Hi,Maybe someone else has better ideas for this issue because I don't anymore. What is possible is that the snap package doesn't support adding the -ephemeral-ports-range flag. Or maybe it's really just the NAT behavior of your router.
Best, Mike On 25.08.2026 21:51, John Thompson via tor-relays wrote:
On 8/25/26 10:35, Mike Dylan Poppelaars via tor-relays wrote:For Snowflake to report unrestricted, inbound UDP must be able to reach the proxy. One approach is to give Snowflake a defined UDP range with - ephemeral-ports-range and then allow/forward that same range through both the host firewall and the router.It is recommended either forwarding an appropriate UDP port range to the proxy or placing the host outside NAT. Roger gives -ephemeral- ports- range 40000:45000 with the same UDP range allowed as a working setup:Thanks. It isn't clear to me which tor-snowflake config file needs to be modified. I added "-ephemeral-ports-range 40000:45000" to the "ExecStart" line in /etc/systemd/system/snap.tor- snowflake.snowflake.service, ran "systemctl reload-daemon", ran "sudo snap restart tor-snowflake", opened ports 40000-45000 in the firewall, restarted firewalld, opened ports 40000-45000 UDP on the router to be forwarded to the snowflake machine, but it hasn't made a difference. NAT is still reported as "restricted."
Attachment:
OpenPGP_0x3FCEC2778F5A302A.asc
Description: OpenPGP public key
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx