Fix description of blocklist rejection behavior

The previous wording ("silently routed to the fronting domain")
is inaccurate. In mtglib/proxy.go the blocklist path calls
conn.Close() immediately with no further handshake or fronting;
domain fronting only happens on FakeTLS failures for non-blocked
IPs. Reword to "TCP connection is closed with no response" so
users searching the docs get the same symptom they actually see.
This commit is contained in:
dolonet
2026-04-13 07:46:52 +00:00
parent 602f85d24d
commit 68a4685ec6
2 changed files with 5 additions and 4 deletions
+3 -2
View File
@@ -529,8 +529,9 @@ message like:
The reason is that the default blocklist (`firehol_level1.netset`)
includes bogon networks, which covers all RFC1918 ranges
(`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`). Any client
connecting from such an address is rejected by the blocklist and
silently routed to the fronting domain.
connecting from such an address is rejected by the blocklist
the TCP connection is closed immediately with no response, so
from the client's point of view nothing loads at all.
There are three ways to resolve it: