chiark / gitweb /
vampire: Add accounting rules for Tor on the OUTPUT chain.
[firewall] / vampire.m4
index 450bdfff60598110b518add2a5678b4abbf70e55..13e37bd6477ea550b2ec6054c6ac8bcdae396a8a 100644 (file)
@@ -72,6 +72,10 @@ run iptables -A inbound -j ACCEPT \
        -s 172.29.198.0/24 \
        -p tcp --destination-port $port_squid
 
+## Watch outgoing Tor usage.
+run iptables -A OUTPUT -m multiport \
+       -p tcp --source-ports $port_tor_public,$port_tor_directory
+
 ## Other interesting things.
 dnsresolver inbound
 ntpclient inbound 158.152.1.76 158.152.1.204 194.159.253.2