@honobono Uhm you'd think so. But i noticed that connection was aborted and the ip that was shown as exit node was on blacklist, after whitelisting it was working again. Well the thing is crowdsec works with community effort so if a thousand servers report a ip as malicious (and some other consensus magic so it can't be poisoned by bad actors false reporting) it gets blocked by all other crowdsec users. Plus i have subscribed some firehol blacklists. Not especially tor.