mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-10-07 06:18:10 +03:00
EN: Retranslate all documents via Gemini Pro 3, Human proofreading
This commit is contained in:
@@ -1,35 +1,35 @@
|
||||
# Advanced Documentation
|
||||
|
||||
**This chapter contains experience sharing of using Xray at an advanced level. If you are already familiar with Xray, the experience shared here can help you unleash the full power of Xray.**
|
||||
**This section contains advanced insights into using Xray. If you are already familiar with Xray, the experiences shared here will help you further unleash its full potential.**
|
||||
|
||||
[Beginner's Guide to Transparent Proxies](./transparent_proxy/transparent_proxy.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="32" height="32" alt="a"/> [@kirin](https://github.com/kirin10000)
|
||||
[Introduction to Transparent Proxy](./transparent_proxy/transparent_proxy.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="32" height="32" alt="a"/> [@kirin](https://github.com/kirin10000)
|
||||
|
||||
An Introduction to Transparent Proxies.
|
||||
An introductory chapter on Transparent Proxy.
|
||||
|
||||
[TProxy Configuration Tutorial](./tproxy.md) by <img src="https://avatars2.githubusercontent.com/u/41363844?s=32" width="32" height="32" alt="a"/> [@BioniCosmos](https://github.com/BioniCosmos)
|
||||
[Transparent Proxy (TProxy) Configuration Tutorial](./tproxy.md) by <img src="https://avatars2.githubusercontent.com/u/41363844?s=32" width="32" height="32" alt="a"/> [@BioniCosmos](https://github.com/BioniCosmos)
|
||||
|
||||
Complete tutorial on configuring transparent proxy (TProxy) based on Xray.
|
||||
A complete tutorial on configuring Transparent Proxy (TProxy) based on Xray.
|
||||
|
||||
[TProxy Transparent Proxy (IPv4 and IPv6) Configuration Tutorial](./tproxy_ipv4_and_ipv6.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="32" height="32" alt="a"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
Xray-based TProxy Transparent Proxy (IPv4 and IPv6) Configuration Tutorial
|
||||
Configuration tutorial for Xray-based TProxy Transparent Proxy (IPv4 and IPv6).
|
||||
|
||||
[Nginx_TLS Tunnel Hidden Fingerprint](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="32" height="32" alt="a"/> [@SQLimit](https://github.com/SQLimit)
|
||||
[Using Nginx or HAProxy to Build TLS Tunnels to Hide Fingerprints](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="32" height="32" alt="a"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
Use Nginx_TLS tunnel on both ends to hide the fingerprint.
|
||||
Using Nginx or HAProxy on both ends to build a TLS tunnel for fingerprint hiding.
|
||||
|
||||
[[Transparent Proxy] Avoiding Xray Traffic Through gid](./iptables_gid.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="32" height="32" alt="a"/> [@kirin](https://github.com/kirin10000)
|
||||
[[Transparent Proxy] Bypassing Xray Traffic via GID](./iptables_gid.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="32" height="32" alt="a"/> [@kirin](https://github.com/kirin10000)
|
||||
|
||||
A new way of bypassing Xray traffic in transparent proxy implemented by iptables/nftables.
|
||||
A new method to bypass Xray traffic in transparent proxies implemented via iptables/nftables.
|
||||
|
||||
[Redirect Specific Traffic to Specific Gateway using Xray to Achieve Global Routing "Load Balancing"](./redirect.md) by <img src="https://avatars.githubusercontent.com/u/28607089?s=32" width="32" height="32" alt="a"/> [@Zzz3m](https://github.com/Zzz3m)
|
||||
[Directing Specific Traffic to Specific Exits via Xray for Global Routing "Traffic Splitting"](./redirect.md) by <img src="https://avatars.githubusercontent.com/u/28607089?s=32" width="32" height="32" alt="a"/> [@Zzz3m](https://github.com/Zzz3m)
|
||||
|
||||
Play Xray to the fullest: Implement "load balancing" based on fwmark or sendThrough.
|
||||
Getting creative with Xray: Achieving "traffic splitting" based on fwmark, sendThrough, or sockopt.interface.
|
||||
|
||||
[Enhancing Proxy Security with Cloudflare Warp](./warp.md) by <img src="https://avatars.githubusercontent.com/u/1588741?s=32" width="32" height="32" alt="a"/> [@yuhan6665](https://github.com/yuhan6665)
|
||||
[Enhancing Proxy Security via Cloudflare Warp](./warp.md) by <img src="https://avatars.githubusercontent.com/u/1588741?s=32" width="32" height="32" alt="a"/> [@yuhan6665](https://github.com/yuhan6665)
|
||||
|
||||
Introduction to using WireGuard for outbound traffic added in Xray v1.6.5.
|
||||
Introduction to the use of the WireGuard outbound added in Xray v1.6.5.
|
||||
|
||||
[Xray Traffic Statistics](./traffic_stats.md) by <img src="https://avatars.githubusercontent.com/u/1588741?s=32" width="32" height="32" alt="a"/> [@yuhan6665](https://github.com/yuhan6665)
|
||||
|
||||
Adapt traffic statistics and scripts compatible with Xray.
|
||||
Traffic statistics and scripts adapted for Xray.
|
||||
|
||||
@@ -1,98 +1,97 @@
|
||||
---
|
||||
title: Transparent proxy via GID
|
||||
title: GID Transparent Proxy
|
||||
---
|
||||
|
||||
# Transparent proxy to circumvent Xray traffic via GID
|
||||
# Transparent Proxy: Bypassing Xray Traffic via GID
|
||||
|
||||
In the existing transparent proxy configuration(**[New V2Ray vernacular tutorial on transparent proxy](https://guide.v2fly.org/app/transparent_proxy.html)** 、 **[New V2Ray vernacular tutorial on transparent proxy (TProxy)](https://guide.v2fly.org/app/tproxy.html)** 、 **[Transparent proxy(TProxy)configuration tutorial](./tproxy.md)**)tutorials, the circumvention of Xray traffic is achieved by using mark. That is, mark outbound traffics and set up iptables rules which directly connect traffics corresponding to the mark, to circumvent the Xray traffic and prevent loop back.
|
||||
In existing `iptables` transparent proxy guides (**[New V2Ray Plain English Guide - Transparent Proxy](https://guide.v2fly.org/app/transparent_proxy.html)**, **[New V2Ray Plain English Guide - Transparent Proxy (TPROXY)](https://guide.v2fly.org/app/tproxy.html)**, **[Transparent Proxy (TProxy) Configuration Tutorial](./tproxy)**), the method used to bypass Xray traffic (to prevent routing loops) involves marking packets (`mark`). Specifically, marks are applied to Xray's outbound traffic, and `iptables` rules are set to direct traffic with corresponding marks to go out directly, thus bypassing the Xray proxy process.
|
||||
|
||||
There are several problems with this method:
|
||||
There are several issues with this approach:
|
||||
|
||||
1. **[Inexplicable traffic into PREROUTING chain](https://github.com/v2ray/v2ray-core/issues/2621)**
|
||||
1. **[Unexplained traffic entering the PREROUTING chain](https://github.com/v2ray/v2ray-core/issues/2621)**.
|
||||
2. Android systems have their own marking mechanism, making this solution unusable on Android.
|
||||
|
||||
2. Android has its own mark mechanism and this solution is not available on Android
|
||||
The solution in this tutorial does not require setting marks. Theoretically, it offers higher performance and avoids the issues mentioned above.
|
||||
|
||||
The solution in this tutorial does not require a mark setting and has a higher theoretical performance, as well as not having the problems mentioned above.
|
||||
## Concept
|
||||
|
||||
## Ideas
|
||||
TProxy traffic can only be received by the root user (`uid==0`) or other users with `CAP_NET_ADMIN` privileges.
|
||||
|
||||
TProxy traffic can only be received by users with root privileges (uid==0) or other users with CAP_NET_ADMIN privileges.
|
||||
`iptables` rules can route traffic based on UID (User ID) and GID (Group ID).
|
||||
|
||||
The iptables rules can separate network traffic by uid (user id) and gid (user group id).
|
||||
Let Xray run on a user with uid==0 but gid!=0. Set the iptables rule to not proxy traffic for that gid to circumvent Xray traffic.
|
||||
By running Xray as a user with `uid==0` but `gid!=0`, we can set `iptables` rules to exclude traffic from that specific GID, thereby bypassing Xray traffic.
|
||||
|
||||
## Configuration Procedure
|
||||
## Configuration Process
|
||||
|
||||
### 1. Preliminary preparation
|
||||
### 1. Prerequisites
|
||||
|
||||
**Android**
|
||||
**Android System**
|
||||
|
||||
1. System has root privilege.
|
||||
1. System must be rooted.
|
||||
2. Install **[busybox](https://play.google.com/store/apps/details?id=stericson.busybox)**.
|
||||
3. Have a terminal capable of executing commands, such as `adb shell`, `termux`, etc.
|
||||
|
||||
2. Install **[busybox](https://play.google.com/store/apps/details?id=stericson.busybox)**
|
||||
**Other Linux Systems**
|
||||
|
||||
3. There is a terminal that can execute commands, you can use adb shell, termux etc.
|
||||
Requires dependencies: `sudo`, `iptables-mod-tproxy`, and `iptables-mod-extra`.
|
||||
|
||||
**Other Linux system**
|
||||
|
||||
Need sudo, iptables-tproxy module and iptables-extra module。
|
||||
|
||||
Usually the system comes with these functions. If you are using openwrt, you will need to run the following command:
|
||||
Most systems come with these built-in. For OpenWrt, run:
|
||||
|
||||
```bash
|
||||
opkg install sudo iptables-mod-tproxy iptables-mod-extra
|
||||
```
|
||||
|
||||
Also attached are some common dependencies for openwrt, the lack of which may prevent Xray from running
|
||||
Here are some common dependencies for OpenWrt. Missing them might prevent Xray from running:
|
||||
|
||||
```bash
|
||||
opkg install libopenssl ca-certificates
|
||||
```
|
||||
|
||||
### 2. Add user (Android users please ignore this section)
|
||||
### 2. Add User (Skip for Android users)
|
||||
|
||||
Android does not support managing users by modifying the /etc/passwd file, please ignore it and go straight to the next step.
|
||||
Android systems do not support managing users via the `/etc/passwd` file, so please ignore this and proceed to the next step.
|
||||
|
||||
```bash
|
||||
grep -qw xray_tproxy /etc/passwd || echo "xray_tproxy:x:0:23333:::" >> /etc/passwd
|
||||
```
|
||||
|
||||
where xray_tproxy is the username, 0 is the uid and 23333 is the gid, the username and gid can be set by yourself, the uid must be 0.
|
||||
To check if the user was added successfully, run
|
||||
Here, `xray_tproxy` is the username, `0` is the UID, and `23333` is the GID. The username and GID can be customized, but the UID must be 0.
|
||||
To check if the user was added successfully, run:
|
||||
|
||||
```bash
|
||||
sudo -u xray_tproxy id
|
||||
```
|
||||
|
||||
The result displayed should be uid 0 and gid 23333.
|
||||
The displayed result should show UID as 0 and GID as 23333.
|
||||
|
||||
### 3. Configure and run Xray, and configure iptables rules
|
||||
### 3. Configure/Run Xray and Set iptables Rules
|
||||
|
||||
In the existing transparent proxy configuration(**[New V2Ray vernacular tutorial on transparent proxy](https://guide.v2fly.org/app/transparent_proxy.html)** 、 **[New V2Ray vernacular tutorial on transparent proxy (TProxy)](https://guide.v2fly.org/app/tproxy.html)** 、 **[Transparent proxy(TProxy)configuration tutorial](./tproxy.md)**)tutorials, modify:
|
||||
Modify based on the existing `iptables` transparent proxy guides (**[New V2Ray Plain English Guide - Transparent Proxy](https://guide.v2fly.org/app/transparent_proxy.html)**, **[New V2Ray Plain English Guide - Transparent Proxy (TPROXY)](https://guide.v2fly.org/app/tproxy.html)**, **[Transparent Proxy (TProxy) Configuration Tutorial](./tproxy)**):
|
||||
|
||||
1. Modify the json configuration file: remove mark-related content
|
||||
1. Modify the JSON configuration file to delete content related to `mark`.
|
||||
2. Modify `iptables` rules to delete content related to `mark`, and add the option `-m owner ! --gid-owner 23333` to the rule applied in the OUTPUT chain.
|
||||
|
||||
2. Modify the iptables rule to remove the mark-related content and add the option at the OUTPUT chain application rule: `-m owner ! --gid-owner 23333`
|
||||
For example:
|
||||
|
||||
e.g.:
|
||||
```bash
|
||||
iptables -t mangle -A OUTPUT -j XRAY_SELF
|
||||
```
|
||||
|
||||
`iptables -t mangle -A OUTPUT -j XRAY_SELF`
|
||||
Change to:
|
||||
|
||||
Change to
|
||||
```bash
|
||||
iptables -t mangle -A OUTPUT -m owner ! --gid-owner 23333 -j XRAY_SELF
|
||||
```
|
||||
|
||||
`iptables -t mangle -A OUTPUT -m owner ! --gid-owner 23333 -j XRAY_SELF`
|
||||
1. Modify the way Xray is run so that it runs as a user with `uid=0` and `gid=23333`. Refer to [this section](#_3-configure-max-open-files-run-xray-client).
|
||||
|
||||
1. Modify the way you run Xray so that it runs on a user with uid 0 and gid 23333, refer to [here](#_3-configure-and-run-xray-and-configure-iptables-rules).
|
||||
## Below is a complete configuration process for implementing global TProxy
|
||||
|
||||
## Steps
|
||||
### 1. Complete the Prerequisites and User Addition steps above
|
||||
|
||||
The following provides a complete configuration process for implementing the tproxy global proxy
|
||||
### 2. Prepare Xray Configuration File
|
||||
|
||||
### 1. Finish **[Preliminary preparation](#_1-preliminary-preparation)** and **[Add user](#_2-add-user-android-users-please-ignore-this-section)**
|
||||
|
||||
### 2. Preparing Xray profiles
|
||||
|
||||
Configure Xray to listen to 12345 at dokodemo-door, turn on followRedirect and tproxy, no sniffing required:
|
||||
Configure Xray `dokodemo-door` to listen on port 12345, enable `followRedirect` and `tproxy`. Setting `sniffing` is not required:
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -113,60 +112,60 @@ Configure Xray to listen to 12345 at dokodemo-door, turn on followRedirect and t
|
||||
],
|
||||
"outbounds": [
|
||||
{
|
||||
// Your server configuration
|
||||
Your Server Configuration
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
### 3. Configuring the maximum number of open files and run the Xray client
|
||||
### 3. Configure Max Open Files & Run Xray Client
|
||||
|
||||
About the maximum number of open files, see: **[too many open files issues](https://guide.v2fly.org/app/tproxy.html#解决-too-many-open-files-问题)**
|
||||
For issues regarding the maximum number of open files, see: **[Too many open files issue](https://guide.v2fly.org/app/tproxy.html#解决-too-many-open-files-问题)**.
|
||||
|
||||
The current Xray server installed with the official script has the maximum number of open files automatically configured, so no further changes are required.
|
||||
Currently, Xray servers installed using the official script automatically configure the maximum open file limit, so no further modification is needed.
|
||||
|
||||
**Android**
|
||||
**Android System**
|
||||
|
||||
```bash
|
||||
ulimit -SHn 1000000
|
||||
setuidgid 0:23333 "Command to run Xray"&
|
||||
```
|
||||
|
||||
**Other Linux system**
|
||||
**Other Linux Systems**
|
||||
|
||||
```bash
|
||||
ulimit -SHn 1000000
|
||||
sudo -u xray_tproxy "Command to run Xray"&
|
||||
```
|
||||
|
||||
e.g.:
|
||||
For example:
|
||||
|
||||
```bash
|
||||
ulimit -SHn 1000000
|
||||
sudo -u xray_tproxy xray -c /etc/xray/config.json &
|
||||
```
|
||||
|
||||
_The first command:_
|
||||
*First command:*
|
||||
|
||||
Change the maximum number of open files, valid only for the current terminal and to be run every time before starting Xray, this command is to set the maximum number of open files for the client.
|
||||
Changes the maximum number of open files. It is only effective for the current terminal and must be run every time before starting Xray. This command sets the maximum file limit for the client.
|
||||
|
||||
_The second command:_
|
||||
*Second command:*
|
||||
|
||||
Run the Xray client as a user with uid 0 and gid not 0, followed by & for running in the background.
|
||||
Runs the Xray client as a user with `uid=0` and a non-zero `gid`. The `&` at the end indicates running in the background.
|
||||
|
||||
**Check if the maximum number of open files is set successfully**
|
||||
**Check if Max Open Files was set successfully**
|
||||
|
||||
```bash
|
||||
cat /proc/"Xray's pid"/limits
|
||||
cat /proc/PID_OF_XRAY/limits
|
||||
```
|
||||
|
||||
Find max open files, which should be the value you set. Xray's pid can be obtained by running `ps` or `ps -aux` or `ps -a`
|
||||
Find the `max open files` item; it should match the value you set. You can get the PID by running `ps`, `ps -aux`, `ps -a`, or `pidof xray`.
|
||||
|
||||
Both the server and client side should be checked.
|
||||
Check both the server and the client.
|
||||
|
||||
### 4. Setting up iptables rules
|
||||
### 4. Set iptables Rules
|
||||
|
||||
**Proxy ipv4**
|
||||
**Proxy IPv4**
|
||||
|
||||
```bash
|
||||
ip rule add fwmark 1 table 100
|
||||
@@ -174,31 +173,40 @@ ip route add local 0.0.0.0/0 dev lo table 100
|
||||
|
||||
# Proxy LAN devices
|
||||
iptables -t mangle -N XRAY
|
||||
# "ipv4 segment where the gateway is located" is obtained by running the command "ip address | grep -w inet | awk '{print $2}'", usually there are multiple
|
||||
iptables -t mangle -A XRAY -d "first ipv4 segment where the gateway is located" -j RETURN
|
||||
iptables -t mangle -A XRAY -d "second ipv4 segment where the gateway is located" -j RETURN
|
||||
# "Gateway IPv4 subnet" is obtained by running "ip address | grep -w inet | awk '{print $2}'". There are usually multiple.
|
||||
iptables -t mangle -A XRAY -d Gateway_IPv4_Subnet_1 -j RETURN
|
||||
iptables -t mangle -A XRAY -d Gateway_IPv4_Subnet_2 -j RETURN
|
||||
...
|
||||
|
||||
# If the gateway is used as the primary router, add this line, see: [Other considerations for transparent proxy of iptables](https://xtls.github.io/en/documents/level-2/transparent_proxy/transparent_proxy/#proxy-ipv6)
|
||||
# The "gateway LAN_IPv4 address segment", obtained by running the command "ip address | grep -w "inet" | awk '{print $2}'", is one of the results
|
||||
iptables -t mangle -A XRAY ! -s "gateway LAN_IPv4 address segment" -j RETURN
|
||||
# Direct connection for Multicast/Class E/Broadcast addresses
|
||||
iptables -t mangle -A XRAY -d 224.0.0.0/3 -j RETURN
|
||||
|
||||
# Mark 1 for TCP and forward to port 12345
|
||||
# mark can only be set to 1 for the traffic to be accepted by the Xray dokodemo-door
|
||||
|
||||
# If the gateway serves as the main router, add this line.
|
||||
# See: [https://xtls.github.io/documents/level-2/transparent_proxy/transparent_proxy.md#iptables透明代理的其它注意事项](https://xtls.github.io/documents/level-2/transparent_proxy/transparent_proxy.md#iptables透明代理的其它注意事项)
|
||||
# Gateway_LAN_IPv4_Subnet is one of the results from "ip address | grep -w "inet" | awk '{print $2}'".
|
||||
iptables -t mangle -A XRAY ! -s Gateway_LAN_IPv4_Subnet -j RETURN
|
||||
|
||||
# Mark TCP packets with 1, forward to port 12345
|
||||
# Traffic is accepted by Xray dokodemo-door only if mark is set to 1
|
||||
iptables -t mangle -A XRAY -p tcp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A XRAY -p udp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
# Apply rules
|
||||
iptables -t mangle -A PREROUTING -j XRAY
|
||||
|
||||
# Proxy gateway itself
|
||||
# Proxy the Gateway itself
|
||||
iptables -t mangle -N XRAY_MASK
|
||||
iptables -t mangle -A XRAY_MASK -d "the first ipv4 segment where the gateway is located" -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d "the second ipv4 segment where the gateway is located" -j RETURN
|
||||
|
||||
iptables -t mangle -A XRAY_MASK -m owner --gid-owner 23333 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d Gateway_IPv4_Subnet_1 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d Gateway_IPv4_Subnet_2 -j RETURN
|
||||
...
|
||||
iptables -t mangle -A XRAY_MASK -d 224.0.0.0/3 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -m owner ! --gid-owner 23333 ! -p icmp -j XRAY_MASK
|
||||
iptables -t mangle -A OUTPUT -p tcp -j XRAY_MASK
|
||||
iptables -t mangle -A OUTPUT -p udp -j XRAY_MASK
|
||||
```
|
||||
|
||||
**Proxy ipv6 (optional)**
|
||||
**Proxy IPv6 (Optional)**
|
||||
|
||||
```bash
|
||||
ip -6 rule add fwmark 1 table 106
|
||||
@@ -206,23 +214,27 @@ ip -6 route add local ::/0 dev lo table 106
|
||||
|
||||
# Proxy LAN devices
|
||||
ip6tables -t mangle -N XRAY6
|
||||
# The "ipv6 segment where the gateway is located" is obtained by running the command "ip address | grep -w inet6 | awk '{print $2}'".
|
||||
ip6tables -t mangle -A XRAY6 -d "the first ipv6 segment where the gateway is located" -j RETURN
|
||||
ip6tables -t mangle -A XRAY6 -d "the second ipv6 segment where the gateway is located" -j RETURN
|
||||
# "Gateway IPv6 subnet" is obtained by running "ip address | grep -w inet6 | awk '{print $2}'".
|
||||
ip6tables -t mangle -A XRAY6 -d Gateway_IPv6_Subnet_1 -j RETURN
|
||||
ip6tables -t mangle -A XRAY6 -d Gateway_IPv6_Subnet_2 -j RETURN
|
||||
...
|
||||
|
||||
# If the gateway is used as the primary router, add this line, see: [Other considerations for transparent proxy of iptables](https://xtls.github.io/en/documents/level-2/transparent_proxy/transparent_proxy/#proxy-ipv6)
|
||||
# The "gateway LAN_IPv6 address segment", obtained by running the command "ip address | grep -w "inet6" | awk '{print $2}'", is one of the results
|
||||
ip6tables -t mangle -A XRAY6 ! -s "gateway LAN_IPv6 address segment" -j RETURN
|
||||
# If the gateway serves as the main router, add this line.
|
||||
# See: [https://xtls.github.io/documents/level-2/transparent_proxy/transparent_proxy.md#iptables透明代理的其它注意事项](https://xtls.github.io/documents/level-2/transparent_proxy/transparent_proxy.md#iptables透明代理的其它注意事项)
|
||||
# Gateway_LAN_IPv6_Subnet is one of the results from "ip address | grep -w "inet6" | awk '{print $2}'".
|
||||
ip6tables -t mangle -A XRAY6 ! -s Gateway_LAN_IPv6_Subnet -j RETURN
|
||||
|
||||
ip6tables -t mangle -A XRAY6 -p udp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
ip6tables -t mangle -A XRAY6 -p tcp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
ip6tables -t mangle -A PREROUTING -j XRAY6
|
||||
|
||||
# Proxy gateway itself
|
||||
# Proxy the Gateway itself
|
||||
ip6tables -t mangle -N XRAY6_MASK
|
||||
ip6tables -t mangle -A XRAY6_MASK -d "the first ipv6 segment where the gateway is located" -j RETURN
|
||||
ip6tables -t mangle -A XRAY6_MASK -d "the second ipv6 segment where the gateway is located" -j RETURN
|
||||
|
||||
ip6tables -t mangle -A XRAY6_MASK -m owner --gid-owner 23333 -j RETURN
|
||||
ip6tables -t mangle -A XRAY6_MASK -d Gateway_IPv6_Subnet_1 -j RETURN
|
||||
ip6tables -t mangle -A XRAY6_MASK -d Gateway_IPv6_Subnet_2 -j RETURN
|
||||
...
|
||||
ip6tables -t mangle -A XRAY6_MASK -j MARK --set-mark 1
|
||||
ip6tables -t mangle -A OUTPUT -m owner ! --gid-owner 23333 ! -p icmp -j XRAY6_MASK
|
||||
ip6tables -t mangle -A OUTPUT -p tcp -j XRAY6_MASK
|
||||
ip6tables -t mangle -A OUTPUT -p udp -j XRAY6_MASK
|
||||
```
|
||||
|
||||
@@ -1,18 +1,18 @@
|
||||
---
|
||||
title: Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹
|
||||
title: Using Nginx or HAProxy to Build TLS Tunnels to Hide Fingerprints
|
||||
---
|
||||
|
||||
Nginx 或 Haproxy 实现的 HTTPS 隧道、HTTP/2 over HTTPS 隧道、WebSocket over HTTP/2 over HTTPS 隧道、gRPC over HTTP/2 over HTTPS 隧道以及自签证书双端认证的 gRPC over HTTP/2 over HTTPS 隧道
|
||||
HTTPS tunnels, HTTP/2 over HTTPS tunnels, WebSocket over HTTP/2 over HTTPS tunnels, gRPC over HTTP/2 over HTTPS tunnels implemented via Nginx or HAProxy, and gRPC over HTTP/2 over HTTPS tunnels with self-signed certificate mutual authentication.
|
||||
|
||||
# 客户端服务端 Nginx 构建 HTTPS 隧道隐藏指纹
|
||||
# Building HTTPS Tunnels with Nginx on Client & Server to Hide Fingerprints
|
||||
|
||||
网路结构:
|
||||
Network Structure:
|
||||
|
||||
xray_client ---tcp--- nginx_client ---HTTPS--- nginx_sever ---tcp--- xray_server
|
||||
|
||||
## 编译 nginx --with-stream
|
||||
## Compile Nginx --with-stream
|
||||
|
||||
在客户端及服务端均编译
|
||||
Compile on both the client and the server.
|
||||
|
||||
`curl -O -L http://nginx.org/download/nginx-1.22.1.tar.gz`
|
||||
|
||||
@@ -20,45 +20,44 @@ xray_client ---tcp--- nginx_client ---HTTPS--- nginx_sever ---tcp--- xray_server
|
||||
|
||||
`cd nginx-1.22.1`
|
||||
|
||||
`apt install gcc make` //编译依赖 gcc 以及 make
|
||||
`apt install gcc make` // Install compilation dependencies: gcc and make
|
||||
|
||||
`./configure --prefix=/usr/local/nginx --with-http_ssl_module --with-http_v2_module --with-stream --with-stream_ssl_module` //此步需要依赖一些库,根据报错安装相应 lib
|
||||
`./configure --prefix=/usr/local/nginx --with-http_ssl_module --with-http_v2_module --with-stream --with-stream_ssl_module` // This step requires some libraries; install the corresponding libs based on any errors reported.
|
||||
|
||||
`make && make install`
|
||||
|
||||
编译之后 nginx 文件夹位于 `/usr/local/nginx`
|
||||
After compilation, the nginx folder is located at `/usr/local/nginx`.
|
||||
|
||||
## 配置 nginx
|
||||
## Configure Nginx
|
||||
|
||||
编辑 nginx 配置文件 nginx.conf
|
||||
Edit the nginx configuration file `nginx.conf`.
|
||||
|
||||
`vim /usr/local/nginx/conf/nginx.conf`
|
||||
|
||||
服务端加入如下配置
|
||||
Add the following configuration to the **Server**:
|
||||
|
||||
服务器申请证书不再赘述,参考[白话文](../level-0/ch06-certificates.md)
|
||||
(I won't go into detail about applying for server certificates; refer to the [Plain Language Guide](../level-0/ch06-certificates.md)).
|
||||
|
||||
```
|
||||
```nginx
|
||||
stream {
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
ssl_protocols TLSv1.3;
|
||||
ssl_certificate /path/to/cert/domain.crt; # crt 文件位置
|
||||
ssl_certificate_key /path/to/cert/domain.key; # key 文件位置
|
||||
proxy_pass unix:/dev/shm/vless.sock; # 使用 domain socket
|
||||
ssl_certificate /path/to/cert/domain.crt; # Location of crt file
|
||||
ssl_certificate_key /path/to/cert/domain.key; # Location of key file
|
||||
proxy_pass unix:/dev/shm/vless.sock; # Use domain socket
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
::: warning 注意
|
||||
|
||||
stream 部分与 http 模块并列,客户端可删除 http 部分,服务端可删除或搭建网页伪装回落
|
||||
::: warning Note
|
||||
The `stream` section is parallel to the `http` module. On the client side, you can delete the `http` section. On the server side, you can delete it or set up a web page fallback for camouflage.
|
||||
:::
|
||||
|
||||
客户端加入如下配置
|
||||
Add the following configuration to the **Client**:
|
||||
|
||||
```
|
||||
```nginx
|
||||
stream {
|
||||
server {
|
||||
listen 6666;
|
||||
@@ -66,19 +65,19 @@ stream {
|
||||
proxy_ssl on;
|
||||
proxy_ssl_protocols TLSv1.3;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_ssl_name yourdomain.domain; # 服务器域名
|
||||
proxy_pass ip:443; # 服务器 ip 形如 proxy_pass 6.6.6.6:443; 或 proxy_pass [2401:0:0::1]:443;
|
||||
proxy_ssl_name yourdomain.domain; # Server domain name
|
||||
proxy_pass ip:443; # Server IP, e.g., proxy_pass 6.6.6.6:443; or proxy_pass [2401:0:0::1]:443;
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
在 `/etc/systemd/system` 文件夹中创建 `nginx.service` 文件
|
||||
Create the `nginx.service` file in the `/etc/systemd/system` directory.
|
||||
|
||||
`vim /etc/systemd/system/nginx.service`
|
||||
|
||||
写入如下
|
||||
Write the following:
|
||||
|
||||
```
|
||||
```ini
|
||||
[Unit]
|
||||
Description=The NGINX HTTP and reverse proxy server
|
||||
After=syslog.target network-online.target remote-fs.target nss-lookup.target
|
||||
@@ -96,13 +95,13 @@ PrivateTmp=true
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
加入开机自启
|
||||
Enable auto-start on boot:
|
||||
|
||||
`systemctl enable nginx`
|
||||
|
||||
## xray 配置
|
||||
## Xray Configuration
|
||||
|
||||
服务端 xray 配置
|
||||
**Server-side** Xray Configuration:
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -138,7 +137,7 @@ WantedBy=multi-user.target
|
||||
}
|
||||
```
|
||||
|
||||
客户端 xray 配置,此处以旁路由透明代理为例
|
||||
**Client-side** Xray Configuration (Taking transparent proxy on a side-router/gateway as an example):
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -270,49 +269,49 @@ WantedBy=multi-user.target
|
||||
}
|
||||
```
|
||||
|
||||
如果使用透明代理需要在 iptables 或 ip6tables 配置中加入
|
||||
If using transparent proxy, you need to add the following to the `iptables` or `ip6tables` configuration:
|
||||
|
||||
```
|
||||
# 设置策略路由 v4
|
||||
```bash
|
||||
# Set policy routing v4
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
|
||||
# 设置策略路由 v6
|
||||
# Set policy routing v6
|
||||
ip -6 rule add fwmark 1 table 106
|
||||
ip -6 route add local ::/0 dev lo table 106
|
||||
|
||||
# VPS IP 直连
|
||||
# VPS IP Direct Connection
|
||||
iptables -t mangle -A XRAY_MASK -d VSP_IPv4/32 -j RETURN
|
||||
ip6tables -t mangle -A XRAY6_MASK -d VPS_IPv6/128 -j RETURN
|
||||
```
|
||||
|
||||
## 客户端及服务端启动服务
|
||||
## Start Services on Client & Server
|
||||
|
||||
`systemctl restart xray`
|
||||
|
||||
`systemctl restart nginx`
|
||||
|
||||
## 结束
|
||||
## Conclusion
|
||||
|
||||
# 双端 Haproxy 构建 HTTPS 隧道隐藏指纹
|
||||
# Building HTTPS Tunnels with Dual-End HAProxy to Hide Fingerprints
|
||||
|
||||
安装 Haproxy
|
||||
Install HAProxy:
|
||||
|
||||
`pacman -Su haproxy` 或 `apt install haproxy`
|
||||
`pacman -Su haproxy` or `apt install haproxy`
|
||||
|
||||
Haproxy 处理 ssl 需要 openssl 支持,检查 openssl 版本,必要时安装或更新
|
||||
HAProxy requires OpenSSL support to handle SSL. Check the OpenSSL version and install or update it if necessary.
|
||||
|
||||
## HTTPS 隧道
|
||||
## HTTPS Tunnel
|
||||
|
||||
前述 Nginx HTTPS 隧道 Hproxy 同样可以简单做到
|
||||
The Nginx HTTPS tunnel described above can also be easily achieved with HAProxy.
|
||||
|
||||
网路结构:
|
||||
Network Structure:
|
||||
|
||||
xray_client ---tcp--- haproxy_client ---HTTPS--- haproxy_sever ---tcp--- xray_server
|
||||
|
||||
### haproxy_client 配置 (运行前去掉注释)
|
||||
### haproxy_client Configuration (Uncomment before running)
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -322,7 +321,7 @@ global
|
||||
group root
|
||||
daemon
|
||||
|
||||
# 隧道强制使用 TLS 1.3
|
||||
# Force tunnel to use TLS 1.3
|
||||
ssl-default-server-options ssl-min-ver TLSv1.3
|
||||
|
||||
defaults
|
||||
@@ -333,17 +332,20 @@ defaults
|
||||
timeout server 300s
|
||||
|
||||
frontend xray
|
||||
bind 127.0.0.1:6666 # 监听本机 6666 端口
|
||||
bind 127.0.0.1:6666 # Listen on local port 6666
|
||||
default_backend tunnel
|
||||
|
||||
backend tunnel
|
||||
server tunnel www.example.com:443 ssl verify none sni req.hdr(host) alpn h2,http/1.1
|
||||
# 域名或 IP 均可以,若填域名建议在 hosts 中指定 IP 降低解析时间;alpn 与服务器协商,服务器端为 alpn h2,http1.1 时,客户端指定为 h2 则隧道为 HTTP2 方式连接,指定为 http1.1 为 HTTP 方式,双端均写优先 h2
|
||||
server tunnel [www.example.com:443](https://www.example.com:443) ssl verify none sni req.hdr(host) alpn h2,http/1.1
|
||||
# Domain or IP are both fine. If using a domain, it's recommended to specify the IP in hosts to reduce resolution time.
|
||||
# alpn negotiates with the server. If the server side is alpn h2,http1.1:
|
||||
# Specifying h2 on the client means the tunnel connects via HTTP2.
|
||||
# Specifying http1.1 means HTTP. It is recommended to prioritize h2 on both ends.
|
||||
```
|
||||
|
||||
### haproxy_server 配置 (运行前去掉注释)
|
||||
### haproxy_server Configuration (Uncomment before running)
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -353,7 +355,7 @@ global
|
||||
group root
|
||||
daemon
|
||||
|
||||
# 指定安全套件并指定 ssl 版本最低 1.2 增加真实性
|
||||
# Specify cipher suites and set minimum SSL version to 1.2 to increase authenticity
|
||||
ssl-default-bind-ciphers ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256
|
||||
ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
||||
ssl-default-bind-options ssl-min-ver TLSv1.2
|
||||
@@ -366,40 +368,40 @@ defaults
|
||||
timeout server 300s
|
||||
|
||||
frontend tls-in
|
||||
bind :::443 ssl crt /path/to/pem alpn h2,http/1.1 # haproxy 使用 pem 进行 ssl 解密,pem 由 cat www.example.com.crt www.example.com.key > www.example.com.pem 获得
|
||||
bind :::443 ssl crt /path/to/pem alpn h2,http/1.1 # haproxy uses pem for ssl decryption. pem is obtained by: cat [www.example.com](https://www.example.com).crt [www.example.com](https://www.example.com).key > [www.example.com](https://www.example.com).pem
|
||||
default_backend xray
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if HTTP
|
||||
use_backend web if HTTP
|
||||
|
||||
backend xray
|
||||
server xray /dev/shm/vless.sock # 支持 abstract 格式: "abns@vless.sock" ;loopback 方式:127.0.0.1:6666
|
||||
server xray /dev/shm/vless.sock # Supports abstract format: "abns@vless.sock"; loopback method: 127.0.0.1:6666
|
||||
|
||||
backend web
|
||||
server web /dev/shm/h1h2c.sock # 回落到网页
|
||||
server web /dev/shm/h1h2c.sock # Fallback to web page
|
||||
```
|
||||
|
||||
### xray 配置
|
||||
### Xray Configuration
|
||||
|
||||
同上 nginx 部分:最简单的 TCP 配置,可搭配任意协议,建议使用 VLESS+TCP 无需多余加密,参考文档或其他示例
|
||||
Same as the Nginx section above: Simplest TCP configuration. It works with any protocol. It is recommended to use VLESS+TCP without extra encryption. Refer to the documentation or other examples.
|
||||
|
||||
## WebSocket over HTTP/2
|
||||
|
||||
Haproxy 支持 HTTP/2 的 h2c 进站及出站
|
||||
HAProxy supports inbound and outbound HTTP/2 h2c.
|
||||
|
||||
然而援引 xray 文档 HTTP/2 的说明
|
||||
However, quoting the Xray documentation on HTTP/2:
|
||||
|
||||
“由 HTTP/2 的建议,客户端和服务器必须同时开启 TLS 才可以正常使用这个传输方式。...... 当前版本的 HTTP/2 的传输方式并不强制要求入站(服务端)有 TLS 配置。”
|
||||
"According to HTTP/2 recommendations, both the client and server must enable TLS to use this transport method normally... The current version of HTTP/2 transport does not enforce TLS configuration for inbound (server side)."
|
||||
|
||||
即入站可以使用 h2c,出站并不支持 h2c。因此无法使用 xray_client ---h2c--- haproxy_client ---HTTP/2+TLS--- haproxy_sever ---h2c--- xray_server
|
||||
This means inbound can use h2c, but outbound does not support h2c. Therefore, you cannot use: `xray_client ---h2c--- haproxy_client ---HTTP/2+TLS--- haproxy_sever ---h2c--- xray_server`.
|
||||
|
||||
但是可以通过 ws 偷个鸡,Haproxy 支持 ws over HTTP/2
|
||||
However, we can use a trick with WS (WebSocket). HAProxy supports WS over HTTP/2.
|
||||
|
||||
则网络结构:xray_client ---ws--- haproxy_client ---ws over HTTP/2 over HTTPS--- haproxy_sever ---ws--- xray_server
|
||||
So the network structure is: `xray_client ---ws--- haproxy_client ---ws over HTTP/2 over HTTPS--- haproxy_sever ---ws--- xray_server`.
|
||||
|
||||
### haproxy_client 配置
|
||||
### haproxy_client Configuration
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -409,9 +411,9 @@ global
|
||||
group root
|
||||
daemon
|
||||
|
||||
# 调整 HTTP/2 的性能,当遇到 HTTP/2 性能问题时都可以设置相关项,更多设置见 Haproxy 文档 tune.h2 部分 https://docs.haproxy.org/2.7/configuration.html
|
||||
tune.h2.initial-window-size 536870912 # 初始窗口大小,建议设置,默认值 65536 单位 byte,此值在突发大流量情况下需要一定加载时间,建议根据网速调整
|
||||
tune.h2.max-concurrent-streams 512 # 复用线路数,可根据情况设置,默认值 100,一般不用设置(官方不建议改动)
|
||||
# Adjust HTTP/2 performance. Set relevant items when encountering HTTP/2 performance issues. For more settings, see the tune.h2 section of the Haproxy documentation [https://docs.haproxy.org/2.7/configuration.html](https://docs.haproxy.org/2.7/configuration.html)
|
||||
tune.h2.initial-window-size 536870912 # Initial window size. Recommended to set. Default is 65536 bytes. Larger values may require some load time during traffic bursts. Adjust based on network speed.
|
||||
tune.h2.max-concurrent-streams 512 # Number of multiplexed streams. Set as needed. Default is 100. Generally no need to set (official recommendation is not to change).
|
||||
|
||||
ssl-default-server-options ssl-min-ver TLSv1.3
|
||||
|
||||
@@ -427,13 +429,13 @@ frontend xray
|
||||
default_backend tunnel
|
||||
|
||||
backend tunnel
|
||||
server tunnel www.example.com:443 ssl verify none sni req.hdr(host) ws h2 alpn h2
|
||||
server tunnel [www.example.com:443](https://www.example.com:443) ssl verify none sni req.hdr(host) ws h2 alpn h2
|
||||
# ws over HTTP/2
|
||||
```
|
||||
|
||||
### haproxy_server 配置
|
||||
### haproxy_server Configuration
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -443,7 +445,7 @@ global
|
||||
group root
|
||||
daemon
|
||||
|
||||
# 客户端配置即可,服务端配置也无妨
|
||||
# Configured on client is enough, configuring on server is also fine
|
||||
tune.h2.initial-window-size 536870912
|
||||
tune.h2.max-concurrent-streams 512
|
||||
|
||||
@@ -465,7 +467,7 @@ frontend tls-in
|
||||
use_backend server2 if { ssl_fc_alpn -i h2 } { path_beg /path2 }
|
||||
use_backend server3 if { ssl_fc_alpn -i h2 } { path_beg /path3 }
|
||||
default_backend web
|
||||
# haproxy 使用 http 模式可以根据 path 分流
|
||||
# haproxy using http mode can route based on path
|
||||
|
||||
backend xray
|
||||
server xray abns@vless.sock ws h1
|
||||
@@ -483,19 +485,19 @@ backend web
|
||||
server web /dev/shm/h1h2c.sock
|
||||
```
|
||||
|
||||
### xray 配置
|
||||
### Xray Configuration
|
||||
|
||||
简单的 websocket 配置即可,无需 TLS, 配置见 xray 文档示例,配置 "path" 可以用于服务端 haproxy 分流(客户端有分流需求同样可以通过客户端 haproxy 进行,原理类似,参考服务端的 path 分流配置)
|
||||
A simple WebSocket configuration is sufficient. No TLS required. See Xray documentation examples. Configuration of "path" can be used for server-side HAProxy routing (if the client has routing needs, it can also be done via client-side HAProxy; the principle is similar, refer to the server-side path routing configuration).
|
||||
|
||||
## gRPC over HTTP/2
|
||||
|
||||
虽然双端的 h2c 不行,但是 gRPC 不要求必须 TLS,直接冲
|
||||
Although dual-end h2c doesn't work, gRPC does not mandate TLS, so we can go straight ahead.
|
||||
|
||||
网络结构:xray_client ---gRPC h2c--- haproxy_client ---gRPC over HTTP/2 over HTTPS--- haproxy_sever ---gRPC h2c--- xray_server
|
||||
Network Structure: `xray_client ---gRPC h2c--- haproxy_client ---gRPC over HTTP/2 over HTTPS--- haproxy_sever ---gRPC h2c--- xray_server`
|
||||
|
||||
### haproxy_client 配置
|
||||
### haproxy_client Configuration
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -518,16 +520,16 @@ defaults
|
||||
timeout server 300s
|
||||
|
||||
frontend xray
|
||||
bind 127.0.0.1:6666 proto h2 # 指定 proto h2 使用 h2c
|
||||
bind 127.0.0.1:6666 proto h2 # Specify proto h2 to use h2c
|
||||
default_backend tunnel
|
||||
|
||||
backend tunnel
|
||||
server tunnel www.example.com:443 ssl verify none sni req.hdr(host) alpn h2
|
||||
server tunnel [www.example.com:443](https://www.example.com:443) ssl verify none sni req.hdr(host) alpn h2
|
||||
```
|
||||
|
||||
### haproxy_server 配置
|
||||
### haproxy_server Configuration
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -553,7 +555,7 @@ defaults
|
||||
|
||||
frontend tls-in
|
||||
bind :::443 ssl crt /path/to/pem alpn h2,http/1.1
|
||||
use_backend xray if { ssl_fc_alpn -i h2 } { path_beg /tunnel } # xray gRPC 中配置的 "serviceName" 在 harpoxy 中可以使用 path 进行分流,为方便使用 "multiMode",使用 path_beg 参数匹配路径
|
||||
use_backend xray if { ssl_fc_alpn -i h2 } { path_beg /tunnel } # The "serviceName" configured in xray gRPC can be used for routing in haproxy via path. For convenience when using "multiMode", use the path_beg parameter to match the path.
|
||||
use_backend server1 if { ssl_fc_alpn -i h2 } { path_beg /path1 }
|
||||
use_backend server2 if { ssl_fc_alpn -i h2 } { path_beg /path2 }
|
||||
use_backend server3 if { ssl_fc_alpn -i h2 } { path_beg /path3 }
|
||||
@@ -575,27 +577,27 @@ backend web
|
||||
server web /dev/shm/h1h2c.sock
|
||||
```
|
||||
|
||||
### xray 配置
|
||||
### Xray Configuration
|
||||
|
||||
简单的 gRPC 配置,无需 TLS,配置见文档,配置的 serviceName 可用于分流。
|
||||
Simple gRPC configuration, no TLS needed. See documentation for configuration. The configured `serviceName` can be used for routing.
|
||||
|
||||
# Haproxy 使用自签证书进行双端认证(gRPC 示例)
|
||||
# HAProxy Using Self-Signed Certificates for Mutual Authentication (gRPC Example)
|
||||
|
||||
这里使用自签证书双端认证加强隧道安全性(但会牺牲一点延迟,不过使用 gRPC 后感知不强),而服务端同时处理信任的证书和自签名证书,并据此分流伪装网站和隧道流量
|
||||
Here, we use self-signed certificates with mutual authentication (mTLS) to strengthen tunnel security (at the cost of a little latency, though not very noticeable with gRPC). The server handles both trusted certificates and self-signed certificates simultaneously, and routes traffic for the camouflage site and tunnel traffic accordingly.
|
||||
|
||||
其中 www.example.com 为伪装站信任证书(如白话文中申请的证书)
|
||||
Where `www.example.com` is the trusted certificate for the camouflage site (like certificates applied for in the Plain Language Guide).
|
||||
|
||||
tunnel.example.com 为自签证书网址,自签证书可以参考 https://learn.microsoft.com/zh-cn/azure/application-gateway/self-signed-certificates
|
||||
`tunnel.example.com` is the URL for the self-signed certificate. For self-signed certificates, refer to: <https://learn.microsoft.com/en-us/azure/application-gateway/self-signed-certificates>
|
||||
|
||||
根证书 ca.crt 服务器证书 server.crt 服务器密钥 server.key
|
||||
Root certificate: `ca.crt`; Server certificate: `server.crt`; Server key: `server.key`.
|
||||
|
||||
至少需要生成一个 server.pem,客户端可以同样使用此证书用于双端认证;或者生成两个证书,一个 client,一个 server,用于双端认证
|
||||
You need to generate at least one `server.pem`. The client can use this same certificate for mutual authentication; or generate two certificates, one for client and one for server, for mutual authentication.
|
||||
|
||||
需准备 fullchain.crt 用于认证( cat server.crt ca.crt > fullchain.crt ),server.pem ( cat server.crt server.key ca.crt > server.pem )用于解密
|
||||
Prepare `fullchain.crt` for verification (`cat server.crt ca.crt > fullchain.crt`) and `server.pem` (`cat server.crt server.key ca.crt > server.pem`) for decryption.
|
||||
|
||||
### haproxy_client 配置
|
||||
### haproxy_client Configuration
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -623,12 +625,12 @@ frontend xray
|
||||
|
||||
backend tunnel
|
||||
server tunnel tunnel.example.com:443 tfo allow-0rtt ssl crt /path/to/client.pem verify required ca-file /path/to/fullchain.crt sni str(tunnel.example.com) alpn h2
|
||||
# 网址自定义,和自签证书一致即可,hosts 中配置 IP 解析,sni 的 str 设定 sni,用于服务端识别
|
||||
# The URL is custom, just keep it consistent with the self-signed certificate. Configure IP resolution in hosts. Set sni with `sni str()` for server-side identification.
|
||||
```
|
||||
|
||||
### haproxy_server 配置
|
||||
### haproxy_server Configuration
|
||||
|
||||
```
|
||||
```haproxy
|
||||
global
|
||||
log /dev/log local0 alert
|
||||
log /dev/log local1 alert
|
||||
@@ -653,14 +655,14 @@ defaults
|
||||
timeout server 300s
|
||||
|
||||
frontend tls-in
|
||||
bind :::443 tfo allow-0rtt ssl crt /path/to/server.pem verify optional ca-file /path/to/fullchain.crt crt /path/to/www.example.com.pem alpn h2,http/1.1
|
||||
bind :::443 tfo allow-0rtt ssl crt /path/to/server.pem verify optional ca-file /path/to/fullchain.crt crt /path/to/[www.example.com](https://www.example.com).pem alpn h2,http/1.1
|
||||
use_backend xray if { ssl_fc_sni tunnel.example.com } { ssl_c_used } { ssl_fc_alpn -i h2 } { path_beg /tunnel }
|
||||
use_backend server1 if { ssl_fc_sni atunnel.example.com } { ssl_c_used } { ssl_fc_alpn -i h2 } { path_beg /path2 }
|
||||
use_backend server2 if { ssl_fc_sni btunnel.example.com } { ssl_c_used } { ssl_fc_alpn -i h2 } { path_beg /path3 }
|
||||
use_backend server3 if { ssl_fc_sni ctunnel.example.com } { ssl_c_used } { ssl_fc_alpn -i h2 } { path_beg /path4 }
|
||||
default_backend web
|
||||
# Haproxy 支持多个 pem 解密
|
||||
# 可根据多个客户端的不同 sni 分流,也可以 path 分流,方式多样,更多 acl 见 Haproxy 文档
|
||||
# Haproxy supports multiple pem decryptions
|
||||
# Can route based on different client SNIs, or based on path. Various methods available. See Haproxy docs for more ACLs.
|
||||
|
||||
backend xray
|
||||
server xray abns@vless.sock proto h2
|
||||
@@ -678,6 +680,6 @@ backend web
|
||||
server web /dev/shm/h1h2c.sock
|
||||
```
|
||||
|
||||
### xray 配置
|
||||
### Xray Configuration
|
||||
|
||||
简单的 gRPC 配置,无需 TLS,配置见文档,配置的 serviceName 可用于分流。
|
||||
Simple gRPC configuration, no TLS needed. See documentation for configuration. The configured `serviceName` can be used for routing.
|
||||
|
||||
@@ -1,146 +1,100 @@
|
||||
---
|
||||
title: 出站流量重定向
|
||||
title: Outbound Traffic Redirection
|
||||
---
|
||||
|
||||
# 基于 fwmark 或 sendThrough 的流量重定向
|
||||
# Traffic Redirection Based on fwmark or sendThrough
|
||||
|
||||
通过 Xray 将特定的流量指向特定出口,实现全局路由“分流”
|
||||
Direct specific traffic to specific exits via Xray to achieve global routing "traffic splitting".
|
||||
|
||||
## 前言
|
||||
## Foreword
|
||||
|
||||
之前在网络上看到许多代理或者 VPN 会接管全局路由,如果与 Xray 同时安装,会导致 Xray 失效。参考了网络上许多教程,及时分流,也是通过维护一张或者多张 CIDR
|
||||
路由表来实现的。这种情况下并不优雅,如果我想可以任意替换,实现按需分流,那有没有更好的办法呢?有!
|
||||
Previously, I noticed that many proxies or VPNs take over the global routing table. If installed alongside Xray, this causes Xray to fail. I referred to many tutorials online, and even immediate traffic splitting was achieved by maintaining one or more CIDR routing tables. This approach is not elegant. If I want to be able to replace interfaces arbitrarily and achieve on-demand splitting, is there a better way? Yes!
|
||||
|
||||
通过 fwmark 或 Xray 的 sendThrough,再简单配合路由表功能即可实现:
|
||||
By using `fwmark` or Xray's `sendThrough`/`sockopt.interface`, combined simply with routing table functions, we can achieve:
|
||||
|
||||
1. Xray 可设置指定的 Tag、域名等走指定接口。如果您的接口是双栈的,可以指定 IPV4 或者 IPV6
|
||||
2. 其余用户则走原 IPV4 或者 IPV6
|
||||
1. Xray can set specific Tags, domains, etc., to go through a specific interface. If your interface is dual-stack, you can specify IPv4 or IPv6.
|
||||
2. The rest of the users will use the original IPv4 or IPv6.
|
||||
|
||||
具体设置如下(以 Debian10 为例):
|
||||
The specific settings are as follows (using Debian 10 as an example):
|
||||
|
||||
## 1、安装代理或者 VPN 软件(例如 Wireguard、IPsec 等)
|
||||
## 1. Install Proxy or VPN Software (e.g., WireGuard, IPsec, etc.)
|
||||
|
||||
根据不同系统和不同软件,请参考官方安装方法
|
||||
Please refer to the official installation methods for different systems and software.
|
||||
|
||||
## 2、编辑 VPN 配置文件(以 WireGuard 为例)
|
||||
## 2. Edit VPN Configuration File (Using WireGuard as an example)
|
||||
|
||||
原始文件:
|
||||
|
||||
<Tabs title="if-config">
|
||||
|
||||
<Tab title="fwmark1">
|
||||
Original file:
|
||||
|
||||
```ini
|
||||
[Interface]
|
||||
PrivateKey = xxxxxxxxxxxxxxxxxxxx
|
||||
Address = "your wg0 v4 address"
|
||||
Address = "your wg0 v6 address"
|
||||
PrivateKey = <PriKey>
|
||||
Address = <IPv4>
|
||||
Address = <IPv6>
|
||||
DNS = 8.8.8.8
|
||||
MTU = 1280
|
||||
[Peer]
|
||||
PublicKey = xxxxxxxxxxxxxxxxxxxxx
|
||||
PublicKey = <Pubkey>
|
||||
AllowedIPs = ::/0
|
||||
AllowedIPs = 0.0.0.0/0
|
||||
Endpoint = "ip:port"
|
||||
Endpoint = <EndpointIP>:<Port>
|
||||
```
|
||||
|
||||
在 `[Interface]` 下添加如下命令:
|
||||
Add the following commands under `[Interface]`:
|
||||
|
||||
```ini
|
||||
Table = off
|
||||
PostUP = ip -4 rule add fwmark <mark> lookup <table>
|
||||
PostUP = ip -4 route add default dev <接口名称> table <table>
|
||||
PostUP = ip -4 rule add table main suppress_prefixlength 0
|
||||
Table = <table>
|
||||
### fwmark
|
||||
PostUP = ip rule add fwmark <mark> lookup <table>
|
||||
PostDown = ip rule del fwmark <mark> lookup <table>
|
||||
PostUP = ip -6 rule add fwmark <mark> lookup <table>
|
||||
PostUP = ip -6 rule add not fwmark <table> table <table>
|
||||
PostUP = ip -6 route add ::/0 dev <接口名称> table <table>
|
||||
PostUP = ip -6 rule add table main suppress_prefixlength 0
|
||||
PostDown = ip -4 rule delete fwmark <mark> lookup <table>
|
||||
PostDown = ip -4 rule delete table main suppress_prefixlength 0
|
||||
PostDown = ip -6 rule delete fwmark <mark> lookup <table>
|
||||
PostDown = ip -6 rule delete not fwmark <table> table <table>
|
||||
PostDown = ip -6 rule delete table main suppress_prefixlength 0
|
||||
PostDown = ip -6 rule del fwmark <mark> lookup <table>
|
||||
## sendThrough
|
||||
PreUp = ip rule add from <IPv4> lookup <table>
|
||||
PostDown = ip rule del from <IPv4> lookup <table>
|
||||
PreUp = ip -6 rule add from <IPv6> lookup <table>
|
||||
PostDown = ip -6 rule del from <IPv6> lookup <table>
|
||||
## sockopt.interface
|
||||
PreUp = ip rule add oif %i lookup <table>
|
||||
PostDown = ip rule del oif %i lookup <table>
|
||||
PreUp = ip -6 rule add oif %i lookup <table>
|
||||
PostDown = ip -6 rule del oif %i lookup <table>
|
||||
```
|
||||
|
||||
::: tip
|
||||
|
||||
- 此命令表示 IPv4 中 fwmark 为 `<mark>`,IPv6 中 fwmark 为`<mark>`,::/0 全局 v6 走 WireGuard
|
||||
- 可根据自己需求增删命令,mark 值要与 Xray-core 中设置为相同,table 值自定
|
||||
- 如果不支持配置文件,可以在系统中修改路由表
|
||||
- This configuration integrates `fwmark` / `sendThrough` / `sockopt.interface`, meaning:
|
||||
- Connections sent to this device `%i` / Connections sent to this `<IPv4/6>` / Connections marked with `fwmark` `<mark>`
|
||||
- Will be forwarded using WireGuard.
|
||||
- `%i` is a placeholder in the WireGuard configuration file, which represents the device name to be replaced at startup.
|
||||
:::
|
||||
|
||||
</Tab>
|
||||
Save it.
|
||||
|
||||
<Tab title="sendThrough1">
|
||||
You can also install this handy tool:
|
||||
|
||||
```ini
|
||||
[Interface]
|
||||
PrivateKey = xxxxxxxxxxxxxxxxxxxx
|
||||
Address = "your wg0 v4 address"
|
||||
Address = "your wg0 v6 address"
|
||||
DNS = 8.8.8.8
|
||||
MTU = 1280
|
||||
[Peer]
|
||||
PublicKey = xxxxxxxxxxxxxxxxxxxxx
|
||||
AllowedIPs = ::/0
|
||||
AllowedIPs = 0.0.0.0/0
|
||||
Endpoint = "ip:port"
|
||||
```
|
||||
|
||||
在 `[Interface]` 下添加如下命令:
|
||||
|
||||
```ini
|
||||
Table = off
|
||||
PostUP = ip -4 rule add from "your wg0 v4 address" lookup <table>
|
||||
PostUP = ip -4 route add default dev wg0 table <table>
|
||||
PostUP = ip -4 rule add table main suppress_prefixlength 0
|
||||
PostUP = ip -6 rule add not fwmark <table> table <table>
|
||||
PostUP = ip -6 route add ::/0 dev wg0 table <table>
|
||||
PostUP = ip -6 rule add table main suppress_prefixlength 0
|
||||
PostDown = ip -4 rule delete from "your wg0 v4 address" lookup <table>
|
||||
PostDown = ip -4 rule delete table main suppress_prefixlength 0
|
||||
PostDown = ip -6 rule delete not fwmark <table> table <table>
|
||||
PostDown = ip -6 rule delete table main suppress_prefixlength 0
|
||||
```
|
||||
|
||||
::: tip
|
||||
|
||||
- 此命令表示 IPV4 中来自 `your wg0 v4 address` 地址的走 WireGuard,IPv6 中::/0 全局 v6 走 WireGuard)
|
||||
- 可根据自己需求增删命令,实现 v6 分流,也可以与 fwmark 融合
|
||||
- 如果不支持配置文件,可以在系统中修改路由表
|
||||
:::
|
||||
|
||||
</Tab>
|
||||
|
||||
</Tabs>
|
||||
|
||||
保存
|
||||
|
||||
可顺手安装
|
||||
::: warning
|
||||
If the `DNS` field in `[Interface]` is used, this program is required.
|
||||
:::
|
||||
|
||||
```bash
|
||||
apt install openresolv
|
||||
```
|
||||
|
||||
## 3、启用 WireGuard 网络接口
|
||||
## 3. Enable WireGuard Network Interface
|
||||
|
||||
加载内核模块
|
||||
Load the kernel module:
|
||||
|
||||
```bash
|
||||
modprobe wireguard
|
||||
```
|
||||
|
||||
检查 WG 模块加载是否正常
|
||||
Check if the WG module is loaded correctly:
|
||||
|
||||
```bash
|
||||
lsmod | grep wireguard
|
||||
```
|
||||
|
||||
## 4、Xray-core 配置文件修改
|
||||
|
||||
<Tabs title="xray-config">
|
||||
|
||||
<Tab title="fwmark2">
|
||||
## 4. Xray-core Configuration Modification
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -167,105 +121,48 @@ lsmod | grep wireguard
|
||||
{
|
||||
"protocol": "freedom",
|
||||
"settings": {
|
||||
"domainStrategy": "UseIPv6"
|
||||
//设置默认用户走指定方式”UseIPv6”或者”UseIPv4”
|
||||
"domainStrategy": "UseIPv4"
|
||||
}
|
||||
// Modify here, can be v4 or v6
|
||||
},
|
||||
// <--Please choose between different schemes--> Scheme 1: fwmark
|
||||
{
|
||||
"protocol": "freedom",
|
||||
"tag": "wg0",
|
||||
"streamSettings": {
|
||||
"sockopt": {
|
||||
"mark": <mark>
|
||||
"mark": // <mark>
|
||||
}
|
||||
},
|
||||
"settings": {
|
||||
"domainStrategy": "UseIPv6"
|
||||
}
|
||||
//设置fwmark为<mark>的用户走指定方式”UseIPv6””UseIPv4”
|
||||
},
|
||||
{
|
||||
"protocol": "blackhole",
|
||||
"settings": {},
|
||||
"tag": "blocked"
|
||||
}
|
||||
],
|
||||
"policy": {
|
||||
"system": {
|
||||
"statsInboundDownlink": true,
|
||||
"statsInboundUplink": true
|
||||
}
|
||||
},
|
||||
"routing": {
|
||||
"rules": [
|
||||
{
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api"
|
||||
},
|
||||
{
|
||||
"outboundTag": "wg0",
|
||||
"inboundTag": [
|
||||
"<inboundTag>"
|
||||
//需要之前在inbound中指定好Tag,我这里是api生成的,还可以添加域名等等
|
||||
]
|
||||
},
|
||||
{
|
||||
"outboundTag": "blocked",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"stats": {}
|
||||
}
|
||||
```
|
||||
|
||||
</Tab>
|
||||
|
||||
<Tab title="sendThrough2">
|
||||
|
||||
```json
|
||||
{
|
||||
"api": {
|
||||
"services": [
|
||||
"HandlerService",
|
||||
"LoggerService",
|
||||
"StatsService"
|
||||
],
|
||||
"tag": "api"
|
||||
},
|
||||
"inbounds": [
|
||||
{
|
||||
"listen": "127.0.0.1",
|
||||
"port": <port>,
|
||||
"protocol": "dokodemo-door",
|
||||
"settings": {
|
||||
"address": "127.0.0.1"
|
||||
},
|
||||
"tag": "api"
|
||||
}
|
||||
],
|
||||
"outbounds": [
|
||||
{
|
||||
"protocol": "freedom",
|
||||
"settings": {
|
||||
"domainStrategy": "UseIPv4"
|
||||
}
|
||||
//修改此处,可v4或者v6
|
||||
},
|
||||
}, // Users with fwmark set to <mark> use the specified strategy "UseIPv6" or "UseIPv4"
|
||||
// <--Please choose between different schemes--> Scheme 2: sendThrough
|
||||
{
|
||||
"tag": "wg0",
|
||||
"protocol": "freedom",
|
||||
"sendThrough": "your wg0 v4 address",
|
||||
//修改此处,可v4或者v6
|
||||
// Modify here, can be v4 or v6
|
||||
"settings": {
|
||||
"domainStrategy": "UseIPv4"
|
||||
}
|
||||
//修改此处,可v4或者v6
|
||||
// Modify here, can be v4 or v6
|
||||
},
|
||||
// <--Please choose between different schemes--> Scheme 3: sockopt.interface
|
||||
{
|
||||
"tag": "wg0",
|
||||
"protocol": "freedom",
|
||||
"settings": {
|
||||
"domainStrategy": "UseIPv4"
|
||||
},
|
||||
"streamSettings": {
|
||||
"sockopt": {
|
||||
"interface": "wg0"
|
||||
}
|
||||
}
|
||||
},
|
||||
// <--Please choose between different schemes--> End
|
||||
{
|
||||
"protocol": "blackhole",
|
||||
"settings": {},
|
||||
@@ -290,7 +187,7 @@ lsmod | grep wireguard
|
||||
"outboundTag": "wg0",
|
||||
"inboundTag": [
|
||||
"<inboundTag>"
|
||||
//需要之前在 inbound 中指定好 Tag,我这里是 api 生成的,还可以添加域名等等
|
||||
// Need to specify the Tag in inbound beforehand; here it's generated by api, domains can also be added, etc.
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -305,43 +202,43 @@ lsmod | grep wireguard
|
||||
}
|
||||
```
|
||||
|
||||
</Tab>
|
||||
|
||||
</Tabs>
|
||||
|
||||
::: tip
|
||||
可以通过修改 "domainStrategy": "UseIPv6"来控制对应用户的访问方式 实测优先级要高于系统本身的 gai.config
|
||||
You can control the access method for corresponding users by modifying `"domainStrategy": "UseIPv6"`. Actual tests show priority is higher than the system's own `gai.config`.
|
||||
:::
|
||||
|
||||
## 5、系统设置配置
|
||||
## 5. System Settings Configuration
|
||||
|
||||
::: tip
|
||||
需要打开系统的 ip_forward
|
||||
You need to enable the system's `ip_forward`.
|
||||
`sysctl -w net.ipv4.ip_forward=1`
|
||||
`sysctl -w net.ipv6.conf.all.forwarding=1`
|
||||
:::
|
||||
|
||||
## 6、完成 WireGuard 相关设置
|
||||
## 6. Complete WireGuard Settings
|
||||
|
||||
开启隧道
|
||||
Start the tunnel:
|
||||
|
||||
```bash
|
||||
wg-quick up wg0
|
||||
```
|
||||
|
||||
开机自启
|
||||
Enable auto-start on boot:
|
||||
|
||||
```bash
|
||||
systemctl enable wg-quick@wg0
|
||||
systemctl start wg-quick@wg0
|
||||
```
|
||||
|
||||
验证 IPv4/IPv6
|
||||
Verify IPv4/IPv6:
|
||||
|
||||
> 自行验证 Google 搜索 myip
|
||||
> Run `curl ip-api.com -4/-6` on the proxy / Visit ip-api.com via browser
|
||||
|
||||
## 后记
|
||||
## Postscript
|
||||
|
||||
本文本意是可以避免的多余的流量浪费,将路由和分流的功能交给 Xray 处理。避免了维护路由表的繁琐工作。顺便技术提升 UP。
|
||||
The intention of this article is to avoid unnecessary waste of traffic by handing over the routing and splitting functions to Xray. This avoids the tedious work of maintaining routing tables. It also serves to level up your technical skills.
|
||||
|
||||
## 感谢
|
||||
## Acknowledgments
|
||||
|
||||
@Xray-core @V2ray-core @WireGuard @p3terx @w @Hiram @Luminous @Ln @JackChou
|
||||
[XTLS/Xray-core](https://github.com/XTLS/Xray-core); [v2fly/v2ray-core](https://github.com/v2fly/v2ray-core); [WireGuard](https://www.wireguard.com/); [@p3terx](https://p3terx.com/); @w; @Hiram; @Luminous; @Ln; @JackChou;
|
||||
|
||||
<!--剩下几位大佬我实在找不到他们的地址或Github空间,请大家帮忙找吧-->
|
||||
|
||||
@@ -1,24 +1,24 @@
|
||||
---
|
||||
title: TProxy 透明代理
|
||||
title: TProxy Transparent Proxy
|
||||
---
|
||||
|
||||
# 透明代理(TProxy)配置教程
|
||||
# Transparent Proxy (TProxy) Configuration Tutorial
|
||||
|
||||
本配置基于[TProxy 透明代理的新 V2Ray 白话文教程](https://guide.v2fly.org/app/tproxy.html),加入了 Xray 的新特性,使用 VLESS + XTLS Vision 方案,并将旧教程中默认出站代理的分流方式改为默认出站直连,使用者请按照实际情况进行修改。
|
||||
This configuration is based on the [New V2Ray Plain Guide for Transparent Proxy (TProxy)](https://guide.v2fly.org/app/tproxy.html), adding new features from Xray. It utilizes the VLESS + XTLS Vision scheme. Unlike the old tutorial which defaulted to proxying outbound traffic, this configuration defaults to direct connection for outbound traffic. Users should adjust this according to their actual needs.
|
||||
|
||||
本文中所有配置已在 Raspberry Pi 2B、Ubuntu 20.04 环境下测试成功,如在其它环境中使用请自行调整配置。
|
||||
All configurations in this article have been successfully tested on Raspberry Pi 2B and Ubuntu 20.04. If you are using a different environment, please adjust the configuration accordingly.
|
||||
|
||||
## 开始之前
|
||||
## Before You Start
|
||||
|
||||
请检查您的设备是否有可用的网络连接,且服务端已经配置成功,客户端已经安装完毕。
|
||||
Please check that your device has an active network connection, the server-side is successfully configured, and the client is installed.
|
||||
|
||||
需注意的是,目前很多透明代理教程都会将 Linux 系统的 IP 转发打开,但这样会导致 Splice 性能下降。详情请参考[大案牍术破案纪实第三篇--我们是如何破解 Splice 性能下降甚至低于 Direct 之谜的](https://github.com/XTLS/Xray-core/discussions/59)。
|
||||
It is worth noting that many transparent proxy tutorials instruct you to enable IP Forwarding on Linux. However, doing so can degrade `Splice` performance. For details, please refer to [Detective Story Part 3: How we solved the mystery of Splice performance dropping even below Direct](https://github.com/XTLS/Xray-core/discussions/59).
|
||||
|
||||
这里我想要补充的是,很多透明代理教程会使用 Netfilter 进行分流,使直连流量直接发出而不经过 Xray,这时必须开启 IP 转发;也有的教程,如本文,会将所有流量导入 Xray 之中,由 Xray 的路由模块进行分流,这时无需开启 IP 转发。
|
||||
I would like to add that many transparent proxy tutorials use Netfilter for traffic splitting (routing), allowing direct traffic to go out without passing through Xray. In that case, IP Forwarding must be enabled. However, some tutorials, like this one, direct *all* traffic into Xray, and the routing module within Xray handles the splitting. In this scenario, IP Forwarding does **not** need to be enabled.
|
||||
|
||||
## Xray 配置
|
||||
## Xray Configuration
|
||||
|
||||
为了更好的分流体验,请替换默认路由规则文件为 [Loyalsoldier/v2ray-rules-dat](https://github.com/Loyalsoldier/v2ray-rules-dat),否则 Xray-core 将无法加载本配置。
|
||||
For a better routing experience, please replace the default routing rule files with [Loyalsoldier/v2ray-rules-dat](https://github.com/Loyalsoldier/v2ray-rules-dat); otherwise, Xray-core will not be able to load this configuration.
|
||||
|
||||
```bash
|
||||
sudo curl -oL /usr/local/share/xray/geoip.dat https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geoip.dat
|
||||
@@ -71,7 +71,7 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
"settings": {
|
||||
"vnext": [
|
||||
{
|
||||
"address": "服务端域名",
|
||||
"address": "Server_Domain",
|
||||
"port": 443,
|
||||
"users": [
|
||||
{
|
||||
@@ -118,7 +118,7 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
],
|
||||
"dns": {
|
||||
"hosts": {
|
||||
"服务端域名": "服务端 IP"
|
||||
"Server_Domain": "Server_IP"
|
||||
},
|
||||
"servers": [
|
||||
{
|
||||
@@ -168,26 +168,22 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
```
|
||||
|
||||
::: tip TIP
|
||||
本配置会劫持所有发往 53 端口的流量以解决 DNS 污染问题,所以客户端和本机的 DNS 服务器的地址可以随意配置。
|
||||
This configuration hijacks all traffic sent to port 53 to solve DNS pollution issues, so the DNS server addresses on the client and the local machine can be configured arbitrarily.
|
||||
:::
|
||||
|
||||
## 策略路由配置
|
||||
## Policy Routing Configuration
|
||||
|
||||
```
|
||||
sudo ip route add local default dev lo table 100 # 添加路由表 100
|
||||
sudo ip rule add fwmark 1 table 100 # 为路由表 100 设定规则
|
||||
```bash
|
||||
sudo ip route add local default dev lo table 100 # Add routing table 100
|
||||
sudo ip rule add fwmark 1 table 100 # Set rules for routing table 100
|
||||
```
|
||||
|
||||
## Netfilter 配置
|
||||
## Netfilter Configuration
|
||||
|
||||
::: warning 注意
|
||||
nftables 配置与 iptables 配置二选一,不可同时使用。
|
||||
::: warning Note
|
||||
Choose either **nftables** or **iptables** configuration. Do not use both simultaneously.
|
||||
:::
|
||||
|
||||
<Tabs title="netfilter">
|
||||
|
||||
<Tab title="nftables1">
|
||||
|
||||
```nftables
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
@@ -226,15 +222,11 @@ table ip xray {
|
||||
}
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
::: tip Usage
|
||||
|
||||
将上述配置写入一个文件(如 `nft.conf`),之后将该文件赋予可执行权限,最后使用 root 权限执行该文件即可(`# ./nft.conf`)。
|
||||
Write the above configuration to a file (e.g., `nft.conf`), then give the file executable permissions, and finally execute the file with root privileges (`# ./nft.conf`).
|
||||
:::
|
||||
|
||||
</Tab>
|
||||
|
||||
<Tab title="iptables1">
|
||||
|
||||
```bash
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 10.0.0.0/8 -j RETURN
|
||||
@@ -270,21 +262,11 @@ iptables -t mangle -A XRAY_SELF -p udp -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -j XRAY_SELF
|
||||
```
|
||||
|
||||
</Tab>
|
||||
After the configuration is complete, change the default gateway of other devices in the LAN to the IP of this device to bypass the firewall directly. After successfully testing on both other hosts and the local machine, you can proceed to the next step.
|
||||
|
||||
</Tabs>
|
||||
## Persistence and Auto-start
|
||||
|
||||
配置完成后,将局域网内其它设备的默认网关改为该设备 IP,就可以直接翻墙了。在其它主机和本机皆测试成功后,可进行下一步配置。
|
||||
|
||||
## 配置永久化与开机自启
|
||||
|
||||
<br/>
|
||||
|
||||
<Tabs title="netfilter2">
|
||||
|
||||
<Tab title="nftables2">
|
||||
|
||||
首先将已经编辑好的 nftables 配置文件移动到 `/etc` 目录下,并重命名为 `nftables.conf`。然后编辑 `/lib/systemd/system/nftables.service`。
|
||||
First, move the edited `nftables` configuration file to the `/etc` directory and rename it to `nftables.conf`. Then edit `/lib/systemd/system/nftables.service`.
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
@@ -309,17 +291,13 @@ ExecStop=/usr/sbin/nft flush ruleset ; /usr/sbin/ip route del local default dev
|
||||
WantedBy=sysinit.target
|
||||
```
|
||||
|
||||
最后 enable 即可。
|
||||
Finally, enable it.
|
||||
|
||||
</Tab>
|
||||
For persistence with `iptables`, it is recommended to install `iptables-persistent` directly.
|
||||
|
||||
<Tab title="iptables2">
|
||||
During the installation process, you will be prompted to "Save current IPv4 rules?". If you have already applied the iptables configuration to the system, select "Yes". If not, it doesn't matter; after installation, apply the configuration and then execute `netfilter-persistent save` (root privileges required).
|
||||
|
||||
关于 iptables 的永久化,建议直接安装 `iptables-persistent`。
|
||||
|
||||
安装过程中会提示你选择“是否保存配置”,如果已经将 iptables 配置写入系统,那么此时选择“是”即可;如果尚未写入也没有关系,安装完毕后将配置写入,然后执行 `netfilter-persistent save` 即可(需要 root 权限)。
|
||||
|
||||
之后编辑 `/lib/systemd/system/netfilter-persistent.service`。
|
||||
After that, edit `/lib/systemd/system/netfilter-persistent.service`.
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
@@ -340,7 +318,3 @@ ExecStop=/usr/sbin/netfilter-persistent stop ; /usr/sbin/ip route flush dev lo t
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
</Tab>
|
||||
|
||||
</Tabs>
|
||||
|
||||
@@ -1,33 +1,33 @@
|
||||
---
|
||||
title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
title: TProxy Transparent Proxy (IPv4 and IPv6)
|
||||
---
|
||||
|
||||
# TProxy 透明代理(ipv4 and ipv6)配置教程
|
||||
# TProxy Transparent Proxy (IPv4 and IPv6) Configuration Tutorial
|
||||
|
||||
本配置参考了[TProxy 透明代理的新 V2Ray 白话文教程](https://guide.v2fly.org/app/tproxy.html),[透明代理(TProxy)配置教程](https://xtls.github.io/document/level-2/tproxy.html#%E5%BC%80%E5%A7%8B%E4%B9%8B%E5%89%8D)以及[透明代理通过 gid 规避 Xray 流量](https://xtls.github.io/document/level-2/iptables_gid.html),加入了透明代理对 ipv6 的支持,并且使用 VLESS-TCP-XTLS-RPRX-Vision 方案对抗封锁 (推荐使用 1.7.2 及之后版本)。
|
||||
This configuration is based on the [New V2Ray Plain English Guide for TProxy Transparent Proxy](https://guide.v2fly.org/app/tproxy.html), the [Transparent Proxy (TProxy) Configuration Tutorial](https://xtls.github.io/document/level-2/tproxy.html#%E5%BC%80%E5%A7%8B%E4%B9%8B%E5%89%8D), and [Bypassing Xray Traffic via GID](https://xtls.github.io/document/level-2/iptables_gid.html). It adds support for IPv6 transparent proxying and utilizes the VLESS-TCP-XTLS-RPRX-Vision scheme to counter blocking (version 1.7.2 or later is recommended).
|
||||
|
||||
关于 Xray 的配置并不是本文重点,使用者可依实际情况进行修改,具体可以参考[官方文档示例](https://github.com/XTLS/Xray-examples)或其他优秀示例 比如[@chika0801](https://github.com/chika0801/Xray-examples) 又如[@lxhao61](https://github.com/lxhao61/integrated-examples)。
|
||||
The configuration of Xray itself is not the main focus of this article. Users should modify it according to their actual situation. For specific details, please refer to the [official document examples](https://github.com/XTLS/Xray-examples) or other excellent examples such as [@chika0801](https://github.com/chika0801/Xray-examples) and [@lxhao61](https://github.com/lxhao61/integrated-examples).
|
||||
|
||||
::: warning 注意
|
||||
::: warning Note
|
||||
|
||||
若使用其他配置,你需要着重注意客户端配置中 `outbound` 中`tag` 为 `proxy` 的部分,其他部分不变
|
||||
If you use other configurations, you need to pay special attention to the part where the `tag` is `proxy` in the `outbound` section of the client configuration. Other parts remain unchanged.
|
||||
|
||||
服务端配置也要同时改变
|
||||
The server configuration must also be changed accordingly.
|
||||
:::
|
||||
|
||||
此配置意在解决例如 Netflix 等默认使用 ipv6 连接的网站无法通过旁路由进行代理的问题,或对 ipv6 代理有需要。
|
||||
This configuration aims to solve the problem where websites that default to IPv6 connections, such as Netflix, cannot be proxied through a side router (gateway), or to satisfy the need for IPv6 proxying.
|
||||
|
||||
本文网络结构为单臂旁路由
|
||||
The network structure in this article is a Single-Arm Router (Side Router).
|
||||
|
||||
本文中所有配置已在 Arch Linux (Kernel: 6.0.10) 环境下测试成功,如在其它环境中同理
|
||||
All configurations in this article have been successfully tested in an Arch Linux (Kernel: 6.0.10) environment. The logic is the same for other environments.
|
||||
|
||||
注意安装相应程序 `# sudo apt install iptables ip6tables` 或 `# sudo apt install nftables`。
|
||||
Note that you need to install the corresponding programs: `# sudo apt install iptables ip6tables` or `# sudo apt install nftables`.
|
||||
|
||||
若旁路由未安装 xray 程序,可以手动下载相应 xray 程序如 [Xray-linux-64.zip](https://github.com/XTLS/Xray-core/releases/download/v1.7.0/Xray-linux-64.zip) ,然后复制 [install-release.sh](https://github.com/XTLS/Xray-install/blob/main/install-release.sh) 文件到旁路由,赋予可执行权限 `# chmod 700 install-release.sh`,然后使用 `# ./install-release.sh --local Xray-linux-64.zip` 根据提示进行本地安装。
|
||||
If the Xray program is not installed on the side router, you can manually download the corresponding Xray program, such as [Xray-linux-64.zip](https://github.com/XTLS/Xray-core/releases/download/v1.7.0/Xray-linux-64.zip), then copy the [install-release.sh](https://github.com/XTLS/Xray-install/blob/main/install-release.sh) file to the side router, grant executable permission `# chmod 700 install-release.sh`, and then use `# ./install-release.sh --local Xray-linux-64.zip` to perform a local installation according to the prompts.
|
||||
|
||||
## Xray 配置
|
||||
## Xray Configuration
|
||||
|
||||
### 客户端配置
|
||||
### Client Configuration
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -49,8 +49,7 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
},
|
||||
"streamSettings": {
|
||||
"sockopt": {
|
||||
"tproxy": "tproxy",
|
||||
"mark": 255
|
||||
"tproxy": "tproxy"
|
||||
}
|
||||
}
|
||||
},
|
||||
@@ -69,17 +68,19 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
],
|
||||
"outbounds": [
|
||||
{
|
||||
//此为默认outbound,路由(routing)模块若未匹配到任何规则,则默认走此 proxy 出口,如果你希望直连国内优先请将下面 direct 出口放到 outbound 第一,看不懂可忽略
|
||||
// This is the default outbound. If the routing module does not match any rules,
|
||||
// it defaults to this "proxy" exit. If you prefer direct connection for domestic traffic as priority,
|
||||
// please move the "direct" outbound below to the first position in outbounds. Ignore if you don't understand.
|
||||
"tag": "proxy",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"vnext": [
|
||||
{
|
||||
"address": "yourdomain.domain", //改为你自己的域名,直接填写ipv4或ipv6地址也可以
|
||||
"address": "yourdomain.domain", // Change to your own domain. Direct IPv4 or IPv6 address is also acceptable.
|
||||
"port": 443,
|
||||
"users": [
|
||||
{
|
||||
"id": "uuid", //填写uuid,可通过在终端中输入 xray uuid 生成;此处也支持任意字符串(https://xtls.github.io/config/inbounds/vless.html#clientobject)
|
||||
"id": "uuid", // Fill in UUID. Can be generated by typing 'xray uuid' in terminal; Arbitrary strings are also supported ([https://xtls.github.io/config/inbounds/vless.html#clientobject](https://xtls.github.io/config/inbounds/vless.html#clientobject))
|
||||
"encryption": "none",
|
||||
"flow": "xtls-rprx-vision"
|
||||
}
|
||||
@@ -92,12 +93,12 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"mark": 255
|
||||
},
|
||||
"network": "tcp",
|
||||
"security": "tls", //注意使用 xtls-rprx-vision 流控此处需为 tls
|
||||
"security": "tls", // Note: must be tls when using xtls-rprx-vision flow
|
||||
"tlsSettings": {
|
||||
//注意使用 xtls-rprx-vision 流控此处需为 tlsSettings
|
||||
// Note: must be tlsSettings when using xtls-rprx-vision flow
|
||||
"allowInsecure": false,
|
||||
"serverName": "yourdomain.domain", //改为你自己的域名
|
||||
"fingerprint": "chrome" //此设置建议先看下Release, https://github.com/XTLS/Xray-core/releases/tag/v1.7.3
|
||||
"serverName": "yourdomain.domain", // Change to your own domain
|
||||
"fingerprint": "chrome" // Recommended to check Release notes for this setting: [https://github.com/XTLS/Xray-core/releases/tag/v1.7.3](https://github.com/XTLS/Xray-core/releases/tag/v1.7.3)
|
||||
}
|
||||
}
|
||||
},
|
||||
@@ -136,16 +137,16 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"hosts": {
|
||||
"domain:googleapis.cn": "googleapis.com",
|
||||
"dns.google": "8.8.8.8",
|
||||
"你的VPS域名": "你的VSP IP" //如果 outbound 的 proxy 里 address 填的域名:希望代理走ipv4,这里 VPS IP 填VPS的ipv4, 希望代理走ipv6,这里VPS IP 填VPS的ipv6;outbound 的 proxy 里 address 填的 IP,这行不用写。
|
||||
"Your_VPS_Domain": "Your_VPS_IP" // If 'address' in outbound proxy is a domain: fill VPS IPv4 if you want proxy via IPv4, fill VPS IPv6 if via IPv6; If 'address' is an IP, skip this line.
|
||||
},
|
||||
"servers": [
|
||||
"https://1.1.1.1/dns-query",
|
||||
"[https://1.1.1.1/dns-query](https://1.1.1.1/dns-query)",
|
||||
{
|
||||
"address": "119.29.29.29",
|
||||
"domains": ["geosite:cn"],
|
||||
"expectIPs": ["geoip:cn"]
|
||||
},
|
||||
"https://dns.google/dns-query",
|
||||
"[https://dns.google/dns-query](https://dns.google/dns-query)",
|
||||
"223.5.5.5",
|
||||
"localhost"
|
||||
]
|
||||
@@ -179,7 +180,7 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"ip": ["geoip:private", "geoip:cn"], //此处可加入 VPS IP 避免 ssh 时被代理
|
||||
"ip": ["geoip:private", "geoip:cn"], // Can add VPS IP here to avoid proxying SSH connections
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
@@ -203,7 +204,7 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
}
|
||||
```
|
||||
|
||||
### 服务端配置
|
||||
### Server Configuration
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -214,7 +215,7 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
//阻止 cnip 提高安全性,或者可以将 cn 流量导入 warp 中,详见https://xtls.github.io/document/level-2/warp.html
|
||||
// Block CN IP to improve security, or you can route CN traffic into Warp, see [https://xtls.github.io/document/level-2/warp.html](https://xtls.github.io/document/level-2/warp.html)
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "block"
|
||||
}
|
||||
@@ -227,14 +228,14 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
"id": "uuid", //与客户端相同
|
||||
"id": "uuid", // Same as client
|
||||
"flow": "xtls-rprx-vision"
|
||||
}
|
||||
],
|
||||
"decryption": "none",
|
||||
"fallbacks": [
|
||||
{
|
||||
"dest": 8080 //回落,需要 web 配合,参见白话文,不设置也行
|
||||
"dest": 8080 // Fallback, requires web server cooperation, see the plain English guide. Optional.
|
||||
}
|
||||
]
|
||||
},
|
||||
@@ -245,7 +246,7 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
"certificates": [
|
||||
{
|
||||
"certificateFile": "/etc/ssl/private/fullchain.crt",
|
||||
"keyFile": "/etc/ssl/private/crt.key" //参照小小白话文将生成的 fullchain.crt 以及 cert.key证书的路径相应填于此处(https://xtls.github.io/document/level-0/ch06-certificates.html#_6-4-%E6%AD%A3%E5%BC%8F%E8%AF%81%E4%B9%A6%E7%94%B3%E8%AF%B7)
|
||||
"keyFile": "/etc/ssl/private/crt.key" // Refer to the Beginner's Guide to fill in the path of the generated fullchain.crt and cert.key here ([https://xtls.github.io/document/level-0/ch06-certificates.html#_6-4-%E6%AD%A3%E5%BC%8F%E8%AF%81%E4%B9%A6%E7%94%B3%E8%AF%B7](https://xtls.github.io/document/level-0/ch06-certificates.html#_6-4-%E6%AD%A3%E5%BC%8F%E8%AF%81%E4%B9%A6%E7%94%B3%E8%AF%B7))
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -269,36 +270,38 @@ title: TProxy 透明代理 (ipv4 and ipv6)
|
||||
}
|
||||
```
|
||||
|
||||
## Netfilter 配置
|
||||
## Netfilter Configuration
|
||||
|
||||
### 首先设置策略路由
|
||||
### First, Set Policy Routing
|
||||
|
||||
```bash
|
||||
# 设置策略路由 v4
|
||||
# Set policy routing v4
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
|
||||
# 设置策略路由 v6
|
||||
# Set policy routing v6
|
||||
ip -6 rule add fwmark 1 table 106
|
||||
ip -6 route add local ::/0 dev lo table 106
|
||||
|
||||
# 直连从主路由发出
|
||||
ip route add default via 192.168.31.1 #写主路由 ipv4, 采用局域网设备上网设置方法一可不写此命令
|
||||
ip -6 route add default via fd00:6868:6868::1 #写主路由 ipv6, 采用局域网设备上网设置方法一可不写此命令
|
||||
# Direct connection goes out from the main router
|
||||
ip route add default via 192.168.31.1 # Write main router IPv4. Not needed if using Method 1 for LAN devices.
|
||||
ip -6 route add default via fd00:6868:6868::1 # Write main router IPv6. Not needed if using Method 1 for LAN devices.
|
||||
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
::: tip Usage
|
||||
|
||||
直接将命令复制到旁路由终端执行
|
||||
Copy the commands directly to the side router terminal and execute them.
|
||||
:::
|
||||
|
||||
::: tip 关于直连从主路由发出
|
||||
::: tip About "Direct connection goes out from the main router"
|
||||
|
||||
在旁路由使用命令`ip route show`,如果使用下属方法一,则`default via`后应是主路由 ip,无需更改;如使用下述方法二,则`default via`后应是旁路由 ip,此时直连网站 DNS 解析会回环,造成直连网站无法访问,因此需指定为主路由 ip。
|
||||
Run the command `ip route show` on the side router.
|
||||
If you use **Method 1** below, the `default via` should be the main router's IP, and no change is needed.
|
||||
If you use **Method 2** below, the `default via` would be the side router's IP. In this case, DNS resolution for direct connections will loop back, causing direct websites to be inaccessible, so it must be specified as the main router's IP.
|
||||
:::
|
||||
|
||||
如果是在路由器上指定了默认网关为旁路由(亦即下述“局域网设备上网设置方法二”),那么就需要设置上述 `# 直连从主路由发出` ,除了通过 iproute2 命令行方式设置,也可以通过 dhcpcd 或者 systemctl-network 设置静态 IP,这里以 dhcpcd 为例,编辑 `/etc/dhcpcd.conf` 文件,在最下方加入如下配置,具体 IP 根据你的实际情况修改,其中 `interface` 可以通过 `# ip link show` 查看要设定的网口或者无线设备。
|
||||
If you specified the default gateway as the side router on the main router (i.e., "LAN Device Internet Setup Method 2" below), then you need to set the above `# Direct connection goes out from the main router`. besides setting it via `iproute2` command line, you can also set a static IP via `dhcpcd` or `systemctl-network`. Here we take `dhcpcd` as an example. Edit the `/etc/dhcpcd.conf` file and add the following configuration at the bottom. Modify the specific IP according to your actual situation. The `interface` can be viewed via `# ip link show` to see the network port or wireless device to be configured.
|
||||
|
||||
```
|
||||
interface enp0s25
|
||||
@@ -308,19 +311,19 @@ static routers=192.168.31.1
|
||||
static domain_name_servers=192.168.31.1 fd00:6868:6868::1
|
||||
```
|
||||
|
||||
这样通过静态 IP 设置 IP 及网关后就无需每次开机设置 `# 直连从主路由发出`。
|
||||
By setting the IP and gateway via static IP this way, there is no need to set `# Direct connection goes out from the main router` every time you boot.
|
||||
|
||||
::: warning 注意
|
||||
::: warning Note
|
||||
|
||||
以下 nftables 配置与 iptables 配置二选一,不可同时使用。
|
||||
Choose **either** the following nftables configuration **or** iptables configuration. Do not use both simultaneously.
|
||||
:::
|
||||
|
||||
### 使用 iptables
|
||||
### Using iptables
|
||||
|
||||
此处配置将 ipv4 与 ipv6 写在同一文件中。
|
||||
This configuration writes IPv4 and IPv6 into the same file.
|
||||
|
||||
```bash
|
||||
# 代理局域网设备 v4
|
||||
# Proxy LAN devices v4
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 127.0.0.1/32 -j RETURN
|
||||
iptables -t mangle -A XRAY -d 224.0.0.0/4 -j RETURN
|
||||
@@ -332,7 +335,7 @@ iptables -t mangle -A XRAY -p udp -j TPROXY --on-ip 127.0.0.1 --on-port 12345 --
|
||||
iptables -t mangle -A XRAY -p tcp -j TPROXY --on-ip 127.0.0.1 --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A PREROUTING -j XRAY
|
||||
|
||||
# 代理局域网设备 v6
|
||||
# Proxy LAN devices v6
|
||||
ip6tables -t mangle -N XRAY6
|
||||
ip6tables -t mangle -A XRAY6 -d ::1/128 -j RETURN
|
||||
ip6tables -t mangle -A XRAY6 -d fe80::/10 -j RETURN
|
||||
@@ -343,7 +346,7 @@ ip6tables -t mangle -A XRAY6 -p udp -j TPROXY --on-ip ::1 --on-port 12345 --tpro
|
||||
ip6tables -t mangle -A XRAY6 -p tcp -j TPROXY --on-ip ::1 --on-port 12345 --tproxy-mark 1
|
||||
ip6tables -t mangle -A PREROUTING -j XRAY6
|
||||
|
||||
# 代理网关本机 v4
|
||||
# Proxy Gateway Itself v4
|
||||
iptables -t mangle -N XRAY_MASK
|
||||
iptables -t mangle -A XRAY_MASK -d 224.0.0.0/4 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d 255.255.255.255/32 -j RETURN
|
||||
@@ -354,7 +357,7 @@ iptables -t mangle -A XRAY_MASK -p udp -j MARK --set-mark 1
|
||||
iptables -t mangle -A XRAY_MASK -p tcp -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -j XRAY_MASK
|
||||
|
||||
# 代理网关本机 v6
|
||||
# Proxy Gateway Itself v6
|
||||
ip6tables -t mangle -N XRAY6_MASK
|
||||
ip6tables -t mangle -A XRAY6_MASK -d fe80::/10 -j RETURN
|
||||
ip6tables -t mangle -A XRAY6_MASK -d fd00::/8 -p tcp -j RETURN
|
||||
@@ -364,13 +367,13 @@ ip6tables -t mangle -A XRAY6_MASK -p udp -j MARK --set-mark 1
|
||||
ip6tables -t mangle -A XRAY6_MASK -p tcp -j MARK --set-mark 1
|
||||
ip6tables -t mangle -A OUTPUT -j XRAY6_MASK
|
||||
|
||||
# 新建 DIVERT 规则,避免已有连接的包二次通过 TPROXY,理论上有一定的性能提升 v4
|
||||
# Create DIVERT rule to avoid packet re-traversal through TPROXY for existing connections, theoretical performance boost v4
|
||||
iptables -t mangle -N DIVERT
|
||||
iptables -t mangle -A DIVERT -j MARK --set-mark 1
|
||||
iptables -t mangle -A DIVERT -j ACCEPT
|
||||
iptables -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
|
||||
|
||||
# 新建 DIVERT 规则,避免已有连接的包二次通过 TPROXY,理论上有一定的性能提升 v6
|
||||
# Create DIVERT rule to avoid packet re-traversal through TPROXY for existing connections, theoretical performance boost v6
|
||||
ip6tables -t mangle -N DIVERT
|
||||
ip6tables -t mangle -A DIVERT -j MARK --set-mark 1
|
||||
ip6tables -t mangle -A DIVERT -j ACCEPT
|
||||
@@ -378,16 +381,16 @@ ip6tables -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
|
||||
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
::: tip Usage
|
||||
|
||||
将上述配置写入一个文件(如 `iptables.rules`),之后将该文件赋予可执行权限`# chmod 700 ./iptables.rules`
|
||||
Write the above configuration into a file (e.g., `iptables.rules`), then grant executable permission to the file: `# chmod 700 ./iptables.rules`.
|
||||
|
||||
最后使用 root 权限执行该文件即可:`# ./iptables.rules`或`# source iptables.rules`。
|
||||
Finally, execute the file with root privileges: `# ./iptables.rules` or `# source iptables.rules`.
|
||||
:::
|
||||
|
||||
### 使用 nftables
|
||||
### Using nftables
|
||||
|
||||
此处合并 ipv4 与 ipv6
|
||||
This merges IPv4 and IPv6.
|
||||
|
||||
```
|
||||
#!/usr/sbin/nft -f
|
||||
@@ -428,30 +431,30 @@ table inet xray {
|
||||
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
::: tip Usage
|
||||
|
||||
将上述配置写入一个文件(如 `nftables.rules`),之后将该文件赋予可执行权限`# chmod 700 ./nftables.rules`
|
||||
Write the above configuration into a file (e.g., `nftables.rules`), then grant executable permission to the file: `# chmod 700 ./nftables.rules`.
|
||||
|
||||
最后使用 root 权限执行该文件即可:`# ./nftables.rules`或`# source nftables.rules`
|
||||
Finally, execute the file with root privileges: `# ./nftables.rules` or `# source nftables.rules`.
|
||||
:::
|
||||
|
||||
其中,网关地址`192.168.0.0/16`, `fd00::/8`等可由`ip address | grep -w inet | awk '{print $2}'`以及`ip address | grep -w inet6 | awk '{print $2}'`[获得](https://xtls.github.io/document/level-2/iptables_gid.html#_4-%E8%AE%BE%E7%BD%AE-iptables-%E8%A7%84%E5%88%99)
|
||||
Where gateway addresses `192.168.0.0/16`, `fd00::/8`, etc., can be [obtained](https://xtls.github.io/document/level-2/iptables_gid.html#_4-%E8%AE%BE%E7%BD%AE-iptables-%E8%A7%84%E5%88%99) by `ip address | grep -w inet | awk '{print $2}'` and `ip address | grep -w inet6 | awk '{print $2}'`.
|
||||
|
||||
或者在 windows 网络设置中查看。
|
||||
Or check in Windows Network Settings.
|
||||
|
||||
又或者在路由器“上网设置”中查看。
|
||||
Or check in the Router's "Internet Settings".
|
||||
|
||||
如果前缀`192.168`, `fd00:`相同可不更改,若不同如 `fc00:`, `fe00:` 等则更改为相应值,写法可通过 Goolge 搜索得到如 `fc00::/7`, `fe00::/9`。
|
||||
If the prefixes `192.168`, `fd00:` are the same, you don't need to change them. If they are different, such as `fc00:`, `fe00:`, etc., change them to the corresponding values. The notation (like `fc00::/7`, `fe00::/9`) can be found via Google search.
|
||||
|
||||
### 开机自动运行 Netfilter 配置
|
||||
### Auto-run Netfilter Configuration on Boot
|
||||
|
||||
首先确认已经运行过上述相应 Netfilter 命令,并且成功测试透明代理配置,以确保接下来输出正确的文件。
|
||||
First, confirm that you have run the corresponding Netfilter commands above and successfully tested the transparent proxy configuration to ensure the output files are correct.
|
||||
|
||||
#### 若使用 iptables 配置
|
||||
#### If using iptables configuration
|
||||
|
||||
1. 首先通过 `# iptables-save > /root/iptables.rulesv4` `# ip6tables-save > /root/iptables.rulesv6` 将 iptables 配置写入 `iptables.rulesv4` 和 `iptables.rulesv6` 文件中
|
||||
1. First, save the iptables configuration to `iptables.rulesv4` and `iptables.rulesv6` files: `# iptables-save > /root/iptables.rulesv4` and `# ip6tables-save > /root/iptables.rulesv6`.
|
||||
|
||||
2. 然后在 `/etc/systemd/system/` 目录下创建一个名为 `tproxyrules.service` 的文件,添加以下内容并保存
|
||||
2. Then create a file named `tproxyrules.service` in the `/etc/systemd/system/` directory, add the following content, and save it:
|
||||
|
||||
```
|
||||
[Unit]
|
||||
@@ -482,13 +485,13 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. 最后执行 `systemctl enable tproxyrules` 命令。
|
||||
1. Finally, execute the command `systemctl enable tproxyrules`.
|
||||
|
||||
#### 如果使用 nftables 配置
|
||||
#### If using nftables configuration
|
||||
|
||||
1. 首先通过 `# nft list ruleset > /root/nftables.rulesv46` 将 nftables 配置写入 `nftables.rulesv46` 文件中
|
||||
1. First, write the nftables configuration to the `nftables.rulesv46` file: `# nft list ruleset > /root/nftables.rulesv46`.
|
||||
|
||||
2. 在 `/etc/systemd/system/` 目录下创建一个名为 `tproxyrules.service` 的文件,然后添加以下内容并保存
|
||||
2. Create a file named `tproxyrules.service` in the `/etc/systemd/system/` directory, then add the following content and save it:
|
||||
|
||||
```
|
||||
[Unit]
|
||||
@@ -517,55 +520,57 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. 最后执行 `systemctl enable tproxyrules` 命令。
|
||||
1. Finally, execute the command `systemctl enable tproxyrules`.
|
||||
|
||||
::: tip tproxyrules.service
|
||||
|
||||
注意其中主路由器 IP 地址,根据实际修改
|
||||
Note the Main Router IP address, modify it according to reality.
|
||||
|
||||
`ExecStartPre=/bin/sh -c 'until ping -c1 192.168.31.1; do sleep 1; done;'` 命令为确保获得 IP 地址后再执行命令,否则会诡异报错,其中 IP 地址为主路由器地址,根据实际修改。
|
||||
The command `ExecStartPre=/bin/sh -c 'until ping -c1 192.168.31.1; do sleep 1; done;'` ensures that the command is executed only after obtaining an IP address, otherwise weird errors may occur. The IP address is the main router address, modify it according to reality.
|
||||
:::
|
||||
|
||||
::: warning 注意
|
||||
::: warning Note
|
||||
|
||||
如果通过 dhcpcd 等设置了静态 IP 及网关,则上述相关 `ip route add/del` 设置需删除
|
||||
If you have set a static IP and gateway via dhcpcd, etc., the related `ip route add/del` settings above should be removed.
|
||||
:::
|
||||
|
||||
## 局域网设备上网设置
|
||||
## LAN Device Internet Setup
|
||||
|
||||
此处假定旁路由 ipv4, ipv6 地址分别为`192.168.31.100`, `fd00:6868:6868::8866`, 旁路由的 ipv4, ipv6 地址可由命令`ip add`获得。
|
||||
Assuming the IPv4 and IPv6 addresses of the side router are `192.168.31.100` and `fd00:6868:6868::8866` respectively. The IP addresses of the side router can be obtained by the command `ip add`.
|
||||
|
||||
### 方法一
|
||||
### Method 1
|
||||
|
||||
局域网设备上网有两种方式,第一种就是在使用设备上进行静态 IP 的配置,将网关指向旁路由 IP。注意绝大部分手机仅支持手动配置 ipv4 网关,不支持手动配置 ipv6 网关,除非 root 后进行相关设置。
|
||||
There are two ways for LAN devices to access the Internet. The first is to configure a static IP on the device and point the gateway to the side router IP. Note that most mobile phones only support manual configuration of IPv4 gateways and do not support manual configuration of IPv6 gateways unless rooted and configured accordingly.
|
||||
|
||||
以 windows 设备为例,可以先开启 DHCP 记录自动分配的 IP 以参考,然后手写静态配置。
|
||||
Taking a Windows device as an example, you can first enable DHCP to record the automatically assigned IP for reference, and then write the static configuration manually.
|
||||
|
||||
::: tip DNS 设置
|
||||
::: tip DNS Settings
|
||||
|
||||
此配置劫持 DNS 流量,DNS 可以随便写
|
||||
This configuration hijacks DNS traffic, so DNS can be written arbitrarily.
|
||||
|
||||
It is recommended to set it to the side router IP to prevent DNS leaks.
|
||||
:::
|
||||
|
||||
<img width="231" alt="image" src="https://user-images.githubusercontent.com/110686480/208310266-632e36b9-a23b-4b90-aa28-583b50e87c66.png"> <img width="238" alt="image" src="https://user-images.githubusercontent.com/110686480/208309659-e3172218-ef27-4a94-a017-225f8e05b611.png">
|
||||
|
||||
### 方法二
|
||||
### Method 2
|
||||
|
||||
局域网设备上网的第二种方式,是在路由器上进行网关设置,这种方法对于连接到此路由器的设备无需做任何设置即可科学上网,但注意有些路由器不支持 ipv6 的网关设置,有 ipv6 需求的设备仍需在所需设备上单独手动配置 ipv6 相关设置参考方法一。
|
||||
The second way for LAN devices to access the Internet is to configure the gateway on the router. With this method, devices connected to this router can access the scientific internet (bypass firewall) without any configuration. However, note that some routers do not support IPv6 gateway configuration. Devices requiring IPv6 still need to manually configure IPv6-related settings on the specific device (refer to Method 1).
|
||||
|
||||
<img width="700" alt="image" src="https://user-images.githubusercontent.com/110686480/208310174-2245a890-eb6b-4341-899f-81c6ac8255ff.png">
|
||||
|
||||
## Finally
|
||||
|
||||
按照以上方法设置后设备即可双栈访问,进入测试网站比如 https://ipv6-test.com/ 可以看到如下结果 (需要代理此网站才能看到如下结果)
|
||||
After setting up according to the above methods, the device can access via dual-stack. Entering a test website like <https://ipv6-test.com/>, you can see the following results (you need to proxy this website to see the result below):
|
||||
|
||||
<img width="700" alt="image" src="https://user-images.githubusercontent.com/110686480/208743723-f8a2751b-43d0-4353-9383-5ae0e00e9449.png">
|
||||
|
||||
## 写在最后
|
||||
## Closing Thoughts
|
||||
|
||||
如今 ipv6 并未完全普及,我们日常访问的流量 99%仍为 ipv4 流量;很多 VPS 商家虽然提供 ipv6 地址,但线路优化非常垃圾,甚至处于不可用状态,为何要加入 ipV6 的设置?
|
||||
Nowadays, IPv6 is not yet fully popularized. 99% of our daily access traffic is still IPv4 traffic. Although many VPS providers offer IPv6 addresses, the route optimization is often garbage, or even in an unusable state. So why add IPv6 settings?
|
||||
|
||||
可以看到目前 ipv6 处于很尴尬的境地,各种设备对于 ipv6 的支持很烂,但是都在逐步完善,同时 Windows 系统对于 ipv6 的优先级也在提高,很多浏览器也会优先进行 ipv6 的解析以及访问,很多网站也开始默认使用 ipv6 进行访问(比如 Netflix, 如果没有配置 ipv6, 浏览器打开 Netflix 会显示 Not Available 是因为没有代理 Netflix 的 ipv6 请求,当然可以选择禁用 Windows 的 ipv6,但支持 ipv6 的 pt 站就无法使用)
|
||||
It can be seen that IPv6 is currently in an awkward position. Support for IPv6 on various devices is poor, but it is gradually improving. At the same time, the priority of IPv6 in Windows systems is also increasing. Many browsers will also prioritize IPv6 resolution and access. Many websites have also started to use IPv6 for access by default (such as Netflix; if IPv6 is not configured, opening Netflix in the browser will show "Not Available" because the IPv6 request for Netflix is not proxied. Of course, you can choose to disable IPv6 in Windows, but PT sites that support IPv6 will not be usable).
|
||||
|
||||
这种情况下 ipv4 无法完全胜任网络冲浪的需求,即使是那 1%的流量,遇到了也会让人头疼不已。
|
||||
In this case, IPv4 cannot fully meet the needs of web surfing. Even if it is only that 1% of traffic, encountering it can be a headache.
|
||||
|
||||
而可以预见 ipv6 也会逐步与 ipv4 分庭抗礼,所以有必要加入 ipv6 的设置。
|
||||
And it is foreseeable that IPv6 will gradually stand up to IPv4, so it is necessary to add IPv6 settings.
|
||||
|
||||
@@ -1,23 +1,23 @@
|
||||
---
|
||||
title: 流量统计
|
||||
title: Traffic Statistics
|
||||
---
|
||||
|
||||
# 流量统计配置教程
|
||||
# Traffic Statistics Configuration Tutorial
|
||||
|
||||
请熟悉[流量统计 白话文教程](https://guide.v2fly.org/advanced/traffic.html),本文在其基础上适配了 Xray(1.5.9+)。
|
||||
Please familiarize yourself with the [Traffic Statistics Plain Language Guide](https://guide.v2fly.org/advanced/traffic.html). This article adapts those concepts for Xray (1.5.9+).
|
||||
|
||||
## 查看流量信息
|
||||
## Viewing Traffic Information
|
||||
|
||||
配置方法与 v2fly 一致。
|
||||
查看流量信息是 xray 命令行的其中一个功能。配置内设置的 api dokodemo-door 端口,即为 `--server` 参数的端口。
|
||||
The configuration method is consistent with v2fly.
|
||||
Viewing traffic information is one of the features of the xray command line. The `api dokodemo-door` port set in the configuration corresponds to the port for the `--server` parameter.
|
||||
|
||||
```bash
|
||||
xray api statsquery --server=127.0.0.1:10085 #查看所有流量
|
||||
xray help api statsquery #statsquery 查询匹配的记录
|
||||
xray help api stats #stats 查询一个记录
|
||||
xray api statsquery --server=127.0.0.1:10085 # View all traffic statistics
|
||||
xray help api statsquery # statsquery queries matching records
|
||||
xray help api stats # stats queries a single record
|
||||
```
|
||||
|
||||
输出例子:
|
||||
Output example:
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -58,9 +58,9 @@ xray help api stats #stats 查询一个记录
|
||||
}
|
||||
```
|
||||
|
||||
## 流量信息的处理
|
||||
## Processing Traffic Information
|
||||
|
||||
把以下脚本保存到 `traffic.sh`,注意使用 `chmod 755 traffic.sh` 授予执行权限。注意调整修改 `_APISERVER` 一行的连接具体的端口参数。
|
||||
Save the following script to `traffic.sh`, and remember to use `chmod 755 traffic.sh` to grant execution permissions. Pay attention to adjusting the specific port parameter in the `_APISERVER` line.
|
||||
|
||||
```bash
|
||||
#!/bin/bash
|
||||
|
||||
@@ -1,104 +1,107 @@
|
||||
# 透明代理入门
|
||||
# Introduction to Transparent Proxy
|
||||
|
||||
## 什么是透明代理
|
||||
## What is a Transparent Proxy?
|
||||
|
||||
透明代理简单地说就是不让被代理的设备感觉到自己被代理了。简单地说就是,被代理的设备上不需要运行任何代理软件(比如 Xray、V2RayNG 等),当你连接上网络时,你的设备已经被代理了。
|
||||
Simply put, a transparent proxy means that the proxied device does not realize it is being proxied. In other words, no proxy software (such as Xray, V2RayNG, etc.) needs to be run on the proxied device itself. When you connect to the network, your device is automatically proxied.
|
||||
|
||||
这也意味着,代理的软件运行在别的地方,比如运行在路由器中,通过路由器上网的设备就自动被代理了。
|
||||
This also implies that the proxy software is running elsewhere, for example, on a router. Devices accessing the Internet through this router are automatically proxied.
|
||||
|
||||
## 透明代理的实现
|
||||
## Implementation of Transparent Proxy
|
||||
|
||||
透明代理的实现目前主要有两种方式:
|
||||
There are two main ways to implement a transparent proxy:
|
||||
|
||||
### tun2socks
|
||||
|
||||
可用 Windows/Linux(包括安卓)实现。因为实现过程比较简单,很少有教程,我这里简单描述一下。
|
||||
This can be implemented on Windows/Linux (including Android). Since the implementation process is relatively simple, there are few tutorials available. I will briefly describe it here.
|
||||
|
||||
**Windows**
|
||||
|
||||
1. 安装 **[Netch](https://github.com/NetchX/Netch/releases)** ,使用模式`[3] [TUN/TAP] 绕过局域网`启动。
|
||||
1. Install **[Netch](https://github.com/NetchX/Netch/releases)** and start it using the mode `[3] [TUN/TAP] Bypass LAN`.
|
||||
|
||||
2. 开启热点
|
||||
2. Enable the Mobile Hotspot.
|
||||
|
||||
3. 打开`控制面板`->`网络和 Internet`->`网络和共享中心`->`更改适配器设置`,找到`TAP-Windows Adapter`和`Microsoft Wi-Fi Direct Virtual Adapter`。
|
||||
3. Open `Control Panel` -> `Network and Internet` -> `Network and Sharing Center` -> `Change adapter settings`. Find `TAP-Windows Adapter` and `Microsoft Wi-Fi Direct Virtual Adapter`.
|
||||
|
||||
4. 鼠标右键点击`TAP-Windows Adapter`,`属性`->`共享`,勾选`允许其他网络用户通过此计算机的 Internet 连接来连接`,在`家庭网络连接`中选择`Microsoft Wi-Fi Direct Virtual Adapter`的那个网络连接,点击确定。
|
||||
4. Right-click on `TAP-Windows Adapter`, select `Properties` -> `Sharing`. Check `Allow other network users to connect through this computer's Internet connection`. Under `Home networking connection`, select the network connection corresponding to the `Microsoft Wi-Fi Direct Virtual Adapter`, and click OK.
|
||||
|
||||
**Android**
|
||||
|
||||
1. 配置连接 V2RayNG
|
||||
1. Configure and connect V2RayNG.
|
||||
|
||||
2. 开启热点
|
||||
2. Enable Hotspot.
|
||||
|
||||
3. 热点设置 -> 允许热点使用 VPN(部分安卓系统可能没有这个选项)
|
||||
3. Hotspot Settings -> Allow hotspot to use VPN (some Android systems may not have this option).
|
||||
|
||||
### iptables/nftables
|
||||
|
||||
iptables 与 nftables 实现透明代理的原理相同,下文统一使用 iptables。
|
||||
The principle of implementing a transparent proxy with iptables and nftables is the same. The text below will unify the description using iptables.
|
||||
|
||||
基于 iptables 的透明代理实现只能用于 Linux 系统(包括 openwrt/安卓)。由于其比 tun2socks 更高效率以及适合在路由器中配置而广泛使用。
|
||||
Transparent proxy implementation based on iptables can only be used on Linux systems (including OpenWrt/Android). It is widely used because it is more efficient than tun2socks and is suitable for configuration in routers.
|
||||
|
||||
现存的三篇白话文透明代理教程其实讲的都是基于这种方案的透明代理实现,它们是: **[新 V2Ray 白话文指南-透明代理](https://guide.v2fly.org/app/transparent_proxy.html)** 、 **[新 V2Ray 白话文指南-透明代理(TPROXY)](https://guide.v2fly.org/app/tproxy.html)** 、 **[透明代理(TProxy)配置教程](../tproxy.md)** 。其中第一篇是基于 iptables-redirect 模式,已经过时了,不建议使用,仅供参考。第二篇和第三篇讲的都是基于 iptables-tproxy 模式的透明代理实现。
|
||||
The three existing "Plain Language" transparent proxy tutorials are actually all based on this scheme. They are: **[New V2Ray Plain Guide - Transparent Proxy](https://guide.v2fly.org/app/transparent_proxy.html)**, **[New V2Ray Plain Guide - Transparent Proxy (TPROXY)](https://guide.v2fly.org/app/tproxy.html)**, and **[Transparent Proxy (TProxy) Configuration Tutorial](../tproxy.md)**. The first one is based on the iptables-redirect mode, which is obsolete and not recommended (for reference only). The second and third ones discuss transparent proxy implementation based on the iptables-tproxy mode.
|
||||
|
||||
## iptables 实现透明代理原理
|
||||
## Principle of iptables-based Transparent Proxy
|
||||
|
||||
Linux 使用`Netfilter`来管理网络,`Netfilter`模型如下:
|
||||
Linux uses `Netfilter` to manage the network. The `Netfilter` model is as follows:
|
||||
|
||||

|
||||
|
||||
**假设使用路由器作为网关(即我们平时的上网方式),那么:**
|
||||
**Assuming a router is used as the gateway (which is our usual way of accessing the Internet):**
|
||||
|
||||
局域网设备通过路由器访问互联网的流量方向:
|
||||
Traffic direction for LAN devices accessing the Internet via the router:
|
||||
|
||||
`PREROUTING链->FORWARD链->POSTINGROUTING链`
|
||||
`PREROUTING Chain -> FORWARD Chain -> POSTROUTING Chain`
|
||||
|
||||
局域网设备访问路由器的流量(如登陆路由器 web 管理界面/ssh 连接路由器/访问路由器的 dns 服务器等)方向:
|
||||
Traffic direction for LAN devices accessing the router itself (e.g., logging into the router web UI / SSH connection to router / accessing the router's DNS server):
|
||||
|
||||
`PREROUTING链->INPUT链->网关本机`
|
||||
`PREROUTING Chain -> INPUT Chain -> Gateway Local Process`
|
||||
|
||||
路由器访问互联网的流量方向:
|
||||
Traffic direction for the router accessing the Internet:
|
||||
|
||||
`网关本机->OUTPUT链->POSTINGROUTING链`
|
||||
`Gateway Local Process -> OUTPUT Chain -> POSTROUTING Chain`
|
||||
|
||||
**通过使用 iptables 操控`PREROUTING链`和`OUTPUT链`的流量走向,转发到 Xray,就可以代理局域网设备和网关本机。**
|
||||
**By using iptables to manipulate the traffic flow in the `PREROUTING Chain` and `OUTPUT Chain` and forwarding it to Xray, we can proxy both LAN devices and the gateway itself.**
|
||||
|
||||
## 透明代理难在哪里
|
||||
## Where is the Difficulty?
|
||||
|
||||
透明代理的难点就在于路由,所谓路由,就是区分哪些流量是直连的,哪些该被代理,所以我个人认为叫做**分流**更加合适。
|
||||
The difficulty of transparent proxy lies in routing. Routing essentially means distinguishing which traffic should be direct and which should be proxied. Therefore, I personally think calling it **Traffic Splitting** is more appropriate.
|
||||
|
||||
我们可以把路由由易到难分为以下几个阶段:
|
||||
We can divide routing into the following stages, from easy to difficult:
|
||||
|
||||
1. 代理全部请求
|
||||
1. Proxy all requests.
|
||||
|
||||
2. 本地局域网 IP/组播 IP 请求直连,其它请求代理
|
||||
2. Direct connection for local LAN IPs/Multicast IPs; proxy other requests.
|
||||
|
||||
3. 在 2 的基础上直连 Xray 发起的连接请求
|
||||
3. Based on 2, direct connection for connection requests initiated by Xray itself.
|
||||
|
||||
4. 在 3 的基础上直连指向中国大陆 IP 的连接请求,并对国内外域名选择国内外 DNS 服务器解析。
|
||||
4. Based on 3, direct connection for requests pointing to Mainland China IPs, and selecting domestic/foreign DNS servers for parsing domestic/foreign domains respectively.
|
||||
|
||||
上面说的三篇教程,都是在第四阶段。所以新手直接阅读可能显得有点难懂。
|
||||
The three tutorials mentioned above are all at the fourth stage. Therefore, it might seem a bit difficult for beginners to read directly.
|
||||
|
||||
## 从零开始一步步实现基于 iptables-tproxy 的透明代理
|
||||
## Implementing iptables-tproxy Transparent Proxy Step by Step from Scratch
|
||||
|
||||
### 在开始之前,你需要有一定的基础知识:
|
||||
### Before you start, you need some basic knowledge
|
||||
|
||||
1. 大概知道什么是 TCP/IP 协议、域名和 DNS 服务器
|
||||
1. Roughly know what TCP/IP protocol, domain names, and DNS servers are.
|
||||
|
||||
2. 知道什么是 WAN 口,LAN 口,LAN_IP,WAN_IP 以及 DHCP 服务器。对于旁路由,只有一个网口,这里称其为 LAN 口
|
||||
2. Know what WAN port, LAN port, LAN_IP, WAN_IP, and DHCP server are. For a "Side Router" (single-arm router), there is only one network port, which we call the LAN port here.
|
||||
|
||||
3. 对 Linux 系统有最基础的了解(知道怎么运行命令)
|
||||
3. Have a basic understanding of the Linux system (know how to run commands).
|
||||
|
||||
4. 能够手写客户端 json 文件配置,至少要能看懂
|
||||
4. Be able to hand-write client JSON configuration files, or at least understand them.
|
||||
|
||||
### 前期准备工作
|
||||
### Preparation Work
|
||||
|
||||
**1. 准备一个运行 Linux 系统的网关**
|
||||
::: warning
|
||||
Before starting operations, remember to use `sysctl -w net.ipv4.ip_forward=1` to enable Linux IPv4 packet forwarding.
|
||||
:::
|
||||
**1. Prepare a gateway running a Linux system**
|
||||
|
||||
比如,刷了 OpenWRT 的路由器
|
||||
For example, a router flashed with OpenWrt.
|
||||
|
||||
**2. 在网关(路由器)准备好 Xray 可执行文件以及配置文件**
|
||||
**2. Prepare the Xray executable and configuration file on the gateway (router)**
|
||||
|
||||
配置文件监听 12345 端口,开启 tproxy:
|
||||
The configuration file should listen on port 12345 and enable tproxy:
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -122,19 +125,23 @@ Linux 使用`Netfilter`来管理网络,`Netfilter`模型如下:
|
||||
],
|
||||
"outbounds": [
|
||||
{
|
||||
你的服务器配置
|
||||
Your_Server_Configuration
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
我们由易到难,不写 routing,只写一个 inbound 一个 outbound。
|
||||
Moving from easy to difficult, we won't write `routing` for now, just one `inbound` and one `outbound`.
|
||||
|
||||
### 首先,我们先试试做到第一阶段
|
||||
### First, let's try to achieve Stage 1
|
||||
|
||||
将所有`PREROUTING链`的流量,都转发到 Xray 中。
|
||||
::: warning
|
||||
If you cannot accept that your machine needs to be rebooted, it is best to start a virtual machine for practice first.
|
||||
:::
|
||||
|
||||
运行 Xray,执行以下指令:
|
||||
Forward all traffic from the `PREROUTING Chain` to Xray.
|
||||
|
||||
Run Xray, and execute the following commands:
|
||||
|
||||
```bash
|
||||
ip rule add fwmark 1 table 100
|
||||
@@ -145,43 +152,43 @@ iptables -t mangle -A XRAY -p udp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A PREROUTING -j XRAY
|
||||
```
|
||||
|
||||
当你输入完之后,如果你是使用 ssh 连接到网关上的,你会发现 ssh 的连接断开了(不用紧张,断电重启即可恢复),并且透明代理无法上网;如果你是的网关是虚拟机,你会发现网关本身也无法上网,并且 Xray 日志 access_log 中出现许多源地址为目标地址,目标地址为 WAN_IP 的请求。
|
||||
After entering these commands, if you are connected to the gateway via SSH, you will find that the SSH connection is disconnected (don't panic, a power cycle will restore it), and the transparent proxy cannot access the Internet. If your gateway is a virtual machine, you will find that the gateway itself cannot access the Internet, and many requests with the source address as the destination address and the destination address as the WAN_IP appear in the Xray `access_log`.
|
||||
|
||||
理论上网关本机访问公网只会经过`OUTPUT链`和`POSTROUTING链`,为什么操控`PREROUTING链`会导致网关无法上网呢?这是因为网络通讯往往是双向的,虽然网关访问公网 IP 不需要经过`PREROUTING链`,但被访问的服务器向网关返回信息时要经过`PREROUTING链`,且这部分被转发到 Xray 了,因此出现了日志中的反向请求。
|
||||
Theoretically, the gateway's local access to the public network should only pass through the `OUTPUT Chain` and `POSTROUTING Chain`. Why does manipulating the `PREROUTING Chain` cause the gateway to lose Internet access? This is because network communication is often bidirectional. Although the gateway does not need to pass through the `PREROUTING Chain` to access a public IP, the information returned by the accessed server to the gateway must pass through the `PREROUTING Chain`. Since this part is forwarded to Xray, the reverse requests appear in the log.
|
||||
|
||||
我们修改一下规则,源 IP 不是来自局域网的则返回。重启网关,运行 Xray,执行以下指令:
|
||||
Let's modify the rules to return (skip Xray) if the source IP is not from the LAN. Reboot the gateway, run Xray, and execute the following commands:
|
||||
|
||||
```bash
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
iptables -t mangle -N XRAY
|
||||
# "网关LAN_IP地址段" 通过运行命令"ip address | grep -w "inet" | awk '{print $2}'"获得,是其中的一个
|
||||
iptables -t mangle -A XRAY ! -s 网关LAN_IP地址段 -j RETURN
|
||||
# "Gateway_LAN_IP_Range" can be obtained by running "ip address | grep -w "inet" | awk '{print $2}'". Pick the correct one.
|
||||
iptables -t mangle -A XRAY ! -s Gateway_LAN_IP_Range -j RETURN
|
||||
iptables -t mangle -A XRAY -p tcp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A XRAY -p udp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A PREROUTING -j XRAY
|
||||
```
|
||||
|
||||
然后你会发现,虽然 ssh 连接断开了,但是透明代理已经可用了。只要我们修改系统 dns 为公共 dns,就能正常上网了(因为现在网关访问不了,所以 dns 设置为网关是不行的)。
|
||||
Then you will find that although the SSH connection is disconnected, the transparent proxy is now available. As long as we change the system DNS to a public DNS, we can surf the Internet normally (because the gateway itself cannot be accessed now, setting the DNS to the gateway won't work).
|
||||
|
||||
至此,第一阶段就完成了。之所以无法访问网关,是因为代理规则代理了全部流量,包括访问网关的流量。试想在 VPS 上访问你本地的网关,肯定是访问不了的,所以我们要对这部分流量直连,请看第二阶段:
|
||||
At this point, Stage 1 is complete. The reason the gateway cannot be accessed is that the proxy rules cover *all* traffic, including traffic accessing the gateway. Imagine trying to access your local gateway on a VPS; it certainly won't work. So, we need to make this part of the traffic direct. Please see Stage 2.
|
||||
|
||||
### 第二阶段
|
||||
### Stage 2
|
||||
|
||||
重启网关,运行 Xray,执行以下指令:
|
||||
Reboot the gateway, run Xray, and execute the following commands:
|
||||
|
||||
```bash
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
iptables -t mangle -N XRAY
|
||||
|
||||
# 所有目标地址在网关所在网段的请求直连
|
||||
# 通过运行命令"ip address | grep -w "inet" | awk '{print $2}'"获得,一般来说有多个
|
||||
iptables -t mangle -A XRAY -d 网关所在网段1 -j RETURN
|
||||
iptables -t mangle -A XRAY -d 网关所在网段2 -j RETURN
|
||||
# Direct connection for all requests where the destination address is in the gateway's subnet
|
||||
# Obtained via "ip address | grep -w "inet" | awk '{print $2}'". Generally, there are multiple.
|
||||
iptables -t mangle -A XRAY -d Gateway_Subnet_1 -j RETURN
|
||||
iptables -t mangle -A XRAY -d Gateway_Subnet_2 -j RETURN
|
||||
...
|
||||
|
||||
# 目标地址为组播IP/E类地址/广播IP的请求直连
|
||||
# Direct connection for Multicast IPs / Class E addresses / Broadcast IPs
|
||||
iptables -t mangle -A XRAY -d 224.0.0.0/3 -j RETURN
|
||||
|
||||
iptables -t mangle -A XRAY -p tcp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
@@ -189,86 +196,93 @@ iptables -t mangle -A XRAY -p udp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A PREROUTING -j XRAY
|
||||
```
|
||||
|
||||
使用这条规则后,上一条规则`iptables -t mangle -A XRAY ! -s 网关LAN_IP地址段 -j RETURN`便成为了多余规则,可以删去。
|
||||
After using this rule, the previous rule `iptables -t mangle -A XRAY ! -s Gateway_LAN_IP_Range -j RETURN` becomes redundant and can be removed.
|
||||
|
||||
至此,第二阶段完成。网关已经可以访问,ssh 不会断开。
|
||||
At this point, Stage 2 is complete. The gateway is accessible, and SSH will not disconnect.
|
||||
|
||||
### 第三阶段
|
||||
### Stage 3
|
||||
|
||||
我们平时用的 DNS 一般来自路由器,但这个 iptables 规则只代理了局域网中的设备,却没有代理网关本机,这样返回的 DNS 查询结果可能是错误的或者污染的。
|
||||
The DNS we usually use generally comes from the router, but these iptables rules only proxy devices in the LAN and do not proxy the gateway itself. Thus, the returned DNS query results might be incorrect or polluted.
|
||||
|
||||
iptables-tproxy 不支持对`OUTPUT链`操作,但是`Netfilter`有个特性,在`OUTPUT链`给包打标记为`1`后相应的包会重路由到`PREROUTING链`上。所以我们就给网关本机需要代理的请求在`OUTPUT链`上标记`1`即可。
|
||||
|
||||
如果要代理网关本机发出的的全部请求,就会引入一个问题,Xray 运行在网关,Xray 向代理服务端发送请求,这个请求又被代理了,就形成了回环。
|
||||
|
||||
因此要代理网关本机,就要避免回环发生,即代理规则中规避 Xray 请求的流量。
|
||||
|
||||
**常见的方法有三种:**
|
||||
|
||||
1. 直连目标地址为 VPS 的流量
|
||||
|
||||
重启网关,运行 Xray,执行以下指令:
|
||||
`iptables-tproxy` does not support operations on the `OUTPUT Chain`, but we can reroute packets from the `OUTPUT Chain` to the `PREROUTING Chain` by configuring `Policy Routing`.
|
||||
|
||||
```bash
|
||||
#代理局域网设备
|
||||
#继承上一个阶段的成果
|
||||
# Add policy routing: Packets marked as 1 go to routing table 100
|
||||
ip rule add fwmark 1 table 100
|
||||
# Add route entry to table 100: All packets route to local
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
```
|
||||
|
||||
By configuring the above `Policy Routing`, we only need to mark packets with `1` in the `OUTPUT Chain`, and the corresponding packets will be routed to the local gateway, i.e., the `PREROUTING Chain`. So, we just need to mark requests from the gateway itself that need proxying with `1` on the `OUTPUT Chain`.
|
||||
|
||||
If we proxy all requests originating from the gateway, a problem arises: Xray runs on the gateway and sends requests to the proxy server. If this request is also proxied, a loop is formed.
|
||||
|
||||
Therefore, to proxy the gateway itself, we must avoid loops, which means avoiding Xray's own traffic in the proxy rules.
|
||||
|
||||
**There are three common methods:**
|
||||
|
||||
1. Direct connection for traffic destined for the VPS address
|
||||
|
||||
Reboot the gateway, run Xray, and execute the following commands:
|
||||
|
||||
```bash
|
||||
# Proxy LAN devices
|
||||
# Inherit results from the previous stage
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 网关所在网段1 -j RETURN
|
||||
iptables -t mangle -A XRAY -d 网关所在网段2 -j RETURN
|
||||
iptables -t mangle -A XRAY -d Gateway_Subnet_1 -j RETURN
|
||||
iptables -t mangle -A XRAY -d Gateway_Subnet_2 -j RETURN
|
||||
...
|
||||
iptables -t mangle -A XRAY -d 224.0.0.0/3 -j RETURN
|
||||
iptables -t mangle -A XRAY -p tcp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A XRAY -p udp -j TPROXY --on-port 12345 --tproxy-mark 1
|
||||
iptables -t mangle -A PREROUTING -j XRAY
|
||||
|
||||
#代理网关本机
|
||||
# Proxy the gateway itself
|
||||
iptables -t mangle -N XRAY_MASK
|
||||
iptables -t mangle -A XRAY_MASK -d 网关所在网段1 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d 网关所在网段2 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d Gateway_Subnet_1 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d Gateway_Subnet_2 -j RETURN
|
||||
...
|
||||
iptables -t mangle -A XRAY_MASK -d 224.0.0.0/3 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d VPS公网ip/32 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -d VPS_Public_IP/32 -j RETURN
|
||||
iptables -t mangle -A XRAY_MASK -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -p tcp -j XRAY_MASK
|
||||
iptables -t mangle -A OUTPUT -p udp -j XRAY_MASK
|
||||
```
|
||||
|
||||
但是这么配置有个缺点,如果使用 CDN 或者 VPS 很多的话,就不好写规则了。
|
||||
However, this configuration has a downside: if you use CDNs or many VPSs, writing rules becomes difficult.
|
||||
|
||||
2. 通过 mark 规避
|
||||
1. Bypass via fwmark
|
||||
|
||||
三个白话文教程都是使用这种方法规避,自行参考,这里不再赘述。
|
||||
The three "Plain Language" tutorials all use this method to avoid loops. Please refer to them; I won't repeat it here.
|
||||
|
||||
3. 通过 gid 规避(推荐)
|
||||
1. Bypass via GID (Recommended)
|
||||
|
||||
参考 **[[透明代理]通过 gid 规避 Xray 流量](../iptables_gid.md)**
|
||||
Refer to **[[Transparent Proxy] Bypassing Xray Traffic via GID](../iptables_gid.md)**.
|
||||
|
||||
这样就完成了第三阶段的代理,也就是平时说的全局代理。但是记得把网关的 DNS 服务器设置为国外的 DNS 服务器,否则可能依然返回被污染的结果。
|
||||
This completes Stage 3 proxying, which is what we call Global Proxy. However, remember to set the gateway's DNS server to a foreign DNS server; otherwise, it may still return polluted results.
|
||||
|
||||
### 第四阶段
|
||||
### Stage 4
|
||||
|
||||
其实,并不是所有人都需要实现第四阶段。全局代理对于大部分情况已经适用。
|
||||
In fact, not everyone needs to implement Stage 4. Global proxy is suitable for most situations.
|
||||
|
||||
特别是对于旁路由而言。需要代理时,将网关调成旁路由的 IP,不需要代理时,将网关换回主路由 IP。
|
||||
Especially for "Side Routers" (Gateway Servers). When proxying is needed, set the device gateway to the Side Router's IP; when not needed, set the gateway back to the Main Router's IP.
|
||||
|
||||
至于第四阶段的具体实现,那三篇白话文教程讲的都是。在理解了上面的内容后,再去看那三篇白话文教程,就比较容易理解了。
|
||||
As for the specific implementation of Stage 4, those three "Plain Language" tutorials cover it. After understanding the content above, reading those tutorials should be much easier.
|
||||
|
||||
### 代理 ipv6
|
||||
### Proxying IPv6
|
||||
|
||||
上面的规则只对 ipv4 生效,如果还想要代理 ipv6 请求,则使用 ip6tables 命令,用法与 iptables 基本相同。参考 **[[透明代理]通过 gid 规避 Xray 流量#4-设置 iptables 规则](../iptables_gid#4-设置iptables规则.md)**
|
||||
The rules above only apply to IPv4. If you also want to proxy IPv6 requests, use the `ip6tables` command. The usage is basically the same as `iptables`. Refer to **[[Transparent Proxy] Bypassing Xray Traffic via GID#4-Set iptables rules](../iptables_gid#4-设置iptables规则.md)**.
|
||||
|
||||
# iptables 透明代理的其它注意事项
|
||||
# Other Notes on iptables Transparent Proxy
|
||||
|
||||
1. 如果作为代理的网关作为主路由,要在`PREROUTING链`规则中加一条`iptables -t mangle -A XRAY ! -s 网关LAN_IP地址段 -j RETURN`,即在第一阶段使用、第二阶段被删除的指令。如果不写,WAN 口中同网段的其它人可以将网关填写成你的 WAN_IP,从而蹭你的透明代理用,还可能带来一定的危险性。
|
||||
1. If the gateway acting as the proxy is the **Main Router**, you must add `iptables -t mangle -A XRAY ! -s Gateway_LAN_IP_Range -j RETURN` to the `PREROUTING Chain` rules. This is the command used in Stage 1 but removed in Stage 2. If you don't write this, other people in the same subnet on the WAN port can set their gateway to your WAN_IP, thereby leeching off your transparent proxy, which may also pose certain dangers.
|
||||
|
||||
2. **[新 V2Ray 白话文指南-透明代理(TPROXY)#设置网关](https://guide.v2fly.org/app/tproxy.html#设置网关)** 中的第三条说:`手动配置 PC 的网络,将默认网关指向树莓派的地址即 192.168.1.22。此时 PC 应当能正常上网(由于还没设置代理,“正常”是指可以上国内的网站)`。实际上,Ubuntu、CentOS、debian 等系统就算开启了 IP 转发,PC 也不能正常上网,这是正常的。事实上只有 OpenWRT 能做到文中所描述的那样,据 **[@BioniCosmos](https://github.com/BioniCosmos)** 点拨,这是由于一般的 Linux 系统没有 Masquery 规则。
|
||||
2. **[New V2Ray Plain Guide - Transparent Proxy (TPROXY) #Set Gateway](https://guide.v2fly.org/app/tproxy.html#设置网关)**, item 3 states: `Manually configure the PC's network, pointing the default gateway to the Raspberry Pi's address, i.e., 192.168.1.22. At this time, the PC should be able to access the Internet normally (since no proxy is set yet, "normal" means accessing domestic websites).` In reality, on systems like Ubuntu, CentOS, Debian, etc., even if IP Forwarding is enabled, the PC cannot access the Internet normally. This is expected. Only OpenWrt can achieve what is described in the article. As pointed out by **[@BioniCosmos](https://github.com/BioniCosmos)**, this is because general Linux systems do not have Masquerade rules.
|
||||
|
||||
3. **[too many open files 问题](https://guide.v2fly.org/app/tproxy.html#解决-too-many-open-files-问题)** ,解决方法见 **[[透明代理]通过 gid 规避 Xray 流量-配置最大文件大开数&运行 Xray 客户端](../iptables_gid#3-配置最大文件大开数运行xray客户端)**
|
||||
3. **[too many open files issue](https://guide.v2fly.org/app/tproxy.html#解决-too-many-open-files-问题)**. For the solution, see **[[Transparent Proxy] Bypassing Xray Traffic via GID - Config Max Open Files & Run Xray Client](../iptables_gid#3-配置最大文件大开数运行xray客户端)**.
|
||||
|
||||
4. 关于开启 ip_forward,待补充...
|
||||
4. Avoid double TPROXY for existing connections. To be added...
|
||||
|
||||
5. 避免已有连接的包二次通过 TPROXY ,待补充...
|
||||
|
||||
6. 主路由、单臂路由与旁路由,待补充...
|
||||
5. Main Router vs. Single-Arm Router vs. Side Router. To be added...
|
||||
|
||||
@@ -1,60 +1,153 @@
|
||||
---
|
||||
title: Enhancing Proxy Security with Cloudflare Warp
|
||||
title: Enhancing Proxy Security via Cloudflare Warp
|
||||
---
|
||||
|
||||
# Enhancing Proxy Security with Cloudflare Warp
|
||||
# Enhancing Proxy Security via Cloudflare Warp
|
||||
|
||||
Xray (1.6.5+) has added outbound WireGuard support. Although the added code and dependencies will increase the core size, we believe that this is a necessary new feature for three reasons:
|
||||
Xray (1.6.5+) has added a WireGuard outbound. Although the additional code and dependencies increase the core size, we believe this is a highly necessary new feature for three reasons:
|
||||
|
||||
1. Through recent discussions and [experiments](https://github.com/net4people/bbs/issues/129#issuecomment-1308102504), we know that proxying the traffic back to China is not safe. One way to deal with this is to route the back-to-China traffic to a black hole, but the downside is that due to the delay in geosite and geoip updates or the lack of knowledge on how to properly split the traffic on the client side, the traffic ends up going to the black hole, affecting the user experience. In this case, we only need to import the back-to-China traffic into Cloudflare Warp, which can achieve the same level of security without affecting the user experience.
|
||||
2. As we all know, most airports will log the domain names visited by users, and some airports will even audit and block some user traffic. One way to protect user privacy is to use chain proxies on the client side. The WireGuard lightweight VPN protocol used by Warp adds an extra layer of encryption within the proxy layer. For airports, the target of all user traffic is Warp, thereby maximizing privacy protection.
|
||||
3. It is easy to use, and only one core is needed to complete the split, Wireguard Tun, and chain proxy settings.
|
||||
1. Through recent discussions and [experiments](https://github.com/net4people/bbs/issues/129#issuecomment-1308102504), we know that routing traffic back to China via a proxy is insecure. One countermeasure is to route return traffic to a blackhole. The downside is that if `geosite` and `geoip` rules are not updated in time, or if beginners don't know how to configure routing properly on the client side, legitimate traffic enters the blackhole, affecting the user experience.
|
||||
By routing return traffic (traffic destined for China) to Cloudflare Warp instead, we can achieve the same level of security without impacting the user experience.
|
||||
2. It is well known that most proxy providers ("Airports") log user domain access history, and some even audit and block certain user traffic. One way to protect user privacy is to use a chain proxy on the client side.
|
||||
The WireGuard lightweight VPN protocol used by Warp adds a layer of encryption within the proxy layer. For the proxy provider, the destination of all user traffic appears to be Warp, thereby maximizing privacy protection.
|
||||
3. Ease of use. A single core can handle routing, WireGuard Tun, and chain proxy settings.
|
||||
|
||||
## Applying for a Warp Account
|
||||
|
||||
1. Thank you Cloudflare for promoting a free internet. Now you can use the Warp service for free, and the nearest server will be automatically selected based on the exit.
|
||||
2. Use a VPS and download [wgcf](https://github.com/ViRb3/wgcf/releases).
|
||||
3. Run `wgcf register` to generate `wgcf-account.toml`.
|
||||
4. Run `wgcf generate` to generate `wgcf-profile.conf`. Copy the following content:
|
||||
### Thanks to Cloudflare for promoting a free internet. You can now use the Warp service for free, and it will automatically select the nearest server when connecting
|
||||
|
||||
```
|
||||
#### Method 1
|
||||
|
||||
1. Use a VPS to download [wgcf](https://github.com/ViRb3/wgcf/releases).
|
||||
2. Run `wgcf register` to generate `wgcf-account.toml`.
|
||||
3. Run `wgcf generate` to generate `wgcf-profile.conf`. Copy the content as follows:
|
||||
|
||||
```ini
|
||||
[Interface]
|
||||
PrivateKey = my private key
|
||||
PrivateKey = My_Private_Key
|
||||
Address = 172.16.0.2/32
|
||||
Address = 2606:4700:110:8949:fed8:2642:a640:c8e1/128
|
||||
DNS = 1.1.1.1
|
||||
MTU = 1280
|
||||
[Peer]
|
||||
PublicKey = Warp public key
|
||||
PublicKey = Warp_Public_Key
|
||||
AllowedIPs = 0.0.0.0/0
|
||||
AllowedIPs = ::/0
|
||||
Endpoint = engage.cloudflareclient.com:2408
|
||||
```
|
||||
|
||||
## Diverting inbound traffic to warp on the server side
|
||||
#### Method 2
|
||||
|
||||
Add a new WireGuard outbound in the existing ones.
|
||||
1. Use [warp-reg.sh](https://github.com/chise0713/warp-reg.sh), run:
|
||||
|
||||
```
|
||||
bash -c "$(curl -L warp-reg.vercel.app)"
|
||||
```
|
||||
|
||||
- Output:
|
||||
|
||||
```json
|
||||
{
|
||||
"endpoint": {
|
||||
"v4": "162.159.192.7",
|
||||
"v6": "[2606:4700:d0::a29f:c007]"
|
||||
},
|
||||
"reserved_dec": [35, 74, 190],
|
||||
"reserved_hex": "0x234abe",
|
||||
"reserved_str": "I0q+",
|
||||
"private_key": "yL0kApRiZW4VFfNkKAQ/nYxnMFT3AH0dfVkj1GAlr1k=",
|
||||
"public_key": "bmXOC+F1FxEMF9dyiK2H5/1SUtzH0JuVo51h2wPfgyo=",
|
||||
"v4": "172.16.0.2",
|
||||
"v6": "2606:4700:110:81f3:2a5b:3cad:9d4:9ea6"
|
||||
}
|
||||
```
|
||||
|
||||
1. Copy the output content.
|
||||
|
||||
#### Method 3
|
||||
|
||||
1. Use [wgcf-cli](https://github.com/ArchiveNetwork/wgcf-cli). Run the following to install:
|
||||
|
||||
```
|
||||
bash -c "$(curl -L wgcf-cli.vercel.app)"
|
||||
```
|
||||
|
||||
1. Run `wgcf-cli register` to register. Output:
|
||||
|
||||
```json
|
||||
❯ wgcf-cli register
|
||||
{
|
||||
"endpoint": {
|
||||
"v4": "162.159.192.7:0",
|
||||
"v6": "[2606:4700:d0::a29f:c007]:0"
|
||||
},
|
||||
"reserved_str": "6nT5",
|
||||
"reserved_hex": "0xea74f9",
|
||||
"reserved_dec": [
|
||||
234,
|
||||
116,
|
||||
249
|
||||
],
|
||||
"private_key": "WIAKvgUlq5fBazhttCvjhEGpu8MmGHcb1H0iHSGlU0Q=",
|
||||
"public_key": "bmXOC+F1FxEMF9dyiK2H5/1SUtzH0JuVo51h2wPfgyo=",
|
||||
"addresses": {
|
||||
"v4": "172.16.0.2",
|
||||
"v6": "2606:4700:110:8d9c:3c4e:2190:59d1:2d3c"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
- The complete file will be saved to `wgcf.json` in the working directory.
|
||||
|
||||
1. Run `wgcf-cli generate --xray` to generate a WireGuard outbound config. It will save the content to `wgcf.xray.json`.
|
||||
|
||||
- Example file:
|
||||
|
||||
```json
|
||||
{
|
||||
"protocol": "wireguard",
|
||||
"settings": {
|
||||
"secretKey": "My private key",
|
||||
"secretKey": "6CRVRLgFwGajnikoVOPTDNZnDhx3EydhPsMgpxHfBCY=",
|
||||
"address": ["172.16.0.2/32", "2606:4700:110:857a:6a95:fe27:1870:2a9d/128"],
|
||||
"peers": [
|
||||
{
|
||||
"publicKey": "bmXOC+F1FxEMF9dyiK2H5/1SUtzH0JuVo51h2wPfgyo=",
|
||||
"allowedIPs": ["0.0.0.0/0", "::/0"],
|
||||
"endpoint": "162.159.192.1:2408"
|
||||
}
|
||||
],
|
||||
"reserved": [240, 25, 146],
|
||||
"mtu": 1280
|
||||
},
|
||||
"tag": "wireguard"
|
||||
}
|
||||
```
|
||||
|
||||
## Routing Traffic Back to China via Warp on the Server Side
|
||||
|
||||
Add a new WireGuard outbound to your existing outbounds:
|
||||
|
||||
```json
|
||||
{
|
||||
"protocol": "wireguard",
|
||||
"settings": {
|
||||
"secretKey": "My_Private_Key",
|
||||
"address": ["172.16.0.2/32", "2606:4700:110:8949:fed8:2642:a640:c8e1/128"],
|
||||
"peers": [
|
||||
{
|
||||
"publicKey": "Warp public key",
|
||||
"publicKey": "Warp_Public_Key",
|
||||
"endpoint": "engage.cloudflareclient.com:2408"
|
||||
}
|
||||
]
|
||||
],
|
||||
"reserved": [0, 0, 0] // If you have it, paste 'reserved' here
|
||||
},
|
||||
"tag": "wireguard-1"
|
||||
}
|
||||
```
|
||||
|
||||
Recommended routing strategy is `IPIfNonMatch`.
|
||||
Recommended routing strategy: `IPIfNonMatch`.
|
||||
|
||||
Add the following to the existing router:
|
||||
Add the following to your existing routing rules:
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -79,13 +172,14 @@ Add the following to the existing router:
|
||||
{
|
||||
"protocol":"wireguard",
|
||||
"settings":{
|
||||
"secretKey":"My private key",
|
||||
"secretKey":"My_Private_Key",
|
||||
"peers":[
|
||||
{
|
||||
"publicKey":"Warp public key",
|
||||
"publicKey":"Warp_Public_Key",
|
||||
"endpoint":"engage.cloudflareclient.com:2408"
|
||||
}
|
||||
]
|
||||
],
|
||||
"reserved":[0, 0, 0] // If you have it, paste 'reserved' here
|
||||
},
|
||||
"streamSettings":{
|
||||
"sockopt":{
|
||||
@@ -100,11 +194,11 @@ Add the following to the existing router:
|
||||
"settings":{
|
||||
"vnext":[
|
||||
{
|
||||
"address":"My IP",
|
||||
"port":My port,
|
||||
"address":"My_Server_IP",
|
||||
"port":My_Port,
|
||||
"users":[
|
||||
{
|
||||
"id":"My UUID",
|
||||
"id":"My_UUID",
|
||||
"security":"auto"
|
||||
}
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user