[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: iptables and tor
- To: or-talk@xxxxxxxxxxxxx
- Subject: Re: iptables and tor
- From: Tom Hek <tomtorexitnode@xxxxxxxxx>
- Date: Sun, 10 Feb 2008 23:10:29 +0100
- Delivered-to: archiver@xxxxxxxx
- Delivered-to: or-talk-outgoing@xxxxxxxx
- Delivered-to: or-talk@xxxxxxxx
- Delivery-date: Sun, 10 Feb 2008 17:10:42 -0500
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; bh=JsTXmvpOA4WjWEMCcA7pAKDlecIGRI0jjCorvwou4XU=; b=gfre7WRx8KczkBjhEqXAnSpIEgqLtYsTLbczT7Z9fg5EGV9EZJF2Q5FMKZaZCEiwLqxpnVXX5l8fmlEKiy2mF+u6EJCtmaGYL7XydrSO415PlepnEwBbwBP5/zXCDn4Ek5qylLkxfP8rskxsINAYuotpNtbHmXOwkVtGFKEq+KU=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; b=TSM6tRVpr0nbRaIEO/S4klMbzdnqc2enim9O7gxYhCkcZbd70+zTbJjslXMYTpSImb5p0E8Jizv4t5IfqbUBHTbore+2exzH60V0GUf/Me8PkyRDqJZvK4ksNc8CG+OP8xARRCvXEZlRB8E3d1jnwNa1nzBUYShfqYHw4l1tLAc=
- In-reply-to: <47AF756B.5030502@xxxxxx>
- References: <47AE403E.6070805@xxxxxxxxxxxxxxxxxxx> <47AF756B.5030502@xxxxxx>
- Reply-to: or-talk@xxxxxxxxxxxxx
- Sender: owner-or-talk@xxxxxxxxxxxxx
- User-agent: Thunderbird 2.0.0.9 (Macintosh/20071031)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
By default are all the private ranges already blocked in the exitpolicy.
Dominik Schaefer wrote:
> dante schrieb:
>> Hi everyone,
>>
>> Has anyone given any thought as to what firewall rules to use on a linux
>> system running a tor server?
> If you operate a tor node within your private network und your network
> offers
> services which are not public or should not be public, then you should
> remember that you create a tunnel in your local network by running tor. In
> this case you have to ensure that the exit policies of the tor node are
> set in
> a way that nobody can exit from your tor node into you local net.
> Additionally you can filter the relevant traffic originating from your
> tor node.
>
>
> Dominik
>
>
>
>
Tom
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iEYEARECAAYFAkevdlUACgkQStmJ9+mkUHNdxwCeOjcYGMgP8vrmaKGTZIRx/7nh
EqQAn1pfvH7X8+1f1QhcOPE0CfGKCKAG
=7f0e
-----END PGP SIGNATURE-----