Files
substrate/docs/egress-traffic.md
haiyanmeng dc1f263076 Document the egress traffic supported for GA (#1749)
Record which egress protocols are allowed, which are allowed only under
policy controls, and which are blocked, along with the data path each
one takes. Having this written down gives users a single place to check
what Substrate lets an actor reach, and gives us a checklist to
implement and test against before GA.

Point readers at the issue tracker so that requests for traffic we do
not yet support arrive with a use case attached.

Address #1339

> It's a good idea to open an issue first for discussion.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-09-21 21:52:37 +00:00

1.7 KiB

This document specifies the supported egress traffic for GA.

Actor TCP egress (except DNS traffic on port 53) is redirected to atunnel, which opens a CONNECT tunnel to the egress gateway. Egress gateway applies policy.

DNS-over-TCP, UDP and other traffic is filtered by nftables and never reaches the gateway.

TCP

Port Traffic Behavior Path What the actor sees when refused
any HTTP(S) 1.1 / 2 Supported with policy controls atunnel -> egress gateway -> origin 403 Forbidden
any WebSocket Blocked n/a 403 Forbidden
any Standard HTTP(S) CONNECT (forward-proxy tunnel) Blocked n/a 403 Forbidden
53 DNS Allowed via netfilter rules nftables -> node-configured DNS n/a
any Any other TCP Blocked n/a The connection is accepted and then closed with no bytes returned. There is no status code. atunnel logs the failure.

UDP

Port Traffic Behavior Path What the actor sees when refused
53 DNS Allowed via netfilter rules nftables -> node-configured DNS n/a
any other Any other UDP Blocked n/a Packets are dropped, not rejected: no ICMP port-unreachable is sent, so the client hangs until its own timeout.

Other protocols

Everything that is neither TCP nor UDP is blocked. Packets are dropped, not rejected: no ICMP port-unreachable is sent, so the client hangs until its own timeout.

Requesting support

If you would like Substrate to support egress traffic that is blocked above, please file an issue describing your use case.