[tor-dev] How to build a Router that will only allow Tor users

Martin Kepplinger martink at posteo.de
Tue Mar 15 17:11:21 UTC 2016


Am 2016-03-15 um 18:10 schrieb Tom Ritter:
> On 15 March 2016 at 10:52, Martin Kepplinger <martink at posteo.de> wrote:
>> Hi,
>>
>> I try to configure OpenWRT in a way that it will only allow outgoing
>> connections if it is Tor. Basically it is the opposite of "blacklisting
>> exit relays on servers": "whitelisting (guard) relays for clients". It
>> should *not* run Tor itself.
>>
>> A first test setup (onionoo document, ipset and iptables) kind of
>> worked. It's definitely doable, but not totally trivial in the end.
>>
>> What did *not* work, was starting Torbrowser. That's a hard requirement,
>> and before bebugging it through I ask: Do I miss something when I just
>> allow outgoing connections to
>>
>>  * Guard,
>>  * Authority,
>>  * and HSDir flagged relays (do I *need* them? that's a different
>> question probably)
> 
> Well it won't work with bridges obviously, including the hardcoded
> ones in TBB...
> 
> -tom

Yes, that's fine. Let's just ignore bridges too for a proof of concept ;)



More information about the tor-dev mailing list