如何控制Tor出口中继访问权限及解决中继与网桥共存问题
Hey there, let's break down your two Tor relay-related issues step by step—first fixing the iptables access control that's not working, then addressing why you can't run an exit relay and bridge at the same time.
First, let's figure out why your iptables rules aren't taking effect. Common culprits include incorrect rule ordering, targeting the wrong ports, or conflicting firewall tools overriding your rules. Here's how to fix it:
- Confirm Tor's listening ports: Check your
torrcfile (usually at/etc/tor/torrc) for theORPort(default 9001) andDirPort(default 9030) values—these are the ports other Tor nodes connect to. Make sure your rules target these exact ports. - Use the correct rule order: Iptables processes rules top to bottom, so allow rules must come before deny rules (otherwise you'll block the traffic you want to allow first). Here's a working rule set example:
# Allow loopback connections (critical for Tor's internal operations) iptables -A INPUT -i lo -j ACCEPT # Allow established/related connections (so Tor can respond to traffic it initiated) iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT # Allow your specified IP to access ORPort iptables -A INPUT -p tcp --dport 9001 -s YOUR_ALLOWED_IP/32 -j ACCEPT # Allow your specified IP to access DirPort iptables -A INPUT -p tcp --dport 9030 -s YOUR_ALLOWED_IP/32 -j ACCEPT # Block all other traffic to Tor's relay ports iptables -A INPUT -p tcp --dport 9001 -j DROP iptables -A INPUT -p tcp --dport 9030 -j DROP - Save your rules to persist after reboot: On Ubuntu 16.04, run
iptables-save > /etc/iptables/rules.v4to save your rules so they don't vanish after a system restart. - Check for conflicting firewalls: If you're using ufw, it might be overriding your iptables rules. Either configure access control through ufw instead, or stop ufw temporarily with
systemctl stop ufwand test your iptables rules again.
You're spot-on—you can't run an exit relay and bridge in the same Tor instance because they're mutually exclusive roles: an exit relay is a public, listed node, while a bridge is a private, unlisted node designed to bypass censorship. They require different listening ports, data directories, and core configuration settings.
The solution is to run two separate Tor instances, each with its own isolated configuration:
- Create a dedicated bridge configuration file: Copy your existing
torrcto a new file (e.g.,/etc/tor/tor-bridge.conf) and modify these key settings to avoid conflicts:# Enable bridge mode BridgeRelay 1 # Use a different ORPort than your exit relay ORPort 9002 # Use a different DirPort than your exit relay DirPort 9031 # Use a unique data directory to prevent database conflicts DataDirectory /var/lib/tor-bridge # Give your bridge a unique nickname Nickname MyPrivateBridge - Start the bridge instance: Run
tor -f /etc/tor/tor-bridge.confto launch the bridge. You can verify it's running withps aux | grep tor. - Set up auto-start for the bridge: Create a systemd service file at
/etc/systemd/system/tor-bridge.servicewith this content:
Then enable and start the service to make it run on boot:[Unit] Description=Tor Bridge Relay After=network.target [Service] User=debian-tor Type=simple ExecStart=/usr/bin/tor -f /etc/tor/tor-bridge.conf Restart=on-failure [Install] WantedBy=multi-user.targetsystemctl enable tor-bridge.service systemctl start tor-bridge.service
Now you'll have two independent Tor processes running: one as your public exit relay, and the other as a private bridge.
内容的提问来源于stack exchange,提问作者jonny

