Should I switch my guards to exits?
Background: At the time, our AS was generating ~25% of the exit traffic. I then configured one server with 40 exit relays and another with 40 guard relays. We are now only generating ~16%. https://nusenu.github.io/OrNetStats/#autonomous-systems-by-cw-fraction It’s actually a real shame that the abuse-resistant IPs¹ don't handle exit traffic. In addition, my exit policy is very open. reject *:25 accept *:* ¹f#ck y all > /dev/nulll -- ╰_╯ Ciao Marco! Debian GNU/Linux It's free software and it gives you freedom!
Am 12.09.26 um 19:54 schrieb boldsuck via tor-relays:
At the time, our AS was generating ~25% of the exit traffic. I then configured one server with 40 exit relays and another with 40 guard relays.
Is there any problem with that? I know that it would be much better if exits were more distributed, but exit bandwidth is much more limited than entry/middle node bandwidth. -- Gruß Marco Junk-Mail bitte an trashcan@stinkedores.dorfdsl.de
On Wednesday, 16 September 2026 17:58:52 CEST Marco Moock via tor-relays wrote:
Is there any problem with that?
I don't fully grasp the voodoo behind consensus weight and circuit selection, but the fact that all the relays are in the same /16 subnet plays a role. I believe that adding more Tor exit instances to our AS won't increase our CW or traffic volume. And when I see the current attacks against (Hidden)Onion-Services that are forcing some guards to their knees, stable guards are also needed. With the planned 2-week C-tor release cycle, HSDir's are in for some really tough times. ;-) Background: Why niftybunny split up his AS and servers back then https://gitlab.torproject.org/tpo/core/tor/-/work_items/40007
I know that it would be much better if exits were more distributed, but exit bandwidth is much more limited than entry/middle node bandwidth.
There's plenty of bandwidth available¹ Advertised and consumed bandwidth of relay: https://metrics.torproject.org/bandwidth-flags.html ¹Especially in our rack or AS. Multiple machines with 2x10G or 2x25G that do the 'R' in tor. net.ipv4.conf.default.forwarding=1 # be a router and fwd v4 packets net.ipv4.conf.all.forwarding=1 # be a router and fwd v4 packets net.ipv6.conf.default.forwarding=1 # be a router and fwd v6 packets net.ipv6.conf.all.forwarding=1 # be a router and fwd v6 packets -- ╰_╯ Ciao Marco! Debian GNU/Linux It's free software and it gives you freedom!
participants (2)
-
boldsuck -
Marco Moock