Exit nodes
An exit node is a device in the private network that forwards other
devices’ internet traffic, so it leaves from the exit’s address. With the
towonel CLI, both sides need Linux, root or CAP_NET_ADMIN, and the
towonel0 interface.
Exit nodes are off by default. The hub operator turns them on with
TOWONEL_HUB_MESH_EXIT_NODES_ENABLED=true. The managed service keeps them
off.
Exit nodes are for your own devices and the people you give access to. Offering one as a public or anonymizing proxy is against the community guidelines.
Offer a device as an exit
Section titled “Offer a device as an exit”sudo towonel mesh up --advertise-exit-nodeThis needs the nft tool. It turns on IPv4 and IPv6 forwarding and adds
an nftables table named towonel that masquerades traffic leaving the
tunnel. The table is removed when mesh up stops; forwarding stays on.
The device then shows offers exit in the console. A member of the tunnel approves it under Private network. Approving lets the devices your policy allows send their internet traffic through it, and the exit can see where that traffic goes.
Running mesh up without --advertise-exit-node withdraws the offer;
stopping mesh up doesn’t. Once the offer is withdrawn, the approval is
kept for 7 days; after that, offering again needs a new approval.
Use an exit
Section titled “Use an exit”sudo towonel mesh up --exit-node vps-parisThis needs the ip tool. Traffic that would have used your default route
goes to the exit. Everything else stays direct, including your local
network, so printers and NAS boxes keep working. The exit only forwards
to public addresses: it doesn’t give access to its own LAN.
A device can’t offer an exit and use one at the same time.
Internet traffic only goes to the exit over a direct connection, never through the relay. While the exit is only reachable through the relay, that traffic is held back.
Who can use an exit
Section titled “Who can use an exit”Without a custom policy, a device can use an approved exit if it can reach
that device. With a custom policy, add a rule with internet in to:
{ "from": ["*"], "to": ["internet"] }* doesn’t include internet, so existing rules never grant it by
accident.