Skip to content

Egress Security Policy

full-bars edited this page Aug 15, 2026 · 2 revisions

Egress Security Policy (DPI)

The provider inspects egress and ingress packets against a layered security policy. This is deep-packet inspection (DPI). The provider looks past the IP header and into the transport payload to decide what may leave and enter the box.

A packet gets one of three verdicts (ip_security.go):

  • allow β€” the packet passes.
  • drop β€” the packet is discarded silently.
  • incident β€” the packet is dropped and the event is counted and reported.

The egress layers

Egress packets are checked in order. The first layer that makes a decision wins. The SMTP policy layer runs ahead of the general CFAA policy on all egress paths and at the provider ingress.

0. SMTP policy (ahead of CFAA)

The provider enforces an SMTP policy layer before the general policy runs (ip_smtp_policy.go). Plaintext SMTP and SMTP relay through the tunnel are blocked.

  • Port 25 routes locally before CFAA. It can never reach a provider.
  • Port 465 must begin with a TLS ClientHello. Plaintext is reset and dropped.
  • Port 587 permits only a bounded EHLO/HELO/QUIT/STARTTLS negotiation. Transaction and authentication commands are rejected until STARTTLS, which must be followed by a ClientHello.
  • The provider ingress applies the same rules, namespaced by the authenticated source.

Per-flow state is bounded at 1024 flows. Retransmissions are validated. Gaps and stream splices fail closed. Each rejection emits a TCP reset and a block counter entry.

Two fork divergences from upstream are documented in the code. The secure-phase sequence offset uses unsigned arithmetic, so TLS flows survive past 2 GiB. Flow-table eviction spares established secure flows, so a provider at the 1024-flow cap does not reset valid sessions.

1. CFAA endpoint reputation

The provider refuses to send traffic to known malicious or hijacked address space. It ships a packed blocklist of 64,131 IPv4 ranges and 214 IPv6 ranges (ip_security_cfaa_block.go). The ranges are aggregated from public threat-intelligence feeds.

The blocklist is consulted on the egress hot path. A destination in a blocked range is refused. The table is sorted and pairwise-disjoint, so the lookup is fast.

2. DMCA stateful inspection

The provider detects and drops BitTorrent traffic. The detector is stateful and covers all ports, not just the well-known ones (ip_security_dmca.go).

It recognizes the BitTorrent protocol family from the wire format:

  • BEP 3 peer-wire and HTTP tracker traffic.
  • BEP 5 DHT (KRPC).
  • BEP 15 UDP trackers.
  • BEP 29 uTP.

A positive plaintext BitTorrent signature is an incident: it is dropped and reported. An entropy-based encrypted-flow heuristic is the backstop for obfuscated BitTorrent. This covers MSE/PE over TCP and encrypted uTP over UDP.

3. Web-standard matcher

Legitimate encrypted traffic must not be mistaken for obfuscated BitTorrent. The web-standard matcher recognizes real TLS, QUIC, DTLS, and STUN from their byte signatures (ip_security_webstandard.go).

The matchers are clean-room implementations from the RFCs. They cover TLS RFC 8446 and 5246. They cover DTLS RFC 6347 and 9147. They cover QUIC RFC 9000 and 9369. They cover STUN RFC 5389. Recognized web-standard traffic is exempt from the encrypted-flow heuristic, so a normal HTTPS connection is never flagged.

The ingress check

Ingress mirrors the CFAA source-endpoint check. A packet arriving from a known malicious source range is refused before it can reach the relay path.

Why this matters

The policy answers a real liability question for every operator. What traffic does this box carry? What does it refuse?

  • The CFAA layer keeps the provider from becoming a relay for traffic to malicious or hijacked infrastructure.
  • The DMCA layer keeps the provider from being a BitTorrent carrier. That is the fastest way to draw abuse complaints.
  • The web-standard matcher protects legitimate encrypted traffic. The traffic the provider exists to carry is never collateral damage.

Operators cannot tune the individual detectors at runtime. The blocklist is regenerated at build time from the threat feeds. The policy is compiled in, which means it cannot be misconfigured away.

Related

  • Proxy Admission Pipeline β€” how the provider verifies proxies before admitting them.
  • FORK_CHANGES entry 60 β€” the design detail behind the DPI layers.

Clone this wiki locally