How to Set the Local IP Address for the OpenFlux Exit Node: Command-Line and Code Methods

Use the --local-ip flag when starting the binary (e.g., sudo ./openflux --exit-node --local-ip 10.0.0.5) or call tunnel.SetLocalIP("10.0.0.5") programmatically to force the exit node to use a specific IP address for outbound traffic and scoped iptables rules.

OpenFlux is an anti-censorship tunneling tool that supports operating as an exit node to handle forwarded traffic from entry nodes. When running in this mode, you can set the local IP address to control which network interface address handles egress traffic and to scope kernel RST-drop rules to a dedicated alias. This guide explains the two configuration methods based on the p1neappleXpress/OpenFlux source code.

Command-Line Flag Method

The simplest way to set the local IP address is using the --local-ip flag when launching the binary. In main.go (lines 39-47), the application parses this flag during initialization and invokes tunnel.SetLocalIP to store the override in the localIPOverride variable.

Pass the flag with your desired egress IP address:

sudo ./openflux --exit-node --local-ip 10.0.0.5

This approach is ideal for production deployments where you want to isolate OpenFlux traffic to a specific IP alias without affecting the host's primary network configuration.

Complete Network Setup with Alias

Before running the command, allocate the IP address on your network interface:


# Add a dedicated alias IP to your interface

sudo ip address add 10.0.0.5/24 dev eth0

# Start OpenFlux with the specific local IP

sudo ./openflux --exit-node --local-ip 10.0.0.5

Upon startup, the program outputs a suggested iptables rule to drop kernel RST packets only for this specific IP (as implemented in main.go lines 14-23):

sudo iptables -A OUTPUT -p tcp --tcp-flags RST RST -s 10.0.0.5 -j DROP

Programmatic Configuration Method

For developers embedding OpenFlux into larger Go applications or building custom tooling, the tunnel package exports the SetLocalIP function. According to tunnel/tunnel.go (lines 10-12), this function directly assigns the provided string to the package-level localIPOverride variable.

package main

import (
    "universal-bypass-tool/tunnel"
    "universal-bypass-tool/transport"
)

func main() {
    // Force the exit node to use 192.168.99.10 as its egress address
    tunnel.SetLocalIP("192.168.99.10")
    
    // Initialize your transport layer normally
    trans := transport.NewCompressedTransport(transport.NewYandexDocsTransport("", transport.DefaultConfig()))
    // ...
}

This method allows dynamic IP configuration at runtime without modifying command-line arguments.

How the Local IP Override Affects Operations

The getLocalIP function in tunnel/tunnel.go (lines 13-24) implements the override logic. When called, it first checks if localIPOverride is set; if so, it returns that value immediately instead of auto-detecting the external interface address.

The chosen IP address serves two critical functions in the exit node architecture:

  • Source Address Rewriting: Outbound packets exiting the tunnel carry this IP as their source address, ensuring consistent routing.
  • RST-Drop Rule Scoping: The exit node generates iptables commands that target only this specific IP, preventing the kernel from sending RST packets that could interfere with OpenFlux's TCP handling while leaving other host services unaffected.

The tunnel/packettunnel.go file consumes this IP when configuring the exit-node NIC for tunnel traffic, applying it to the underlying packet manipulation layer.

Summary

  • Command-line deployment: Use the --local-ip flag parsed in main.go to set the egress address at startup.
  • Library integration: Call tunnel.SetLocalIP() from Go code to override the address programmatically.
  • Override mechanism: The localIPOverride variable in tunnel/tunnel.go takes precedence over auto-detection in the getLocalIP function.
  • Operational benefits: Scopes iptables RST-drop rules to a specific alias and controls which interface handles tunnel egress.

Frequently Asked Questions

What happens if I do not set a local IP address?

If localIPOverride remains unset, the getLocalIP routine falls back to auto-detecting the external IP address from the default network interface. The RST-drop iptables suggestions will target this auto-detected address instead of a specific alias.

Can I use any IP address with the --local-ip flag?

The IP address must be assigned to a local network interface on the host. OpenFlux does not validate network reachability; it simply uses the provided value for source rewriting in packettunnel.go and generating scoped iptables rules.

Does the local IP setting affect entry node behavior?

No. The --local-ip flag and SetLocalIP function only affect exit node operations where traffic exits the tunnel. Entry nodes do not use the local IP override for their upstream connections.

How does the local IP interact with the kernel RST-drop mechanism?

When set, the exit node logs a specific iptables command that drops TCP RST packets originating from the configured local IP. This prevents the kernel from resetting connections that OpenFlux manages, while the scoped -s parameter ensures other services on the host remain unaffected.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →