Advertisement
actual-batman

LXC tor transproxy config

Oct 31st, 2016
42
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 1.75 KB | None | 0 0
  1. # Transparent tor proxy lxc bridge
  2. auto torbr0
  3. allow-hotplug torbr0
  4. iface torbr0 inet static
  5.         bridge_ports none
  6.         bridge_stp off
  7.         bridge_fd 5
  8.         bridge_maxwait 0
  9.         address 10.0.4.1
  10.         netmask 255.255.255.0
  11.         broadcast 10.0.4.255
  12.         network 10.0.4.0
  13.         up systemctl start tor
  14.         up iptables -t nat -A PREROUTING -i torbr0 -p tcp -m tcp --dport 9050 -j ACCEPT
  15.         up iptables -t nat -A PREROUTING -i torbr0 -p tcp -m tcp --syn -j REDIRECT --to-ports 9040
  16.         up iptables -t nat -A PREROUTING -i torbr0 -p udp -m udp --dport 53 -j REDIRECT --to-ports 9053
  17.         up iptables -A INPUT -i torbr0 -m state --state ESTABLISHED,RELATED -j ACCEPT
  18.         up iptables -A INPUT -i torbr0 -p tcp -m tcp --dport 9040 -j ACCEPT
  19.         up iptables -A INPUT -i torbr0 -p tcp -m tcp --dport 9053 -j ACCEPT
  20.         up iptables -A INPUT -i torbr0 -p udp -m udp --dport 9053 -j ACCEPT
  21.         up iptables -A INPUT -i torbr0 -p tcp -m tcp --dport 9050 -j ACCEPT
  22.         down iptables -t nat -D PREROUTING -i torbr0 -p tcp -m tcp --dport 9050 -j ACCEPT
  23.         down iptables -t nat -D PREROUTING -i torbr0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j REDIRECT --to-ports 9040
  24.         down iptables -t nat -D PREROUTING -i torbr0 -p udp -m udp --dport 53 -j REDIRECT --to-ports 9053
  25.         down iptables -D INPUT -i torbr0 -m state --state ESTABLISHED,RELATED -j ACCEPT
  26.         down iptables -D INPUT -i torbr0 -p tcp -m tcp --dport 9040 -j ACCEPT
  27.         down iptables -D INPUT -i torbr0 -p tcp -m tcp --dport 9053 -j ACCEPT
  28.         down iptables -D INPUT -i torbr0 -p udp -m udp --dport 9053 -j ACCEPT
  29.         down iptables -D INPUT -i torbr0 -p tcp -m tcp --dport 9050 -j ACCEPT
  30.         down systemctl stop tor
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement