mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-09-29 10:27:57 +03:00
No more "type": "field"
This commit is contained in:
+1
-2
@@ -70,8 +70,7 @@ API 服务监听的 IP 和端口。这是一个可选配置项。
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -105,7 +105,6 @@ FakeDNS 本质上是一个 [DNS 服务器](./dns.md#serverobject),能够与任
|
||||
"routing": {
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["dns-in"], // 劫持来自 DNS 查询入口的 DNS 流量,或劫持来自透明代理入站的 DNS 流量。
|
||||
"port": 53,
|
||||
"outboundTag": "dns-out"
|
||||
|
||||
@@ -168,7 +168,6 @@ outbound:
|
||||
{
|
||||
// bridge 发出的请求,且域名为配置的域名,那么说明这是尝试向 portal 建立反向隧道的请求,
|
||||
// 则路由到 interconn,即连接到 portal
|
||||
"type": "field",
|
||||
"inboundTag": ["bridge"],
|
||||
"domain": ["full:reverse-proxy.xray.internal"],
|
||||
"outboundTag": "interconn"
|
||||
@@ -176,7 +175,6 @@ outbound:
|
||||
{
|
||||
// 从 portal 过来的流量,也会从 bridge 出来,但是不带上面的domain
|
||||
// 则路由到 out,即转发给网页服务器
|
||||
"type": "field",
|
||||
"inboundTag": ["bridge"],
|
||||
"outboundTag": "out"
|
||||
}
|
||||
@@ -241,7 +239,6 @@ inbound:
|
||||
{
|
||||
// 如果入站是 external,说明是来自公网的请求,
|
||||
// 则路由到 portal, 最终会转发给 bridge
|
||||
"type": "field",
|
||||
"inboundTag": ["external"],
|
||||
"outboundTag": "portal"
|
||||
},
|
||||
@@ -249,7 +246,6 @@ inbound:
|
||||
// 如果来自 interconn 入站,说明是来自 bridge 的尝试建立反向隧道请求,
|
||||
// 则路由到 portal, 最终会转发给对应的公网客户端
|
||||
// 注意:这里进入的请求会带上了前文配置的domain,所以 portal 能够区分两种被路由到 portal 的请求
|
||||
"type": "field",
|
||||
"inboundTag": ["interconn"],
|
||||
"outboundTag": "portal"
|
||||
}
|
||||
|
||||
@@ -84,7 +84,6 @@
|
||||
"domainStrategy": "IPOnDemand",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn"], // 绕过局域网和国内IP段
|
||||
"outboundTag": "direct"
|
||||
}
|
||||
|
||||
@@ -228,7 +228,6 @@
|
||||
"rules": [
|
||||
// 3.1 防止服务器本地流转问题:如内网被攻击或滥用、错误的本地回环等
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:private" // 分流条件:geoip 文件内,名为"private"的规则(本地)
|
||||
],
|
||||
@@ -236,13 +235,11 @@
|
||||
},
|
||||
{
|
||||
// 3.2 防止服务器直连国内
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// 3.3 屏蔽广告
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:category-ads-all" // 分流条件:geosite 文件内,名为"category-ads-all"的规则(各种广告域名)
|
||||
],
|
||||
|
||||
@@ -151,31 +151,26 @@
|
||||
"rules": [
|
||||
// 3.1 广告域名屏蔽
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// 3.2 国内域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
// 3.3 国外域名代理
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
// 3.4 走国内"223.5.5.5"的DNS查询流量分流走direct出站
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
// 3.5 国内IP直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn", "geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
}
|
||||
|
||||
@@ -125,7 +125,6 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["inbound-10808"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -140,18 +139,16 @@
|
||||
|
||||
注意观察路由配置,我们可以看到几个新名词:
|
||||
|
||||
1. `"domainStrategy": "AsIs"`
|
||||
2. `“rules”`
|
||||
3. `"type": "field"`
|
||||
4. `"inboundTag": ["inbound-10808"]`
|
||||
5. `"outboundTag": "proxy-out-vless"`
|
||||
1. "domainStrategy": "AsIs"
|
||||
2. “rules”
|
||||
3. "inboundTag": ["inbound-10808"]
|
||||
4. "outboundTag": "proxy-out-vless"
|
||||
|
||||
其中 `domainStrategy` 我们暂且按下不表,先简单说明后面几个:
|
||||
|
||||
| 配置名称 | 配置值 | 配置说明 |
|
||||
| :-------------: | :-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------------------------------------- |
|
||||
| `“rules”` | | 它的内层就是【路由规则】的明细设置 |
|
||||
| `"type"` | `"field"` | 该项暂时没有特别定义,但是不能省略,所以记得写上就好 |
|
||||
| `"inboundTag"` | `["inbound-10808"]` | 筛选流量的 **【依据】** 是【入站 Tag】,具体 **【条件】** 现在只有一个:【入站来源是 `inbound-10808`】 |
|
||||
| `"outboundTag"` | `"proxy-out-vless"` | 当上面的筛选条件成立时(即入站`[tag]="inbound-10808"`时 ),`Xray` 会将流量导入 `[tag]="proxy-out-vless"` 的出站 |
|
||||
|
||||
@@ -242,17 +239,14 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
|
||||
@@ -57,19 +57,16 @@
|
||||
"rules": [
|
||||
// 指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定子域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:proxy.yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// 指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -95,13 +92,11 @@
|
||||
"rules": [
|
||||
// 本机内部地址、局域网地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 国内IP集直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
@@ -126,13 +121,11 @@
|
||||
"rules": [
|
||||
// 指定IP地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定IP地址转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -156,7 +149,6 @@
|
||||
"rules": [
|
||||
// 指定 BT 协议直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
@@ -205,33 +197,28 @@
|
||||
// [1-block 广告流量屏蔽]
|
||||
// 1.1 广告域名集屏蔽
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// [2-direct 国内流量直连]
|
||||
// 2.1 国内域名集、指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn", "full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.2 本机内部地址+局域网、国内IP、指定IP直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn", "223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.3 BT协议流量直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// [3-proxy 国外流量转发VPS]
|
||||
// 3.1 国外域名集、指定子域名、指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"full:proxy.yourdomain.com",
|
||||
@@ -241,7 +228,6 @@
|
||||
},
|
||||
// 3.2 指定IP转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -312,7 +298,6 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
@@ -342,12 +327,10 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
|
||||
@@ -237,38 +237,31 @@ WantedBy=multi-user.target
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"port": 123,
|
||||
"network": "udp",
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["tproxy-in"],
|
||||
"outboundTag": "nginxtls"
|
||||
}
|
||||
|
||||
@@ -182,11 +182,9 @@ lsmod | grep wireguard
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "wg0",
|
||||
"inboundTag": [
|
||||
"<inboundTag>"
|
||||
@@ -197,8 +195,7 @@ lsmod | grep wireguard
|
||||
"outboundTag": "blocked",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
],
|
||||
"type": "field"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
@@ -142,28 +142,23 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 53,
|
||||
"outboundTag": "dns-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["8.8.8.8", "1.1.1.1"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:telegram"],
|
||||
"outboundTag": "proxy"
|
||||
}
|
||||
|
||||
@@ -154,51 +154,42 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 123,
|
||||
"network": "udp",
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 53,
|
||||
"network": "udp",
|
||||
"outboundTag": "dns-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["119.29.29.29", "223.5.5.5"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn"], //此处可加入 VPS IP 避免 ssh 时被代理
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1", "8.8.8.8"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"domain:googleapis.cn",
|
||||
@@ -223,7 +214,6 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"rules": [
|
||||
{
|
||||
//阻止 cnip 提高安全性,或者可以将 cn 流量导入 warp 中,详见https://xtls.github.io/document/level-2/warp.html
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
}
|
||||
|
||||
@@ -151,14 +151,12 @@ bash -c "$(curl -L wgcf-cli.vercel.app)"
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:cn"
|
||||
],
|
||||
"outboundTag": "wireguard-1"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:cn"
|
||||
],
|
||||
|
||||
@@ -65,8 +65,7 @@ Add routing rules for the api inbound in the routing configuration.
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -105,7 +105,6 @@ Only by routing DNS queries to FakeDNS can it be effective.
|
||||
"routing": {
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["dns-in"], // Intercept DNS traffic from DNS query inbound or from inbound traffic of transparent proxies.
|
||||
"port": 53,
|
||||
"outboundTag": "dns-out"
|
||||
|
||||
@@ -26,7 +26,6 @@ And add routing rules regarding the metrics inbound in the routing configuration
|
||||
"routing": {
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": [
|
||||
"metrics_in"
|
||||
],
|
||||
|
||||
@@ -148,13 +148,11 @@ Routing Configuration:
|
||||
{
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["bridge"],
|
||||
"domain": ["full:test.xray.com"],
|
||||
"outboundTag": "interconn"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["bridge"],
|
||||
"outboundTag": "out"
|
||||
}
|
||||
@@ -215,12 +213,10 @@ Routing Configuration:
|
||||
{
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["external"],
|
||||
"outboundTag": "portal"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["interconn"],
|
||||
"outboundTag": "portal"
|
||||
}
|
||||
|
||||
@@ -77,7 +77,6 @@ On your PC (or phone), you need to run Xray with the following configuration:
|
||||
"domainStrategy": "IPOnDemand",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
}
|
||||
|
||||
@@ -221,7 +221,6 @@ sudo nano /usr/local/etc/xray/config.json
|
||||
"rules": [
|
||||
// 3.1 Prevent local server flow problems: such as intranet attacks or abuse, incorrect local loopbacks, etc.
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:private" // Diversion condition: In the geoip file, the rule named "private" (local)
|
||||
],
|
||||
@@ -229,13 +228,11 @@ sudo nano /usr/local/etc/xray/config.json
|
||||
},
|
||||
{
|
||||
// 3.2 Prevent the server from connecting directly to China
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// 3.3 Block ads
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:category-ads-all" // Diversion conditions: In the geosite file, the rule named "category-ads-all" (various advertising domain names)
|
||||
],
|
||||
|
||||
@@ -151,31 +151,26 @@
|
||||
"rules": [
|
||||
// 3.1 广告域名屏蔽
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// 3.2 国内域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
// 3.3 国外域名代理
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
// 3.4 走国内"223.5.5.5"的DNS查询流量分流走direct出站
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
// 3.5 国内IP直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn", "geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
}
|
||||
|
||||
@@ -125,7 +125,6 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["inbound-10808"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -140,18 +139,16 @@
|
||||
|
||||
注意观察路由配置,我们可以看到几个新名词:
|
||||
|
||||
1. `"domainStrategy": "AsIs"`
|
||||
2. `“rules”`
|
||||
3. `"type": "field"`
|
||||
4. `"inboundTag": ["inbound-10808"]`
|
||||
5. `"outboundTag": "proxy-out-vless"`
|
||||
1. "domainStrategy": "AsIs"
|
||||
2. “rules”
|
||||
3. "inboundTag": ["inbound-10808"]
|
||||
4. "outboundTag": "proxy-out-vless"
|
||||
|
||||
其中 `domainStrategy` 我们暂且按下不表,先简单说明后面几个:
|
||||
|
||||
| 配置名称 | 配置值 | 配置说明 |
|
||||
| :-------------: | :-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: | :--------------------------------------------------------------------------------------------------------------- |
|
||||
| `“rules”` | | 它的内层就是【路由规则】的明细设置 |
|
||||
| `"type"` | `"field"` | 该项暂时没有特别定义,但是不能省略,所以记得写上就好 |
|
||||
| `"inboundTag"` | `["inbound-10808"]` | 筛选流量的 **【依据】** 是【入站 Tag】,具体 **【条件】** 现在只有一个:【入站来源是 `inbound-10808`】 |
|
||||
| `"outboundTag"` | `"proxy-out-vless"` | 当上面的筛选条件成立时(即入站`[tag]="inbound-10808"`时 ),`Xray` 会将流量导入 `[tag]="proxy-out-vless"` 的出站 |
|
||||
|
||||
@@ -242,17 +239,14 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
|
||||
@@ -57,19 +57,16 @@
|
||||
"rules": [
|
||||
// 指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定子域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:proxy.yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// 指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -95,13 +92,11 @@
|
||||
"rules": [
|
||||
// 本机内部地址、局域网地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 国内IP集直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
@@ -126,13 +121,11 @@
|
||||
"rules": [
|
||||
// 指定IP地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定IP地址转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -156,7 +149,6 @@
|
||||
"rules": [
|
||||
// 指定 BT 协议直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
@@ -205,33 +197,28 @@
|
||||
// [1-block 广告流量屏蔽]
|
||||
// 1.1 广告域名集屏蔽
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// [2-direct 国内流量直连]
|
||||
// 2.1 国内域名集、指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn", "full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.2 本机内部地址+局域网、国内IP、指定IP直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn", "223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.3 BT协议流量直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// [3-proxy 国外流量转发VPS]
|
||||
// 3.1 国外域名集、指定子域名、指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"full:proxy.yourdomain.com",
|
||||
@@ -241,7 +228,6 @@
|
||||
},
|
||||
// 3.2 指定IP转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -312,7 +298,6 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
@@ -342,12 +327,10 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
|
||||
@@ -237,38 +237,31 @@ WantedBy=multi-user.target
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"port": 123,
|
||||
"network": "udp",
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["tproxy-in"],
|
||||
"outboundTag": "nginxtls"
|
||||
}
|
||||
|
||||
@@ -202,11 +202,9 @@ lsmod | grep wireguard
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "wg0",
|
||||
"inboundTag": [
|
||||
"<inboundTag>"
|
||||
@@ -217,8 +215,7 @@ lsmod | grep wireguard
|
||||
"outboundTag": "blocked",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
],
|
||||
"type": "field"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
@@ -287,11 +284,9 @@ lsmod | grep wireguard
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "wg0",
|
||||
"inboundTag": [
|
||||
"<inboundTag>"
|
||||
@@ -302,8 +297,7 @@ lsmod | grep wireguard
|
||||
"outboundTag": "blocked",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
],
|
||||
"type": "field"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
@@ -142,28 +142,23 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 53,
|
||||
"outboundTag": "dns-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["8.8.8.8", "1.1.1.1"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:telegram"],
|
||||
"outboundTag": "proxy"
|
||||
}
|
||||
|
||||
@@ -155,51 +155,42 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 123,
|
||||
"network": "udp",
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 53,
|
||||
"network": "udp",
|
||||
"outboundTag": "dns-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["119.29.29.29", "223.5.5.5"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn"], //此处可加入 VPS IP 避免 ssh 时被代理
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1", "8.8.8.8"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"domain:googleapis.cn",
|
||||
@@ -224,7 +215,6 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"rules": [
|
||||
{
|
||||
//阻止 cnip 提高安全性,或者可以将 cn 流量导入 warp 中,详见https://xtls.github.io/document/level-2/warp.html
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
}
|
||||
|
||||
@@ -58,14 +58,12 @@ Add the following to the existing router:
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:cn"
|
||||
],
|
||||
"outboundTag": "wireguard-1"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:cn"
|
||||
],
|
||||
|
||||
@@ -74,8 +74,7 @@ IP-адрес и порт, на котором прослушивает API-се
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -108,7 +108,6 @@ FakeDNS будет использовать этот блок IP-адресов
|
||||
"routing": {
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["dns-in"], // Перехват DNS-трафика, поступающего от DNS-входа или от входящего подключения прозрачного прокси.
|
||||
"port": 53,
|
||||
"outboundTag": "dns-out"
|
||||
|
||||
@@ -169,7 +169,6 @@ outbound:
|
||||
// Запрос от bridge, и домен соответствует настроенному домену,
|
||||
// это означает, что это попытка установить обратный туннель к portal,
|
||||
// маршрутизируем на interconn, то есть подключаемся к portal
|
||||
"type": "field",
|
||||
"inboundTag": ["bridge"],
|
||||
"domain": ["full:reverse-proxy.xray.internal"],
|
||||
"outboundTag": "interconn"
|
||||
@@ -177,7 +176,6 @@ outbound:
|
||||
{
|
||||
// Трафик от portal также будет выходить из bridge, но без указанного выше домена
|
||||
// маршрутизируем на out, то есть перенаправляем на веб-сервер
|
||||
"type": "field",
|
||||
"inboundTag": ["bridge"],
|
||||
"outboundTag": "out"
|
||||
}
|
||||
@@ -242,7 +240,6 @@ inbound:
|
||||
{
|
||||
// Если входящее соединение помечено external, значит, это запрос из Интернета,
|
||||
// маршрутизируем на portal, который в конечном итоге перенаправит его на bridge
|
||||
"type": "field",
|
||||
"inboundTag": ["external"],
|
||||
"outboundTag": "portal"
|
||||
},
|
||||
@@ -251,7 +248,6 @@ inbound:
|
||||
// маршрутизируем на portal, который в конечном итоге перенаправит его соответствующему клиенту в Интернете.
|
||||
// Обратите внимание: этот запрос будет содержать домен, настроенный ранее, поэтому portal сможет различать два типа запросов,
|
||||
// маршрутизируемых на portal.
|
||||
"type": "field",
|
||||
"inboundTag": ["interconn"],
|
||||
"outboundTag": "portal"
|
||||
}
|
||||
|
||||
@@ -84,7 +84,6 @@
|
||||
"domainStrategy": "IPOnDemand",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn"], // Исключить локальную сеть и диапазоны IP-адресов Китая
|
||||
"outboundTag": "direct"
|
||||
}
|
||||
|
||||
@@ -219,7 +219,6 @@ Xray основан на проекте с открытым исходным к
|
||||
"rules": [
|
||||
// 3.1 Предотвращение проблем с локальной маршрутизацией: атаки на внутреннюю сеть, неправильная обработка локальных адресов и т. д.
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:private" // Условие: адреса из списка "private" в файле geoip (локальные адреса)
|
||||
],
|
||||
@@ -227,13 +226,11 @@ Xray основан на проекте с открытым исходным к
|
||||
},
|
||||
{
|
||||
// 3.2 Предотвращение прямого подключения к китайским серверам
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// 3.3 Блокировка рекламы
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:category-ads-all" // Условие: домены из списка "category-ads-all" в файле geosite (рекламные домены)
|
||||
],
|
||||
|
||||
@@ -150,31 +150,26 @@
|
||||
"rules": [
|
||||
// 3.1 Блокировка рекламных доменов
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// 3.2 Прямое подключение к китайским доменам
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
// 3.3 Проксирование трафика на зарубежные домены
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
// 3.4 Трафик, который идёт на DNS-сервер 223.5.5.5, отправляем напрямую
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
// 3.5 Прямое подключение к китайским IP-адресам
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn", "geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
}
|
||||
|
||||
@@ -125,7 +125,6 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["inbound-10808"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -140,18 +139,16 @@
|
||||
|
||||
Обратите внимание на конфигурацию маршрутизации. Мы видим несколько новых терминов:
|
||||
|
||||
1. `"domainStrategy": "AsIs"`
|
||||
2. `“rules”`
|
||||
3. `"type": "field"`
|
||||
4. `"inboundTag": ["inbound-10808"]`
|
||||
5. `"outboundTag": "proxy-out-vless"`
|
||||
1. "domainStrategy": "AsIs"
|
||||
2. “rules”
|
||||
3. "inboundTag": ["inbound-10808"]
|
||||
4. "outboundTag": "proxy-out-vless"
|
||||
|
||||
Пока оставим `domainStrategy` в стороне и кратко объясним остальные:
|
||||
|
||||
| Название параметра | Значение параметра | Описание параметра |
|
||||
| :----------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `“rules”` | | Внутри этого параметра находятся подробные настройки **правил маршрутизации**. |
|
||||
| `"type"` | `"field"` | На данный момент этот параметр не имеет особого значения, но его нельзя опускать, поэтому просто укажите его. |
|
||||
| `"inboundTag"` | `["inbound-10808"]` | **Критерий** фильтрации трафика - это **тег входящего трафика**, а **условие** сейчас только одно: **источник входящего трафика - `inbound-10808`**. |
|
||||
| `"outboundTag"` | `"proxy-out-vless"` | Если указанное выше условие фильтрации выполняется (т.е. входящий трафик имеет `[tag]="inbound-10808"`), `Xray` направит трафик на исходящий трафик с `[tag]="proxy-out-vless"`. |
|
||||
|
||||
@@ -242,17 +239,14 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
|
||||
@@ -57,19 +57,16 @@
|
||||
"rules": [
|
||||
// Прямое подключение для определенного поддомена
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// Проксирование для определенного поддомена
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:proxy.yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// Проксирование для всех поддоменов
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -95,13 +92,11 @@
|
||||
"rules": [
|
||||
// Прямое подключение для локальных и внутренних IP-адресов
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// Прямое подключение для китайских IP-адресов
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
@@ -124,13 +119,11 @@
|
||||
"rules": [
|
||||
// Прямое подключение для определенного IP-адреса
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// Проксирование для определенного IP-адреса
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -154,7 +147,6 @@
|
||||
"rules": [
|
||||
// Прямое подключение для торрент-трафика
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
@@ -203,33 +195,28 @@
|
||||
// [1-block Блокировка рекламы]
|
||||
// 1.1 Блокировка рекламных доменов
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// [2-direct Прямое подключение к внутренним ресурсам]
|
||||
// 2.1 Прямое подключение для китайских доменов и определенного поддомена
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn", "full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.2 Прямое подключение для локальных, внутренних, китайских и определенных IP-адресов
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn", "223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.3 Прямое подключение для торрент-трафика
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// [3-proxy Проксирование для внешних ресурсов]
|
||||
// 3.1 Проксирование для иностранных доменов, определенного поддомена и всех поддоменов
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"full:proxy.yourdomain.com",
|
||||
@@ -239,7 +226,6 @@
|
||||
},
|
||||
// 3.2 Проксирование для определенного IP-адреса
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
@@ -310,7 +296,6 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
@@ -340,12 +325,10 @@
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
|
||||
@@ -237,38 +237,31 @@ WantedBy=multi-user.target
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"port": 123,
|
||||
"network": "udp",
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["tproxy-in"],
|
||||
"outboundTag": "nginxtls"
|
||||
}
|
||||
|
||||
@@ -181,11 +181,9 @@ lsmod | grep wireguard
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
"outboundTag": "api"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "wg0",
|
||||
"inboundTag": [
|
||||
"<inboundTag>"
|
||||
@@ -197,8 +195,7 @@ lsmod | grep wireguard
|
||||
"outboundTag": "blocked",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
],
|
||||
"type": "field"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
@@ -143,28 +143,23 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 53,
|
||||
"outboundTag": "dns-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["8.8.8.8", "1.1.1.1"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:telegram"],
|
||||
"outboundTag": "proxy"
|
||||
}
|
||||
|
||||
@@ -159,51 +159,42 @@ title: Прозрачное проксирование TProxy (ipv4 и ipv6)
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 123,
|
||||
"network": "udp",
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["all-in"],
|
||||
"port": 53,
|
||||
"network": "udp",
|
||||
"outboundTag": "dns-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["119.29.29.29", "223.5.5.5"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn"], // Здесь можно добавить IP-адрес VPS, чтобы избежать проксирования трафика SSH.
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1", "8.8.8.8"],
|
||||
"outboundTag": "proxy"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"domain:googleapis.cn",
|
||||
@@ -229,7 +220,6 @@ title: Прозрачное проксирование TProxy (ipv4 и ipv6)
|
||||
{
|
||||
// Блокировка китайских IP-адресов для повышения безопасности.
|
||||
// Также можно направить китайский трафик через Warp, см. https://xtls.github.io/document/level-2/warp.html
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
}
|
||||
|
||||
@@ -157,14 +157,12 @@ bash -c "$(curl -L wgcf-cli.vercel.app)"
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:cn"
|
||||
],
|
||||
"outboundTag": "wireguard-1"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:cn"
|
||||
],
|
||||
|
||||
Reference in New Issue
Block a user