From 3d6d1de74ff1d63a51cbd882b46b3f8e923d7bce Mon Sep 17 00:00:00 2001 From: drjones Date: Thu, 10 Sep 2026 01:48:52 -0700 Subject: [PATCH] README: document raw-upstream egress lock (:1080 restricted to CT158) --- README.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/README.md b/README.md index 12bb791..77bf704 100644 --- a/README.md +++ b/README.md @@ -71,6 +71,19 @@ the subscription must exist, be **active**, and **not expired**. The subscriptio selects the upstream exit. Unknown user, wrong password, expired sub, or wrong auth method → rejected; no traffic leaves. All time comparisons are **UTC**. +### Raw upstream egress lock + +The Nord `:1080` exits are LAN-only "dumb relays" with no auth by design. To stop +tailnet nodes (100.64/10), the VPN tunnel (tun0), and other LAN hosts from using them for +free, each Nord CT (680/681/682) restricts `:1080` to the Rigel frontend (CT158, `.116`) + +loopback. Rule lives in `/etc/network/if-up.d/rigel-egress-lock` (persists across reboot, +same hook mechanism as the Nord killswitch). Re-apply or inspect with: + +```sh +sh /etc/network/if-up.d/rigel-egress-lock +iptables -S INPUT | grep 1080 +``` + ## Deploy ```sh