tor-fw-helper-spec.txt 1.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344
  1. Tor's (little) Firewall Helper specification
  2. Jacob Appelbaum
  3. 0. Preface
  4. This document describes issues faced by Tor users who are behind NAT devices
  5. and wish to share their resources with the rest of the Tor network. It also
  6. explains a possible solution for some NAT devices.
  7. 1. Overview
  8. Tor users often wish to relay traffic for the Tor network and their upstream
  9. firewall thwarts their attempted generosity. Automatic port forwarding
  10. configuration for many consumer NAT devices is often available with two common
  11. protocols NAT-PMP[0] and UPnP[1].
  12. 2. Implementation
  13. tor-fw-helper is a program that implements basic port forwarding requests; it
  14. may be used alone or called from Tor itself.
  15. 2.1 Output format
  16. When tor-fw-helper has completed the requested action successfully, it will
  17. report the following message to standard output:
  18. tor-fw-helper: SUCCESS
  19. If tor-fw-helper was unable to complete the requested action successfully, it
  20. will report the following message to standard error:
  21. tor-fw-helper: FAILURE
  22. All informational messages are printed to standard output; all error messages
  23. are printed to standard error.
  24. 3. Security Concerns
  25. It is probably best to hand configure port forwarding and in the process, we
  26. suggest disabling NAT-PMP and/or UPnP.
  27. [0] http://en.wikipedia.org/wiki/NAT_Port_Mapping_Protocol
  28. [1] http://en.wikipedia.org/wiki/Universal_Plug_and_Play