How to Set the Local IP Address for the OpenFlux Exit Node: Command-Line and Code Methods
Use the --local-ip flag when starting the binary (e.g., sudo ./openflux --exit-node --local-ip 10.0.0.5) or call tunnel.SetLocalIP("10.0.0.5") programmatically to force the exit node to use a specific IP address for outbound traffic and scoped iptables rules.
OpenFlux is an anti-censorship tunneling tool that supports operating as an exit node to handle forwarded traffic from entry nodes. When running in this mode, you can set the local IP address to control which network interface address handles egress traffic and to scope kernel RST-drop rules to a dedicated alias. This guide explains the two configuration methods based on the p1neappleXpress/OpenFlux source code.
Command-Line Flag Method
The simplest way to set the local IP address is using the --local-ip flag when launching the binary. In main.go (lines 39-47), the application parses this flag during initialization and invokes tunnel.SetLocalIP to store the override in the localIPOverride variable.
Pass the flag with your desired egress IP address:
sudo ./openflux --exit-node --local-ip 10.0.0.5
This approach is ideal for production deployments where you want to isolate OpenFlux traffic to a specific IP alias without affecting the host's primary network configuration.
Complete Network Setup with Alias
Before running the command, allocate the IP address on your network interface:
# Add a dedicated alias IP to your interface
sudo ip address add 10.0.0.5/24 dev eth0
# Start OpenFlux with the specific local IP
sudo ./openflux --exit-node --local-ip 10.0.0.5
Upon startup, the program outputs a suggested iptables rule to drop kernel RST packets only for this specific IP (as implemented in main.go lines 14-23):
sudo iptables -A OUTPUT -p tcp --tcp-flags RST RST -s 10.0.0.5 -j DROP
Programmatic Configuration Method
For developers embedding OpenFlux into larger Go applications or building custom tooling, the tunnel package exports the SetLocalIP function. According to tunnel/tunnel.go (lines 10-12), this function directly assigns the provided string to the package-level localIPOverride variable.
package main
import (
"universal-bypass-tool/tunnel"
"universal-bypass-tool/transport"
)
func main() {
// Force the exit node to use 192.168.99.10 as its egress address
tunnel.SetLocalIP("192.168.99.10")
// Initialize your transport layer normally
trans := transport.NewCompressedTransport(transport.NewYandexDocsTransport("", transport.DefaultConfig()))
// ...
}
This method allows dynamic IP configuration at runtime without modifying command-line arguments.
How the Local IP Override Affects Operations
The getLocalIP function in tunnel/tunnel.go (lines 13-24) implements the override logic. When called, it first checks if localIPOverride is set; if so, it returns that value immediately instead of auto-detecting the external interface address.
The chosen IP address serves two critical functions in the exit node architecture:
- Source Address Rewriting: Outbound packets exiting the tunnel carry this IP as their source address, ensuring consistent routing.
- RST-Drop Rule Scoping: The exit node generates iptables commands that target only this specific IP, preventing the kernel from sending RST packets that could interfere with OpenFlux's TCP handling while leaving other host services unaffected.
The tunnel/packettunnel.go file consumes this IP when configuring the exit-node NIC for tunnel traffic, applying it to the underlying packet manipulation layer.
Summary
- Command-line deployment: Use the
--local-ipflag parsed inmain.goto set the egress address at startup. - Library integration: Call
tunnel.SetLocalIP()from Go code to override the address programmatically. - Override mechanism: The
localIPOverridevariable intunnel/tunnel.gotakes precedence over auto-detection in thegetLocalIPfunction. - Operational benefits: Scopes iptables RST-drop rules to a specific alias and controls which interface handles tunnel egress.
Frequently Asked Questions
What happens if I do not set a local IP address?
If localIPOverride remains unset, the getLocalIP routine falls back to auto-detecting the external IP address from the default network interface. The RST-drop iptables suggestions will target this auto-detected address instead of a specific alias.
Can I use any IP address with the --local-ip flag?
The IP address must be assigned to a local network interface on the host. OpenFlux does not validate network reachability; it simply uses the provided value for source rewriting in packettunnel.go and generating scoped iptables rules.
Does the local IP setting affect entry node behavior?
No. The --local-ip flag and SetLocalIP function only affect exit node operations where traffic exits the tunnel. Entry nodes do not use the local IP override for their upstream connections.
How does the local IP interact with the kernel RST-drop mechanism?
When set, the exit node logs a specific iptables command that drops TCP RST packets originating from the configured local IP. This prevents the kernel from resetting connections that OpenFlux manages, while the scoped -s parameter ensures other services on the host remain unaffected.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →