Opened 4 years ago

Last modified 10 months ago

#21397 new enhancement

Tor TransparentProxy documentation: add IPv6 support / port to nftables

Reported by: adrelanos Owned by:
Priority: Medium Milestone: Tor: unspecified
Component: Core Tor/Tor Version:
Severity: Normal Keywords: tor-doc wiki nftables ipv6 transproxy tor-client
Cc: whonix-devel@…, iry Actual Points:
Parent ID: Points:
Reviewer: Sponsor:


Child Tickets

Change History (7)

comment:1 Changed 3 years ago by nickm

Please say more about nftables and the lack of ipv6 support?

comment:2 Changed 3 years ago by nickm

Milestone: Tor: unspecified

comment:3 Changed 3 years ago by adrelanos

The wiki page as of version is only using iptables. It does not cover IPv6 yet (then it would have to also use at minimum ip6tables). Therefore transparent proxying IPv6 traffic won't work. Also it's only using IPv4 torrc options, nothing about IPv6. Due to that wiki page being outdated, in best case, it just won't work, in worst case, IPv6 leaks.

nftables replaces iptables, ip6tables etc. While modernizing that page, it might be a great idea to port it to nftables.

comment:4 Changed 3 years ago by teor

Keywords: doc wiki added

comment:5 Changed 3 years ago by nickm

Keywords: tor-doc nftables ipv6 transproxy tor-client added; doc removed

I'd take a patch for this if there are issues in the code or shipped documentation; but in the meantime, somebody who uses transproxy and ipv6 a lot should revise that wiki page.

comment:6 Changed 3 years ago by iry

Cc: iry added

comment:7 Changed 10 months ago by NonaSuomy

Added nftables ruleset to the wiki from duclicsic on #netfilter freenode.

Last edited 10 months ago by NonaSuomy (previous) (diff)
Note: See TracTickets for help on using tickets.