feat(mesh): advertise exit nodes at all three sites (SNAT re-enabled); usage + tradeoff documented
This commit is contained in:
@@ -275,3 +275,24 @@ NH3↔colo, NH3↔ESH, colo↔ESH. FortiGate mgmt via WAN SSH OPEN; ana-wg WG fa
|
|||||||
State: **Site Magic disabled (UI); both IPsec tunnels dormant (UDM ends disabled, config
|
State: **Site Magic disabled (UI); both IPsec tunnels dormant (UDM ends disabled, config
|
||||||
retained); headscale is the sole active site-to-site transport.** Tunnels re-enablable for
|
retained); headscale is the sole active site-to-site transport.** Tunnels re-enablable for
|
||||||
backup (Site Magic in UI; IPsec by flipping the UDM objects enabled=true). Goal met.
|
backup (Site Magic in UI; IPsec by flipping the UDM objects enabled=true). Goal met.
|
||||||
|
|
||||||
|
## 2026-09-06 — exit nodes advertised (multi-location egress proxy)
|
||||||
|
|
||||||
|
All three routers advertise + serve exit nodes; approved on headscale (each shows
|
||||||
|
`0.0.0.0/0` + `::/0` Serving). Clients see three: `nh3-scale` (100.64.0.1, NH3 residential
|
||||||
|
egress 70.230.226.88), `esh-scale` (100.64.0.2, ESH 23.164.40.160), `ana-scale`
|
||||||
|
(100.64.0.3, colo 38.120.12.42).
|
||||||
|
|
||||||
|
⚠ **Design reversal:** exit nodes REQUIRE SNAT, so `--snat-subnet-routes` was flipped back to
|
||||||
|
**true** (NoSNAT=false) on all three routers — this undoes the earlier source-preserving
|
||||||
|
choice. Consequence: cross-site subnet-route traffic now appears to come from the local
|
||||||
|
router's IP, not the original host. Site-to-site re-verified OK after the flip. If per-host
|
||||||
|
source visibility is later needed, the alternative is NoSNAT + a manual selective masquerade
|
||||||
|
rule (`-s 100.64.0.0/10 ! -d 10.0.0.0/8 -o eth0 -j MASQUERADE`) on each router, made
|
||||||
|
persistent — not done.
|
||||||
|
|
||||||
|
**Use one from a client:** `tailscale set --exit-node=nh3-scale` (or `esh-scale` /
|
||||||
|
`ana-scale`), `--exit-node=` to clear. A node that itself advertises an exit node cannot
|
||||||
|
consume one (so the routers can't be used to test egress; use the laptop/iPad).
|
||||||
|
Replaces the nh3-dev SOCKS5 residential-egress proxy — retire that once confirmed on real
|
||||||
|
clients.
|
||||||
|
|||||||
@@ -22,3 +22,12 @@ follow-ups in `docs/pfi/headscale-mesh-plan.md` § CUTOVER EXECUTED. Headlines:
|
|||||||
back. See [[incident_crowdsec_cgnat_false_ban]] (same day) and the plan doc.
|
back. See [[incident_crowdsec_cgnat_false_ban]] (same day) and the plan doc.
|
||||||
- Dormancy = disabled+retained (flip UDM object back to enabled=true to restore); NO auto
|
- Dormancy = disabled+retained (flip UDM object back to enabled=true to restore); NO auto
|
||||||
failover wired. Bonus: exit nodes → free multi-location egress proxy (parked).
|
failover wired. Bonus: exit nodes → free multi-location egress proxy (parked).
|
||||||
|
|
||||||
|
|
||||||
|
## Exit nodes (2026-09-06, operator-requested)
|
||||||
|
All three routers advertise+serve exit nodes (approved). Clients pick location:
|
||||||
|
`tailscale set --exit-node=nh3-scale|esh-scale|ana-scale`. NH3 = residential egress
|
||||||
|
(70.230.226.88) → replaces the nh3-dev SOCKS5 proxy. ⚠ Enabling exit nodes REQUIRED flipping
|
||||||
|
`--snat-subnet-routes=true` (reversed the source-preserving NoSNAT); cross-site traffic now
|
||||||
|
shows the router IP as source. A node advertising an exit node can't consume one — test from
|
||||||
|
the laptop/iPad, not the routers.
|
||||||
|
|||||||
Reference in New Issue
Block a user