How to Run OpenFlux as an Exit Node: Complete Setup Guide
Run OpenFlux as an exit node by compiling the binary from the p1neappleXpress/OpenFlux repository and executing it with root privileges using the --exit-node flag, which triggers the exit-node code path in main/main.go and configures the encrypted transport layer for egress traffic handling.
OpenFlux is a lightweight VPN tunneling tool written in Go that supports both client and exit node operation modes. When you run OpenFlux as an exit node, the server becomes the final hop in the encrypted tunnel, receiving traffic from clients and forwarding it to the public internet. This guide covers the complete setup process, command-line configuration, and internal architecture based on the actual source code implementation.
Prerequisites
Running an exit node requires specific infrastructure and privileges to handle raw sockets and network forwarding.
- VPS or dedicated server: A Linux host with a public IPv4 address is recommended for internet accessibility.
- Root privileges: The process must run as root to create raw sockets and modify firewall rules.
- Dependencies: Git, Go toolchain, and build tools installed on the server.
Building from Source
Clone the repository and compile the binary from the main directory.
sudo apt-get update
sudo apt-get install -y git golang-go make
git clone https://github.com/p1neappleXpress/OpenFlux.git
cd OpenFlux/main
go build -o openflux .
The resulting openflux binary contains the exit node logic implemented in main/main.go, which parses the --exit-node flag to determine operation mode.
Starting the Exit Node
Execute the binary with the --exit-node flag to activate exit node mode. This flag triggers the construction of a OneMeTransport with exit = true and an EncryptedTransport with exitNode = true in the transport stack.
sudo ./openflux --exit-node
By default, the exit node listens on TCP port 443 (the standard TLS port) for incoming client connections. Verify the listening socket with:
sudo netstat -tlnp | grep ':443'
Complete Example with Authentication
For production deployments, specify the user ID and shared secret used for packet filtering and transport encryption:
sudo ./openflux \
--exit-node \
--local-ip 198.51.100.23 \
--port 443 \
--uid 1000 \
--secret "super-long-shared-secret"
Configuring Network Parameters
Specifying the Egress IP
If your host has multiple IP addresses or sits behind NAT, use the --local-ip flag to advertise a specific address to clients. The tunnel/endpoint.go file handles this override via the localIPOverride parameter.
sudo ./openflux --exit-node --local-ip 203.0.113.45
Customizing the Listen Port
Override the default port 443 using the --port flag:
sudo ./openflux --exit-node --port 8443
Internal Architecture of Exit Node Mode
The exit node functionality relies on specific components that distinguish it from client mode:
main/main.go: Parses command-line flags and initializes the transport stack. When--exit-nodeis present, it builds aTCPTunnelconfigured for egress handling viatunnel.NewTCPTunnel.transport/oneme/max_transport.go: Contains theexitboolean flag that propagates mode configuration to inner transport layers.transport/encrypted.go: Implements bidirectional encryption throughNewEncryptedTransport. When theexitNodeparameter istrue, the constructor swaps send and receive keys so the client and exit node use opposite encryption keys.tunnel/tunnel.go: Creates the TCP-forwarding tunnel that manages connections in exit mode.tunnel/packettunnel.go: Handles packet-level flow between the client and exit node.tunnel/endpoint.go: Determines the advertised IP address, using thelocalIPOverridevalue when--local-ipis specified.
Connecting Client Devices
On the client device, run OpenFlux without the --exit-node flag, pointing --server to your exit node's public IP address.
./openflux --server 203.0.113.45 --uid 1000 --secret "my-shared-secret"
The client establishes an encrypted tunnel to the exit node, which then forwards traffic to the public internet.
Security Hardening
Restrict the attack surface by configuring firewall rules and resource limits.
Firewall Configuration
Allow only the tunnel port and deny other incoming traffic:
sudo ufw allow 443/tcp
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable
Memory Limits
For deployment on small VPS instances, restrict memory usage with the --max-mem flag to keep the heap tight:
sudo ./openflux --exit-node --max-mem 256
Summary
- Build the binary from
p1neappleXpress/OpenFluxusinggo buildin themaindirectory. - Execute with
sudo ./openflux --exit-nodeto enable exit node mode, which configures the transport layer inmain/main.gofor egress traffic. - Specify a custom egress IP with
--local-ipif the host has multiple addresses, handled bytunnel/endpoint.go. - Listen on port 443 by default, override with
--portif needed. - Connect clients using the
--serverflag pointing to the exit node's public IP. - Secure the deployment with firewall rules and the
--max-memflag for resource constraints.
Frequently Asked Questions
Do I need root privileges to run OpenFlux as an exit node?
Yes. The exit node requires root access to create raw sockets, bind to privileged ports like 443, and modify packet filter rules. The source code in main/main.go initializes these low-level network operations only when running with sufficient privileges.
Which port does the exit node listen on by default?
The exit node opens a TCP listening socket on port 443 by default, as implemented in the tunnel subsystem. You can override this using the --port flag to specify an alternative port for client connections.
How does encryption work between the client and exit node?
OpenFlux uses bidirectional encryption implemented in transport/encrypted.go. The NewEncryptedTransport function accepts an exitNode boolean parameter; when true, it swaps the send and receive keys so the client and exit node use opposite keys for encryption and decryption, ensuring secure one-way traffic flow.
Can I specify which IP address the exit node uses for outbound traffic?
Yes. Use the --local-ip flag to force a specific egress IP address. This is useful when the server has multiple network interfaces or sits behind NAT. The tunnel/endpoint.go file processes this via the localIPOverride variable to advertise the correct address to connecting clients.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →