[Tor-BSD] TransProxyType pf-divert on local machine

Shawn Webb shawn.webb at hardenedbsd.org
Thu Jan 11 10:15:27 EST 2018


On Thu, Jan 11, 2018 at 04:37:03AM +0000, clematis wrote:
> On Thu, Jan 11, 2018 at 01:39:53PM +1100, teor wrote:
> > There have been bugs the TransProxy tor code in the past. You might have
> > found another one! Let us know if you work out that the bug is in tor.
> > 
> > We have also had trouble finding people to test it when we've done fixes.
> > (I don't know enough to help with the specific setup, sorry!)
> > 
> > T
> 
> Hi Teor,
> Thanks for your reply. OK I will get some more verbose logs and look at
> what's going on.
> 
> To everyone,
> How would you guys get pf to redirect all traffic to tor? What are the
> pf rules you use. (Even on multiple interface. (classic gateway setup))
> Just to have a reference point known to work.

Here's a little tutorial I wrote for transproxy setups:

https://github.com/lattera/articles/blob/master/infosec/tor/2017-01-14_torified_home/article.md

The bits at the beginning are specific to the RPI3, but further down,
it's agnostic of the hardware. All the config files (pf.conf, torrc,
rc.conf, etc.) don't care about what hardware it's deployed onto.

I'm not using divert-to style redirction, but rather rdr rules.

Thanks,

-- 
Shawn Webb
Cofounder and Security Engineer
HardenedBSD

Tor-ified Signal:    +1 443-546-8752
GPG Key ID:          0x6A84658F52456EEE
GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89  3D9E 6A84 658F 5245 6EEE
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.nycbug.org/pipermail/tor-bsd/attachments/20180111/72838f74/attachment.bin>


More information about the Tor-BSD mailing list