AI Gateway is now available: identity-aware access to any AI provider, eliminate API keys, and tunnel to self-hosted models. Get started

ResourcesPrivate Resources

Exit Node (route all traffic)

Create private exit node resources to act as full

Pangolin works as a split tunnel VPN by default. It carries traffic between sites and clients and leaves your public internet traffic alone, for example when you visit Google or Wikipedia. This suits most people, who want secure communication between sensitive devices such as company servers or home computers, without the extra encryption and latency on their regular internet connection.

Sometimes you do want Pangolin to carry your public internet traffic, for instance when:

  • You're on untrusted coffee shop Wi-Fi.
  • You're abroad and need an online service, such as banking, that only works from your home country.

To do this, make a site an exit node and point other devices at it using an exit node resource. Routing everything through an exit node uses the default routes (0.0.0.0/0, ::/0), the same way a typical VPN does.

Subnet routers and exit nodes both route traffic, but they do different jobs. A subnet router gives access to resources to devices not running the Pangolin client on private subnets. Devices can reach Pangolin resources in those subnets, and internet routing is unchanged. An exit node sends outbound internet traffic from your Pangolin clients through sites, like a VPN server. Your traffic appears to originate from the exit node's location, which helps with geo-restricted content or privacy.

Benefits

  • All traffic is secured, including traffic to internet sites and applications.
  • You can deploy exit nodes around the world to fit your scale and location needs.
  • Network connection logging shows traffic across the Pangolin network and supports analysis after a security incident.

Use cases

  • Traveling staff have all their internet traffic secured, whatever network they're on.
  • You can test applications from different locations by deploying exit nodes in several regions and choosing between them.
  • If regulations or compliance rules require your workforce to use a VPN, exit nodes can meet that requirement.

How it works

With the exit node feature, you send all traffic through one or more sites on your Pangolin network. That device is the exit node. You can use exit nodes in several ways:

  • Route all non-Pangolin traffic through an exit node.
  • Use multiple exit nodes on the resource and clients will pick the best one automatically based on latency.

Set up a exit node

Deploy the site

Create a site in the dashboard and run it on the network you want your traffic to leave from. Traffic exits from that site's internet connection. See Install Sites. For redundancy or lower latency, deploy more than one site.

Create the exit node resource

  1. Create a new private resource and set the mode to Exit Node.
  2. Select the sites to use as exit nodes. With several sites, clients pick the best one by latency.
  3. Choose the roles, users, and machine clients that can use the exit node.

An exit node has no destination, since it always routes 0.0.0.0/0. All TCP and UDP ports and ICMP are allowed.

Select the node in your client

Each device enables the exit node on its own, and the steps depend on the client.

MacOS, Windows, iOS, Android

  1. Open the Pangolin app and go to the exit node section.
  2. Select the exit node you want.
  3. Check that the status shows active in the exit node section and when clicking on the sites they are marked for exit node use.
  4. To stop using an exit node, go to the Exit Node section and select None.

CLI

Run this command and pick an exit node from the list:

pangolin select exit-node

If the client is running, the change applies immediately. If not, the choice is saved and applied on the next pangolin up. To turn it off, run the command again and choose None. To select an exit node without the prompt, pass its nice ID with --exit-node.

To confirm routing works, look up your public IP address with an online tool. It should show the exit node's public address instead of your local device's.

Other Resources When Connected

When a client is connected using an exit node other Pangolin resources will still be accessible and resolvable - even on other sites not designated on the exit node resource. In this way Pangolin is still split tunneling these destinations. If you would like to disable this, set the Exit Nodes Take Precedence Over Resources setting on. By enabling this setting, you are configuring Pangolin to ignore other resources outside of the exit node - all traffic will flow to and through the exit node resource and DNS aliases and subnets on other resources will no longer function.

Logging

All exit node traffic appears in the network connection logs.

Network connection logs are available on Enterprise Edition and Pangolin Cloud.

Was this page helpful?

⌘I

On this page