For
Snowflake to report unrestricted, inbound UDP must be able to
reach the proxy. One approach is to give Snowflake a defined UDP
range with -ephemeral-ports-range and then allow/forward
that same range through both the host firewall and the router.
It
is recommended either forwarding an appropriate UDP port range
to the proxy or placing the host outside NAT. Roger gives -ephemeral-ports-range
40000:45000 with the same UDP range
allowed as a working setup:
https://forum.torproject.org/t/tor-relays-running-a-snowflake-bridge-on-debain/20644
If there is double NAT, the forwarding has to work through every NAT layer. If the ISP is using CGNAT, unrestricted IPv4 may not be possible without a public IPv4 address.
On 8/25/26 03:02, Mike Dylan Poppelaars via tor-relays wrote:
One thing to check is the NAT type reported in the log. unrestricted is preferable; a restrictive NAT can limit which clients can connect. Snowflake does not require a fixed forwarded port, but firewall/NAT settings can still affect WebRTC connectivity.
The tor-snowflake log shows "NAT type: restricted" but so far I have not been able to determine what router, firewall, i[tables or nftables settings or combination of settings will allow for unrestricted NAT.
Attachment:
OpenPGP_0x3FCEC2778F5A302A.asc
Description: OpenPGP public key
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx