Skip to main content
See All Integrations

Tor Exit Nodes

Use Tor exit relay IP data in Pomerium Enterprise policy to identify or restrict requests from known Tor exits.

First-party Pomerium Enterprise data source

Category
Context

Overview

Tor exit relay IP data lists addresses that can send traffic from the Tor network to public services. Pomerium Enterprise can use this data as request context.

A known Tor exit address is one coarse request-context signal. It can support an explicit allow or deny rule, but it does not identify the user or device and does not prove abuse.

Pomerium Enterprise Console supplies the bundled pomerium.io/TorExitNode records. Pomerium matches the request IP against those records before it sends approved traffic to the protected service.

How it works

Use Pomerium Enterprise Console version 18 or later and confirm that the bundled Tor exit-node data source is available and current.

Add an explicit Pomerium Policy Language record rule for type pomerium.io/TorExitNode and field id. Choose allow or deny behavior for the selected route.

Attach the policy to the route. Test a known Tor exit address, a normal address, a missing record, and data source update behavior.

Example

A security team adds a reviewed rule to a sensitive administration route. The rule checks whether the request IP is in the current Tor exit data before it permits or denies access.

Considerations

  • The list changes as Tor relays enter and leave the network.
  • Membership means that the address is a Tor exit. It does not prove malicious intent.
  • Adding the data source does not deny requests automatically. Policy must state the desired action.
  • An IP match describes the observed request address. It does not identify the person or device behind that address.
  • The data update schedule controls freshness.
  • Pomerium supplies external data sources as examples and does not promise to maintain each source forever. Verify the selected source before production use.

Sources and official resources

  • Use selected IP geolocation records in Pomerium policy with the documented GeoIP data-source pattern.

  • Use the Pomerium Enterprise FleetDM plugin to evaluate Fleet device policy and vulnerability data during access decisions.

  • Import selected BambooHR workforce fields into Pomerium Enterprise policy with the example external data source and user email matching.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo