Direct/Freedom outbound: Better Compatibility (#896)

https://github.com/XTLS/Xray-core/pull/6058
This commit is contained in:
Meow
2026-09-11 06:46:51 +08:00
committed by GitHub
parent 9125d3237c
commit b7207f4da4
30 changed files with 451 additions and 477 deletions
+3 -3
View File
@@ -34,11 +34,11 @@ The answer is: **Absolutely.**
By making reasonable use of Xray's ~~wheelchair-like~~ powerful built-in DNS features—such as Fallbacks, ECS (EDNS Client Subnet), IP filtering, and Tagging—and carefully adjusting their order, you can obtain a much more accurate and real-time routing condition than `geosite cn/!cn`: the IP address. This works because IP geolocation, especially CN geolocation, changes much less frequently than domain lists.
Before reading further, you need to fully read and understand the "Beginner Skills: Analysis of the Routing Feature [Part 1](./routing-lv1-part1.md) & [Part 2](./routing-lv1-part2.md)".
At the same time, you should have practically memorized the official configuration guide. You must fully understand the functions of `domainStrategy` in routing/outbounds, `sniffing` options in inbounds, and the behaviors produced by their different combinations.
At the same time, you should have practically memorized the official configuration guide. You must fully understand the functions of `domainStrategy` in routing and `sockopt`, `targetStrategy` in outbounds, `sniffing` options in inbounds, and the behaviors produced by their different combinations.
Ready? Please try to understand the following paragraph:
When using **socks/http inbounds**, the request is a domain name. When it reaches the **Routing** module, a `domainStrategy` other than `AsIs` can use the built-in DNS to resolve an IP specifically for routing matching. When the traffic reaches a local **direct outbound**, a `domainStrategy` other than `AsIs` in the outbound can use the built-in DNS to resolve the IP again for the actual connection. The request sent to the Xray Server (remote) contains only the domain name; which IP is actually accessed depends on the server's direct outbound.
When using **socks/http inbounds**, the original request targets a domain name. When it reaches the **Routing** module, a `domainStrategy` other than `AsIs` can use the built-in DNS to resolve IPs temporarily for routing rule matching. If the traffic is routed to a local **direct outbound**, a `domainStrategy` other than `AsIs` in `sockopt` can use the built-in DNS to resolve IPs again for the outbound connection. If the traffic is routed to a remote Xray server and `targetStrategy` on the local outbound is `AsIs`, the request target is still sent as a domain name; which IP is actually accessed depends on the server's direct outbound.
The situation becomes more complex with **Transparent Proxy**. If inbound `sniffing` is enabled and `destOverride` includes `[http, tls]`:
@@ -262,7 +262,7 @@ In a realIp transparent proxy environment, you can even ensure that after hijack
In this scenario, since all requests sent to the Xray Server are domain names, there is no need to use DNS to repeatedly probe for the optimal result. We only need to quickly identify if the domain is polluted and resolve a Chinese CDN-friendly IP as much as possible.
The China IP resolved by the DNS module in this example is already 99% China CDN friendly. Therefore, you can set `domainStrategy` in the direct outbound to **non-AsIs** to utilize the cache if you wish.
The China IP resolved by the DNS module in this example is already 99% China CDN friendly. Therefore, you can set `sockopt.domainStrategy` in the direct outbound to **non-AsIs** to utilize the cache if you wish.
<br>
If you pursue 100% China CDN friendliness, you can set it to `AsIs` to use the OS configured DNS to resolve it again. This adds about 1ms to hundreds of ms of latency; it is recommended to enable optimistic caching to further reduce latency.
+13 -13
View File
@@ -113,8 +113,10 @@ lsmod | grep wireguard
"outbounds": [
{
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIPv4"
"streamSettings": {
"sockopt": {
"domainStrategy": "UseIPv4"
}
}
// Modify here, can be v4 or v6
},
@@ -124,11 +126,9 @@ lsmod | grep wireguard
"tag": "wg0",
"streamSettings": {
"sockopt": {
"mark": 255 // <mark>
"mark": 255, // <mark>
"domainStrategy": "UseIPv6"
}
},
"settings": {
"domainStrategy": "UseIPv6"
}
}, // Users with fwmark set to <mark> use the specified strategy "UseIPv6" or "UseIPv4"
// <--Please choose between different schemes--> Scheme 2: sendThrough
@@ -137,8 +137,10 @@ lsmod | grep wireguard
"protocol": "freedom",
"sendThrough": "your wg0 v4 address",
// Modify here, can be v4 or v6
"settings": {
"domainStrategy": "UseIPv4"
"streamSettings": {
"sockopt": {
"domainStrategy": "UseIPv4"
}
}
// Modify here, can be v4 or v6
},
@@ -146,12 +148,10 @@ lsmod | grep wireguard
{
"tag": "wg0",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"sockopt": {
"interface": "wg0"
"interface": "wg0",
"domainStrategy": "UseIPv4"
}
}
},
@@ -192,7 +192,7 @@ lsmod | grep wireguard
```
::: tip
You can control the access method for corresponding users by modifying `"domainStrategy": "UseIPv6"`. Actual tests show priority is higher than the system's own `gai.config`.
You can control the access method for corresponding users by setting `sockopt.domainStrategy` to `UseIPv6`.
:::
## 5. System Settings Configuration
+4 -8
View File
@@ -52,12 +52,10 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
{
"tag": "direct",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"sockopt": {
"mark": 2
"mark": 2,
"domainStrategy": "UseIPv4"
}
}
},
@@ -94,12 +92,10 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
"settings": {
"rewriteAddress": "8.8.8.8"
},
"proxySettings": {
"tag": "proxy"
},
"streamSettings": {
"sockopt": {
"mark": 2
"mark": 2,
"dialerProxy": "proxy"
}
}
}
@@ -93,12 +93,10 @@ If the Xray program is not installed on the side router, you can manually downlo
{
"tag": "direct",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIP"
},
"streamSettings": {
"sockopt": {
"mark": 255
"mark": 255,
"domainStrategy": "UseIP"
}
}
},