README: document raw-upstream egress lock (:1080 restricted to CT158)
This commit is contained in:
13
README.md
13
README.md
@@ -71,6 +71,19 @@ the subscription must exist, be **active**, and **not expired**. The subscriptio
|
|||||||
selects the upstream exit. Unknown user, wrong password, expired sub, or wrong auth method →
|
selects the upstream exit. Unknown user, wrong password, expired sub, or wrong auth method →
|
||||||
rejected; no traffic leaves. All time comparisons are **UTC**.
|
rejected; no traffic leaves. All time comparisons are **UTC**.
|
||||||
|
|
||||||
|
### Raw upstream egress lock
|
||||||
|
|
||||||
|
The Nord `:1080` exits are LAN-only "dumb relays" with no auth by design. To stop
|
||||||
|
tailnet nodes (100.64/10), the VPN tunnel (tun0), and other LAN hosts from using them for
|
||||||
|
free, each Nord CT (680/681/682) restricts `:1080` to the Rigel frontend (CT158, `.116`) +
|
||||||
|
loopback. Rule lives in `/etc/network/if-up.d/rigel-egress-lock` (persists across reboot,
|
||||||
|
same hook mechanism as the Nord killswitch). Re-apply or inspect with:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
sh /etc/network/if-up.d/rigel-egress-lock
|
||||||
|
iptables -S INPUT | grep 1080
|
||||||
|
```
|
||||||
|
|
||||||
## Deploy
|
## Deploy
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
|
|||||||
Reference in New Issue
Block a user