect.
  • Stability:
    Survived multiple restarts; GUI provided more options than tray icon, but auto-connect remained off to avoid boot issues.

The GUI enhanced usability without altering core fragility around hotspot leases, which requires manual intervention after disconnects.

Outcome

The NordVPN works. I now have a GUI. I can use it if and when for CPanel access. I tested it with CPanel in my browser. No more logouts and weird messages.