diff --git a/docs/pfi/headscale-mesh-plan.md b/docs/pfi/headscale-mesh-plan.md index ec203c9..caae0c1 100644 --- a/docs/pfi/headscale-mesh-plan.md +++ b/docs/pfi/headscale-mesh-plan.md @@ -275,3 +275,24 @@ NH3↔colo, NH3↔ESH, colo↔ESH. FortiGate mgmt via WAN SSH OPEN; ana-wg WG fa State: **Site Magic disabled (UI); both IPsec tunnels dormant (UDM ends disabled, config retained); headscale is the sole active site-to-site transport.** Tunnels re-enablable for backup (Site Magic in UI; IPsec by flipping the UDM objects enabled=true). Goal met. + +## 2026-09-06 — exit nodes advertised (multi-location egress proxy) + +All three routers advertise + serve exit nodes; approved on headscale (each shows +`0.0.0.0/0` + `::/0` Serving). Clients see three: `nh3-scale` (100.64.0.1, NH3 residential +egress 70.230.226.88), `esh-scale` (100.64.0.2, ESH 23.164.40.160), `ana-scale` +(100.64.0.3, colo 38.120.12.42). + +⚠ **Design reversal:** exit nodes REQUIRE SNAT, so `--snat-subnet-routes` was flipped back to +**true** (NoSNAT=false) on all three routers — this undoes the earlier source-preserving +choice. Consequence: cross-site subnet-route traffic now appears to come from the local +router's IP, not the original host. Site-to-site re-verified OK after the flip. If per-host +source visibility is later needed, the alternative is NoSNAT + a manual selective masquerade +rule (`-s 100.64.0.0/10 ! -d 10.0.0.0/8 -o eth0 -j MASQUERADE`) on each router, made +persistent — not done. + +**Use one from a client:** `tailscale set --exit-node=nh3-scale` (or `esh-scale` / +`ana-scale`), `--exit-node=` to clear. A node that itself advertises an exit node cannot +consume one (so the routers can't be used to test egress; use the laptop/iPad). +Replaces the nh3-dev SOCKS5 residential-egress proxy — retire that once confirmed on real +clients. diff --git a/persistent-memory.d/2026-09-06-headscale-cutover.md b/persistent-memory.d/2026-09-06-headscale-cutover.md index 9ef093e..4850ef2 100644 --- a/persistent-memory.d/2026-09-06-headscale-cutover.md +++ b/persistent-memory.d/2026-09-06-headscale-cutover.md @@ -22,3 +22,12 @@ follow-ups in `docs/pfi/headscale-mesh-plan.md` § CUTOVER EXECUTED. Headlines: back. See [[incident_crowdsec_cgnat_false_ban]] (same day) and the plan doc. - Dormancy = disabled+retained (flip UDM object back to enabled=true to restore); NO auto failover wired. Bonus: exit nodes → free multi-location egress proxy (parked). + + +## Exit nodes (2026-09-06, operator-requested) +All three routers advertise+serve exit nodes (approved). Clients pick location: +`tailscale set --exit-node=nh3-scale|esh-scale|ana-scale`. NH3 = residential egress +(70.230.226.88) → replaces the nh3-dev SOCKS5 proxy. ⚠ Enabling exit nodes REQUIRED flipping +`--snat-subnet-routes=true` (reversed the source-preserving NoSNAT); cross-site traffic now +shows the router IP as source. A node advertising an exit node can't consume one — test from +the laptop/iPad, not the routers.