# Firewall needs/settings for running standalone Snowflake proxy

**URL:** https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314
**Category:** Relay Operator
**Tags:** snowflake
**Created:** [August 17, 2022, 1:18pm UTC](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314 "2022-08-17T13:18:48Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![meskio](https://forum.torproject.org/user_avatar/forum.torproject.org/meskio/32/26_2.png) [@meskio](https://forum.torproject.org/u/meskio)
#### Post date: [August 17, 2022, 2:12pm UTC](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314/2 "2022-08-17T14:12:37Z")

</div>

The firewall needs to have the UDP ports 32768-60999 open and reachable from the proxy.

More info:

> [@\[tor-relays\] snowflake incoming UDP ports](https://forum.torproject.org/t/tor-relays-snowflake-incoming-udp-ports/2228/2):
>
> Quoting Toralf Förster (2022-02-19 11:15:19) I do simply run here &nbsp;&nbsp;~/devel/go/src/snowflake/proxy/proxy &\>\>/tmp/snowflake-proxy.log & and was wondering if I have to open special UDP inbound ports ? [...] but b/c I do have a rather restrict inbound firewall rule set I'm wondering about that. If you have a restricted firewall you might have what snowflake calls 'restricted NAT', the most useful snowflake proxies are the 'unrestricted NAT' ones, as they allow clients in a more restric…

---

_[View the full topic](https://forum.torproject.org/t/firewall-needs-settings-for-running-standalone-snowflake-proxy/4314)._
