vampire: Add accounting rules for Tor on the OUTPUT chain.
authorMark Wooding <mdw@distorted.org.uk>
Tue, 13 Jan 2009 18:11:39 +0000 (18:11 +0000)
committerMark Wooding <mdw@distorted.org.uk>
Tue, 13 Jan 2009 18:11:39 +0000 (18:11 +0000)
This will tell me what I actually wanted to know.

vampire.m4

index 450bdff..13e37bd 100644 (file)
@@ -72,6 +72,10 @@ run iptables -A inbound -j ACCEPT \
        -s 172.29.198.0/24 \
        -p tcp --destination-port $port_squid
 
+## Watch outgoing Tor usage.
+run iptables -A OUTPUT -m multiport \
+       -p tcp --source-ports $port_tor_public,$port_tor_directory
+
 ## Other interesting things.
 dnsresolver inbound
 ntpclient inbound 158.152.1.76 158.152.1.204 194.159.253.2