Block Tor exit nodes
Drop every request from a Tor exit node with one firewall rule on the Azion IP Tor Exit Nodes list, from Azion Console, Azion CLI, or the API.
You can drop requests from Tor exit nodes with one firewall rule, from Azion Console, Azion CLI, or the API. To block addresses, networks, or countries you choose, refer to Block requests by IP, ASN, or country. To deploy a new firewall that also scores bots, refer to Block bots and Tor exit nodes with a template.
A Tor exit node is the final point where the Tor network connects to the internet. Tor encryption ends at that node, so the node can see the data a request carries. Traffic from exit nodes can therefore raise security concerns, and it can be malicious.
Azion maintains the Azion IP Tor Exit Nodes network list in every account, with the ID 2. It holds the IP addresses of Tor exit nodes, Azion refreshes them, and no account can change the list. There is no list to create or keep current, only a rule to add. A rule in the Rules Engine matches the list through the Network criterion. Network Shield makes that criterion available on a firewall. One rule or several can reference the list, and each rule matches the addresses the list holds after every refresh.
Select the interface you work in. The prerequisites and both tasks on this page follow that choice.
Prerequisites
- A firewall bound to the workload that serves your application. To bind one, refer to Bind a firewall to a workload.
- Network Shield on for that firewall, which is the default for a new firewall. To check the setting, refer to Set a firewall’s main settings.
- The Edit Firewall permission to add the rule, and View Network Lists to read the Tor list. For more information, refer to Network Lists.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Add the rule that drops the Tor list
The rule holds one criterion, true when the client address of a request is in list 2. Its behavior, Drop (Close Without Response), closes the connection without an HTTP response. Deny (403 Forbidden) answers with Azion’s 403 error page instead. To choose between the two, refer to Deny while you roll a block out, then drop.
To add the rule in Azion Console:
Access Azion Console > Secure > Firewalls.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name. For example: Block Tor Exit Nodes.
In the Description field, enter a short comment on the rule.
In the Criteria section, select the Network variable and the matches operator.
If the variable reads Network - required Network Shield, the firewall has Network Shield off. Turn it on in Main Settings and save, and the variable becomes selectable.
In the Select a Network dropdown, select Azion IP Tor Exit Nodes.
In the Behaviors section, select Drop (Close Without Response).
Select Save.
Azion Console shows the message Rule successfully created, and the rule appears in the Rules Engine tab.
Once the rule reaches Azion’s distributed infrastructure, the firewall drops every request from an address in the Tor list. The client receives no status line and no body. A rule you add takes several minutes to get there. For the propagation times, refer to How Firewall works.
Confirm the rule is saved
A request from your own connection does not test the Tor rule. Your address is not in the Tor list, and any write that would add it is refused with 22004. Read the rule back instead, and check that it names list 2 and the drop behavior.
To read the rule in Azion Console:
Access Azion Console > Secure > Firewalls.
The rule appears in the list of rules, with Active in the Status column.
Select the rule. The Edit Rule drawer opens.
In the Criteria section, the rule reads Network, matches, and Azion IP Tor Exit Nodes.
In the Behaviors section, the rule reads Drop (Close Without Response).
The rule is saved on the firewall with the Tor list as its criterion and the drop behavior.
To see the rule act on traffic, turn on Debug Rules in the firewall’s Main Settings. The firewall then logs the rules that run, and Real-Time Events shows them. For the setting, refer to Set a firewall’s main settings.