wiki:doc/ReducedExitPolicy

Version 4 (modified by mikeperry, 8 years ago) (diff)

Add Google Voice and Android Market

The Reduced Exit Policy is an alternative to the default exit policy. It allows as many Internet services as possible while still blocking the majority of TCP ports. Currently, the policy allows approximately 65 ports. This drastically reduces the odds that a bittorrent user will select your node.

Since bittorrent clients can be run on any port, and most of them pick random ports, every port you add to your exit policy increases the probability of a bittorrent client using your exit node to connect to a monitored peer that is listening on that port. This means that enabling ranges of ports is especially bad, unfortunately. Each new port adds 1/65535 to your risk of getting DMCA takedowns.

This policy has been produced by scanning /etc/services, and checking various port lists around the net. This list has been carefully checked to ensure that none of these ports overlap with popular default ports for bittorrent clients. If you add to this list, please check this carefully too.

Also, it would be great if someone could comment each line to list the services that it allows...

ExitPolicy accept *:20-23    # FTP, SSH, telnet
ExitPolicy accept *:43       # WHOIS
ExitPolicy accept *:53       # DNS
ExitPolicy accept *:79-81    # finger, HTTP
ExitPolicy accept *:88       # kerberos
ExitPolicy accept *:110      # POP3
ExitPolicy accept *:143      # IMAP
ExitPolicy accept *:194      # IRC
ExitPolicy accept *:220      # IMAP3
ExitPolicy accept *:443      # HTTPS
ExitPolicy accept *:464-465  # kpasswd, SMTP over SSL
ExitPolicy accept *:543-544   
ExitPolicy accept *:563      # NNTP over SSL
ExitPolicy accept *:587      # SMTP
ExitPolicy accept *:706      
ExitPolicy accept *:749      # kerberos 
ExitPolicy accept *:873      # rsync
ExitPolicy accept *:902-904
ExitPolicy accept *:981
ExitPolicy accept *:989-995  # FTP over SSL, Netnews Administration System, telnets, IMAP over SSL, ircs, POP3 over SSL
ExitPolicy accept *:1194     # openvpn
ExitPolicy accept *:1220     # QT Server Admin
ExitPolicy accept *:1293     # PKT-KRB-IPSec
ExitPolicy accept *:1500     # VLSI License Manager
ExitPolicy accept *:1723     # PPTP
ExitPolicy accept *:1863     # MSNP
ExitPolicy accept *:2082-2083 # Radius
ExitPolicy accept *:2086-2087 # GNUnet, ELI
ExitPolicy accept *:2095-2096 # NBX
ExitPolicy accept *:3128     # SQUID
ExitPolicy accept *:3389     # MS WBT
ExitPolicy accept *:3690     # SVN
ExitPolicy accept *:4321     # RWHOIS
ExitPolicy accept *:4643      
ExitPolicy accept *:5050     # MMCC
ExitPolicy accept *:5190     # ICQ
ExitPolicy accept *:5222-5223 # XMPP, XMPP over SSL
ExitPolicy accept *:5228     # Android Market
ExitPolicy accept *:5900     # VNC
ExitPolicy accept *:6666-6667 # IRC
ExitPolicy accept *:6679      
ExitPolicy accept *:6697      
ExitPolicy accept *:8000    # iRDMI
ExitPolicy accept *:8008    
ExitPolicy accept *:8080    # HTTP Proxies
ExitPolicy accept *:8087-8088 # Simplify Media SPP Protocol, Radan HTTP
ExitPolicy accept *:8443    # PCsync HTTPS
ExitPolicy accept *:8888    # HTTP Proxies, NewsEDGE
ExitPolicy accept *:9418    # git
ExitPolicy accept *:9999    # distinct
ExitPolicy accept *:10000   # Network Data Management Protocol
ExitPolicy accept *:19294   # Google Voice TCP
ExitPolicy accept *:19638   
ExitPolicy reject *:*