# How to Run OpenFlux as an Exit Node: Complete Setup Guide

> Learn how to run OpenFlux as an exit node with our complete setup guide. Compile the binary from the p1neappleXpress/OpenFlux repository and configure egress traffic handling.

- Repository: [p1neappleXpress/OpenFlux](https://github.com/p1neappleXpress/OpenFlux)
- Tags: how-to-guide
- Published: 2026-09-13

---

**Run OpenFlux as an exit node by compiling the binary from the `p1neappleXpress/OpenFlux` repository and executing it with root privileges using the `--exit-node` flag, which triggers the exit-node code path in [`main/main.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/main/main.go) and configures the encrypted transport layer for egress traffic handling.**

OpenFlux is a lightweight VPN tunneling tool written in Go that supports both client and exit node operation modes. When you run OpenFlux as an exit node, the server becomes the final hop in the encrypted tunnel, receiving traffic from clients and forwarding it to the public internet. This guide covers the complete setup process, command-line configuration, and internal architecture based on the actual source code implementation.

## Prerequisites

Running an exit node requires specific infrastructure and privileges to handle raw sockets and network forwarding.

- **VPS or dedicated server**: A Linux host with a public IPv4 address is recommended for internet accessibility.
- **Root privileges**: The process must run as root to create raw sockets and modify firewall rules.
- **Dependencies**: Git, Go toolchain, and build tools installed on the server.

## Building from Source

Clone the repository and compile the binary from the `main` directory.

```bash
sudo apt-get update
sudo apt-get install -y git golang-go make

```

```bash
git clone https://github.com/p1neappleXpress/OpenFlux.git
cd OpenFlux/main
go build -o openflux .

```

The resulting `openflux` binary contains the exit node logic implemented in [`main/main.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/main/main.go), which parses the `--exit-node` flag to determine operation mode.

## Starting the Exit Node

Execute the binary with the `--exit-node` flag to activate exit node mode. This flag triggers the construction of a `OneMeTransport` with `exit = true` and an `EncryptedTransport` with `exitNode = true` in the transport stack.

```bash
sudo ./openflux --exit-node

```

By default, the exit node listens on TCP port **443** (the standard TLS port) for incoming client connections. Verify the listening socket with:

```bash
sudo netstat -tlnp | grep ':443'

```

### Complete Example with Authentication

For production deployments, specify the user ID and shared secret used for packet filtering and transport encryption:

```bash
sudo ./openflux \
  --exit-node \
  --local-ip 198.51.100.23 \
  --port 443 \
  --uid 1000 \
  --secret "super-long-shared-secret"

```

## Configuring Network Parameters

### Specifying the Egress IP

If your host has multiple IP addresses or sits behind NAT, use the `--local-ip` flag to advertise a specific address to clients. The [`tunnel/endpoint.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/tunnel/endpoint.go) file handles this override via the `localIPOverride` parameter.

```bash
sudo ./openflux --exit-node --local-ip 203.0.113.45

```

### Customizing the Listen Port

Override the default port 443 using the `--port` flag:

```bash
sudo ./openflux --exit-node --port 8443

```

## Internal Architecture of Exit Node Mode

The exit node functionality relies on specific components that distinguish it from client mode:

- **[`main/main.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/main/main.go)**: Parses command-line flags and initializes the transport stack. When `--exit-node` is present, it builds a `TCPTunnel` configured for egress handling via `tunnel.NewTCPTunnel`.
- **[`transport/oneme/max_transport.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/oneme/max_transport.go)**: Contains the `exit` boolean flag that propagates mode configuration to inner transport layers.
- **[`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go)**: Implements bidirectional encryption through `NewEncryptedTransport`. When the `exitNode` parameter is `true`, the constructor swaps send and receive keys so the client and exit node use opposite encryption keys.
- **[`tunnel/tunnel.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/tunnel/tunnel.go)**: Creates the TCP-forwarding tunnel that manages connections in exit mode.
- **[`tunnel/packettunnel.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/tunnel/packettunnel.go)**: Handles packet-level flow between the client and exit node.
- **[`tunnel/endpoint.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/tunnel/endpoint.go)**: Determines the advertised IP address, using the `localIPOverride` value when `--local-ip` is specified.

## Connecting Client Devices

On the client device, run OpenFlux without the `--exit-node` flag, pointing `--server` to your exit node's public IP address.

```bash
./openflux --server 203.0.113.45 --uid 1000 --secret "my-shared-secret"

```

The client establishes an encrypted tunnel to the exit node, which then forwards traffic to the public internet.

## Security Hardening

Restrict the attack surface by configuring firewall rules and resource limits.

### Firewall Configuration

Allow only the tunnel port and deny other incoming traffic:

```bash
sudo ufw allow 443/tcp
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable

```

### Memory Limits

For deployment on small VPS instances, restrict memory usage with the `--max-mem` flag to keep the heap tight:

```bash
sudo ./openflux --exit-node --max-mem 256

```

## Summary

- **Build** the binary from `p1neappleXpress/OpenFlux` using `go build` in the `main` directory.
- **Execute** with `sudo ./openflux --exit-node` to enable exit node mode, which configures the transport layer in [`main/main.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/main/main.go) for egress traffic.
- **Specify** a custom egress IP with `--local-ip` if the host has multiple addresses, handled by [`tunnel/endpoint.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/tunnel/endpoint.go).
- **Listen** on port 443 by default, override with `--port` if needed.
- **Connect** clients using the `--server` flag pointing to the exit node's public IP.
- **Secure** the deployment with firewall rules and the `--max-mem` flag for resource constraints.

## Frequently Asked Questions

### Do I need root privileges to run OpenFlux as an exit node?

Yes. The exit node requires root access to create raw sockets, bind to privileged ports like 443, and modify packet filter rules. The source code in [`main/main.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/main/main.go) initializes these low-level network operations only when running with sufficient privileges.

### Which port does the exit node listen on by default?

The exit node opens a TCP listening socket on port **443** by default, as implemented in the tunnel subsystem. You can override this using the `--port` flag to specify an alternative port for client connections.

### How does encryption work between the client and exit node?

OpenFlux uses bidirectional encryption implemented in [`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go). The `NewEncryptedTransport` function accepts an `exitNode` boolean parameter; when `true`, it swaps the send and receive keys so the client and exit node use opposite keys for encryption and decryption, ensuring secure one-way traffic flow.

### Can I specify which IP address the exit node uses for outbound traffic?

Yes. Use the `--local-ip` flag to force a specific egress IP address. This is useful when the server has multiple network interfaces or sits behind NAT. The [`tunnel/endpoint.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/tunnel/endpoint.go) file processes this via the `localIPOverride` variable to advertise the correct address to connecting clients.