[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: If the IPv6 ORPort can't be reached, will clients/relays fall back to the IPv4 ORPort?



Hi forest,

Yeah, I think your concern is valid.

Looking at the current ipv6-rules.sh, some known provider ranges are grouped by /64 or /80, while anything outside those ranges is handled as /128. Even with /64 grouping, someone with a routed /48 still has a huge number of prefixes to rotate through.

So the current limits can still be worked around by changing prefixes. A global IPv6 cap could help protect the relay, but without fallback it would also block legitimate IPv6 users once the cap is hit.

Wider prefix limits or a global emergency cap might help, but both risk blocking innocent users too. This looks like a real IPv6 limitation in the current rules.

Cheers,
rE-Bo0t.bx1
https://relays.brokenbotnet.com


On 7/21/26 9:52 AM, forest-relay-contact--- via tor-relays wrote:
Hello.

rE-Bo0t.bx1 wrote:
> Short answer: no, Tor doesn't do Happy Eyeballs for OR connections.
> Whatever address family gets picked for a connection attempt is what
> gets tried, and if it fails, that's it for that attempt. Tor won't turn
> around and retry the same relay over IPv4. A later circuit attempt may
> try again or choose another path, but that's separate, not a fallback.

The reason I ask is because I'm considering implications of the toralf
tor-ddos script on relays that use IPv6. By its very design, there are a
number of hosting providers that will provide, say, a routed /48 for a
low cost which could then be used to completely overwhelm the IPv6 anti-
DDoS firewall rules (unlike the IPv4 rules where an attacker would need
to buy a costly new IPv4 just to get an additional 8 connections).

If a hard limit for the number of simultaneous IPv6 connections were set,
then that would force the attacker to fall back to IPv4 long before the
relay is actually overwhelmed, but that would also prevent anyone else
from connecting with IPv6. If connections fell back to IPv4 after failure
to connect with IPv6, it could be a solution. It's unfortunate they don't.

As it is, it seems like the anti-DDoS script and firewall rules are only
effective on dual-stack relays so long as no attacker figures out that
there are plenty of routed IPv6 netblocks that they can cheaply use.

Regards,
forest
> _______________________________________________ > tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx > To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx

Attachment: OpenPGP_0xB3BD6196E1CFBFB4.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx