Exit nodes
An exit node is a device of your network that carries the others’ internet traffic. In a café, your laptop can go online through your VPS instead of the café’s network.
What it is #
Normally a device goes online from wherever it is. With an exit node, it first sends its internet traffic through the tunnel to another member, a device that belongs to your network (How juist works). That member sends it on. Websites then see the exit node’s address, and the café’s network sees only encrypted traffic.
Two steps make a device an exit node. An admin, a person whose key approves
changes to the network, gives the device the role exit. A role is a permission the network
records for one device. Then the device’s operator agrees by running
juist exit serve on it. The operator is the
local user who manages a device without sudo.
Each device decides for itself whether it uses an exit node. Nothing changes
on a device until you run juist exit use there.
Setting up an exit node #
Give the VPS the role:
juist grant vps exitWhere a change needs more than one admin, it waits for the others (how changes are approved).
Agree to carry the network’s internet traffic:
juist exit serveThe first time, it asks to run a setup script with sudo. The script turns on
IP forwarding and lets the forwarded traffic through the firewall. Then it
prints serving as an exit node.
Send this device’s internet traffic through the VPS:
juist exit use vpsIt prints internet via vps. Where systemd-resolved runs, the line
Exit node in juist status now says vps, DNS too.
Back in your own network, juist exit off sends the traffic directly again
and prints internet direct.
What goes through it, and what stays direct #
- Traffic to public internet addresses goes through the exit node.
- DNS goes through it too, where systemd-resolved runs on the device. Names of the LAN’s own domain, such as your router’s, are still asked on the LAN.
- Your LAN and the network’s own devices stay direct.
- Answers to connections from the internet, as to ssh on this device, also stay direct, so the device is still reached at its own address.
juist exit use vps --isolatesends those answers through the exit node as well. It stops where that would end the ssh session you run it in.
It fails closed #
When the exit node you chose cannot be used, internet traffic is refused, not
sent directly. That happens when it is offline, has stopped serving, has lost
its role, or when this device’s view of the network is stale. DNS lookups then
go nowhere rather than to the LAN. Going direct is your choice, with
juist exit off.
Good to know #
juist exitlists the exit nodes, whether each serves, and the one in use.juist exit use vps --forcechooses vps even though it does not serve yet, or though the choice would end your ssh session.juist exit serve --stopstops serving and undoes the setup.juist revoke vps exit, on an admin’s device, takes the role back.- A device that uses an exit node serves as none. A device in several networks sends the internet through one network only.
- Without an access policy every member may
use an exit node. With one, a device uses only the exit nodes a rule such
as
pass from laptop to internet via vpspasses it, and the exit node forwards only that. - A firewall configured by hand on the exit node must let in UDP and TCP 41646
on
juist0, where it answers its members’ DNS (Relays, ports and firewalls). - An exit node that also runs Tailscale answers its members’ DNS as the internet does. It never asks Tailscale’s resolver, which would answer names of its tailnet with addresses its members cannot reach.
- On FreeBSD, exit nodes work with pf, and DNS goes through resolvconf.
- On Linux, an exit node or subnet router turns on UDP GRO forwarding on the
network device of its default route, as
ethtool -K eth0 rx-udp-gro-forwarding on rx-gro-list offdoes, so that it forwards UDP such as QUIC in batches. It sets the device back as it found it when it stops serving, and logs both. - A clean stop of juistd lifts the refusal, so during a restart of the service traffic goes direct for a moment.
If something goes wrong #
| You see | What to do |
|---|---|
juist status: Exit node says vps, internet refused: … | bring vps back, or juist exit off to go direct |
juist exit use vps: vps does not serve as an exit node | run juist exit serve on vps, or add --force |
juist status: Exit node says vps, internet refused: the access policy does not let this device use it | add a rule pass from … to internet via vps (Access policy) |
on vps, juist status: this device does not serve: IP forwarding is off on this host | run juist exit serve again, which sets it up with sudo |
warning: DNS goes to …, outside the tunnel: systemd-resolved refused juistd | install the package, whose polkit rule allows juistd that, and polkit |
warning: strict reverse-path filtering on … drops the exit node's answers | run the sudo sysctl -w … line the hint prints |
After internet refused: the status gives the reason, such as
it cannot be reached, its operator has not agreed to serve or
the network has not made it an exit node.