
Tor Exit Nodes
Use Tor exit relay IP data in Pomerium Enterprise policy to identify or restrict requests from known Tor exits.
Overview
Tor exit relay IP data lists addresses that can send traffic from the Tor network to public services. Pomerium Enterprise can use this data as request context.
A known Tor exit address is one coarse request-context signal. It can support an explicit allow or deny rule, but it does not identify the user or device and does not prove abuse.
Pomerium Enterprise Console supplies the bundled pomerium.io/TorExitNode records. Pomerium matches the request IP against those records before it sends approved traffic to the protected service.
How it works
Use Pomerium Enterprise Console version 18 or later and confirm that the bundled Tor exit-node data source is available and current.
Add an explicit Pomerium Policy Language record rule for type pomerium.io/TorExitNode and field id. Choose allow or deny behavior for the selected route.
Attach the policy to the route. Test a known Tor exit address, a normal address, a missing record, and data source update behavior.
Example
A security team adds a reviewed rule to a sensitive administration route. The rule checks whether the request IP is in the current Tor exit data before it permits or denies access.
Considerations
- The list changes as Tor relays enter and leave the network.
- Membership means that the address is a Tor exit. It does not prove malicious intent.
- Adding the data source does not deny requests automatically. Policy must state the desired action.
- An IP match describes the observed request address. It does not identify the person or device behind that address.
- The data update schedule controls freshness.
- Pomerium supplies external data sources as examples and does not promise to maintain each source forever. Verify the selected source before production use.
