# Firewall needs/settings for running standalone Snowflake proxy

**URL:** https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314
**Category:** Relay Operator
**Tags:** snowflake
**Created:** [August 17, 2022, 1:18pm UTC](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314 "2022-08-17T13:18:48Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![mre](https://forum.torproject.org/letter_avatar_proxy/v4/letter/m/96bed5/32.png) [@mre](https://forum.torproject.org/u/mre)
#### Post date: [August 17, 2022, 1:18pm UTC](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314/1 "2022-08-17T13:18:48Z")

</div>

Hi there,

I’m trying to set up a snowflake proxy on a vps, but I am not having luck finding any info on firewall requirements. I’m not sure experienced with NAT and would appreciate a little guidance as to what to do. I have the docker image up and running and accepting connections, but have shut it down until I figure out how to secure the proxy.

It’s set up with the sole purpose of running this proxy and is not hosting any other services.

Thanks in advance.

Emil

---

<div class="post-metadata">

### Author: ![meskio](https://forum.torproject.org/user_avatar/forum.torproject.org/meskio/32/26_2.png) [@meskio](https://forum.torproject.org/u/meskio)
#### Post date: [August 17, 2022, 2:12pm UTC](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314/2 "2022-08-17T14:12:37Z")

</div>

The firewall needs to have the UDP ports 32768-60999 open and reachable from the proxy.

More info:

> [@\[tor-relays\] snowflake incoming UDP ports](https://forum.torproject.org/t/tor-relays-snowflake-incoming-udp-ports/2228/2):
>
> Quoting Toralf Förster (2022-02-19 11:15:19) I do simply run here &nbsp;&nbsp;~/devel/go/src/snowflake/proxy/proxy &\>\>/tmp/snowflake-proxy.log & and was wondering if I have to open special UDP inbound ports ? [...] but b/c I do have a rather restrict inbound firewall rule set I'm wondering about that. If you have a restricted firewall you might have what snowflake calls 'restricted NAT', the most useful snowflake proxies are the 'unrestricted NAT' ones, as they allow clients in a more restric…

---

<div class="post-metadata">

### Author: ![mre](https://forum.torproject.org/letter_avatar_proxy/v4/letter/m/96bed5/32.png) [@mre](https://forum.torproject.org/u/mre)
#### Post date: [August 18, 2022, 4:04pm UTC](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314/3 "2022-08-18T16:04:57Z")

</div>

Hi meskido,

Thanks for your quick reply.

I ended up allowing all outgoing connections (and blocking all incoming). From looking at the docker logs it seems to be working?

I do wonder why there so much more outbound than inbound traffic, though.

 ![Screenshot 2022-08-18 at 17.51.19](https://forum.torproject.org/uploads/default/original/2X/8/88ed0bac9ba6526be5713fa5c8a5f2ab13cc73d7.png)
