README: document raw-upstream egress lock (:1080 restricted to CT158)

This commit is contained in:
drjones
2026-09-10 01:48:52 -07:00
parent 5015c47ee3
commit 3d6d1de74f

View File

@@ -71,6 +71,19 @@ the subscription must exist, be **active**, and **not expired**. The subscriptio
selects the upstream exit. Unknown user, wrong password, expired sub, or wrong auth method →
rejected; no traffic leaves. All time comparisons are **UTC**.
### Raw upstream egress lock
The Nord `:1080` exits are LAN-only "dumb relays" with no auth by design. To stop
tailnet nodes (100.64/10), the VPN tunnel (tun0), and other LAN hosts from using them for
free, each Nord CT (680/681/682) restricts `:1080` to the Rigel frontend (CT158, `.116`) +
loopback. Rule lives in `/etc/network/if-up.d/rigel-egress-lock` (persists across reboot,
same hook mechanism as the Nord killswitch). Re-apply or inspect with:
```sh
sh /etc/network/if-up.d/rigel-egress-lock
iptables -S INPUT | grep 1080
```
## Deploy
```sh