Opened 16 months ago

Last modified 4 months ago

#21397 new enhancement

Tor TransparentProxy documentation: add IPv6 support / port to nftables

Reported by: adrelanos Owned by:
Priority: Medium Milestone: Tor: unspecified
Component: Core Tor/Tor Version:
Severity: Normal Keywords: tor-doc wiki nftables ipv6 transproxy tor-client
Cc: whonix-devel@…, iry Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Child Tickets

Change History (6)

comment:1 Changed 15 months ago by nickm

Please say more about nftables and the lack of ipv6 support?

comment:2 Changed 15 months ago by nickm

Milestone: Tor: unspecified

comment:3 Changed 15 months ago by adrelanos

The wiki page https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy as of version https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy?version=111 is only using iptables. It does not cover IPv6 yet (then it would have to also use at minimum ip6tables). Therefore transparent proxying IPv6 traffic won't work. Also it's only using IPv4 torrc options, nothing about IPv6. Due to that wiki page being outdated, in best case, it just won't work, in worst case, IPv6 leaks.

nftables replaces iptables, ip6tables etc. While modernizing that page, it might be a great idea to port it to nftables.

comment:4 Changed 15 months ago by teor

Keywords: doc wiki added

comment:5 Changed 11 months ago by nickm

Keywords: tor-doc nftables ipv6 transproxy tor-client added; doc removed

I'd take a patch for this if there are issues in the code or shipped documentation; but in the meantime, somebody who uses transproxy and ipv6 a lot should revise that wiki page.

comment:6 Changed 4 months ago by iry

Cc: iry added
Note: See TracTickets for help on using tickets.