README: document raw-upstream egress lock (:1080 restricted to CT158)
This commit is contained in:
13
README.md
13
README.md
@@ -71,6 +71,19 @@ the subscription must exist, be **active**, and **not expired**. The subscriptio
|
||||
selects the upstream exit. Unknown user, wrong password, expired sub, or wrong auth method →
|
||||
rejected; no traffic leaves. All time comparisons are **UTC**.
|
||||
|
||||
### Raw upstream egress lock
|
||||
|
||||
The Nord `:1080` exits are LAN-only "dumb relays" with no auth by design. To stop
|
||||
tailnet nodes (100.64/10), the VPN tunnel (tun0), and other LAN hosts from using them for
|
||||
free, each Nord CT (680/681/682) restricts `:1080` to the Rigel frontend (CT158, `.116`) +
|
||||
loopback. Rule lives in `/etc/network/if-up.d/rigel-egress-lock` (persists across reboot,
|
||||
same hook mechanism as the Nord killswitch). Re-apply or inspect with:
|
||||
|
||||
```sh
|
||||
sh /etc/network/if-up.d/rigel-egress-lock
|
||||
iptables -S INPUT | grep 1080
|
||||
```
|
||||
|
||||
## Deploy
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user