mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-09-22 22:38:05 +03:00
Refine tproxy article layout
This commit is contained in:
@@ -252,14 +252,14 @@ export const sidebar: DefaultTheme.Config["sidebar"] = {
|
||||
text: "TProxy (IPv4 and IPv6)",
|
||||
link: "/en/document/level-2/tproxy_ipv4_and_ipv6.md"
|
||||
},
|
||||
{
|
||||
text: "Hide Fingerprint with Nginx/Haproxy TLS Tunnel",
|
||||
link: "/en/document/level-2/nginx_or_haproxy_tls_tunnel.md"
|
||||
},
|
||||
{
|
||||
text: "GID Transparent Proxy",
|
||||
link: "/en/document/level-2/iptables_gid.md"
|
||||
},
|
||||
{
|
||||
text: "Hide Fingerprint with Nginx/Haproxy TLS Tunnel",
|
||||
link: "/en/document/level-2/nginx_or_haproxy_tls_tunnel.md"
|
||||
},
|
||||
{
|
||||
text: "Outbound Traffic Redirection",
|
||||
link: "/en/document/level-2/redirect.md"
|
||||
|
||||
@@ -222,14 +222,14 @@ export const sidebar: DefaultTheme.Config["sidebar"] = {
|
||||
text: "TProxy 透明代理(ipv4 and ipv6)",
|
||||
link: "/document/level-2/tproxy_ipv4_and_ipv6.md"
|
||||
},
|
||||
{
|
||||
text: "Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹",
|
||||
link: "/document/level-2/nginx_or_haproxy_tls_tunnel.md"
|
||||
},
|
||||
{
|
||||
text: "GID 透明代理",
|
||||
link: "/document/level-2/iptables_gid.md"
|
||||
},
|
||||
{
|
||||
text: "Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹",
|
||||
link: "/document/level-2/nginx_or_haproxy_tls_tunnel.md"
|
||||
},
|
||||
{ text: "出站流量重定向", link: "/document/level-2/redirect.md" },
|
||||
{
|
||||
text: "通过 Cloudflare Warp 增强代理安全性",
|
||||
|
||||
@@ -279,14 +279,14 @@ export const sidebar: DefaultTheme.Config["sidebar"] = {
|
||||
text: "Прозрачный прокси TProxy (IPv4 и IPv6)",
|
||||
link: "/ru/document/level-2/tproxy_ipv4_and_ipv6.md"
|
||||
},
|
||||
{
|
||||
text: "Создание TLS-туннеля с Nginx или Haproxy для скрытия отпечатков",
|
||||
link: "/ru/document/level-2/nginx_or_haproxy_tls_tunnel.md"
|
||||
},
|
||||
{
|
||||
text: "Прозрачный прокси GID",
|
||||
link: "/ru/document/level-2/iptables_gid.md"
|
||||
},
|
||||
{
|
||||
text: "Создание TLS-туннеля с Nginx или Haproxy для скрытия отпечатков",
|
||||
link: "/ru/document/level-2/nginx_or_haproxy_tls_tunnel.md"
|
||||
},
|
||||
{
|
||||
text: "Перенаправление исходящего трафика",
|
||||
link: "/ru/document/level-2/redirect.md"
|
||||
|
||||
@@ -20,18 +20,18 @@
|
||||
|
||||
---
|
||||
|
||||
[Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
双端使用 Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹
|
||||
|
||||
---
|
||||
|
||||
[[透明代理]通过 gid 规避 Xray 流量](./iptables_gid.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@kirin](https://github.com/kirin10000)
|
||||
|
||||
在 iptables/nftables 实现的透明代理中,一种新的规避 Xray 流量的方式。
|
||||
|
||||
---
|
||||
|
||||
[Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
双端使用 Nginx 或 Haproxy 搭建 TLS 隧道隐藏指纹
|
||||
|
||||
---
|
||||
|
||||
[通过 Xray 将特定的流量指向特定出口,实现全局路由“分流”](./redirect.md) by <img src="https://avatars.githubusercontent.com/u/28607089?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Zzz3m](https://github.com/Zzz3m)
|
||||
|
||||
将 Xray 玩出花:基于 fwmark 、 sendThrough 或 sockopt.interface 方式实现“分流”。
|
||||
@@ -50,6 +50,6 @@ Xray v1.6.5 新增 WireGuard 出站的使用介绍。
|
||||
|
||||
---
|
||||
|
||||
[VLESS 反向代理](./vless_reverse.md)
|
||||
[VLESS 反向代理](./vless_reverse.md) by <img src="https://avatars.githubusercontent.com/u/197331664?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Meo597](https://github.com/Meo597)
|
||||
|
||||
VLESS 反向代理教程。
|
||||
|
||||
@@ -161,7 +161,7 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
|
||||
## 策略路由配置
|
||||
|
||||
```
|
||||
```sh
|
||||
sudo ip route add local default dev lo table 100 # 添加路由表 100
|
||||
sudo ip rule add fwmark 1 table 100 # 为路由表 100 设定规则
|
||||
```
|
||||
@@ -170,9 +170,13 @@ sudo ip rule add fwmark 1 table 100 # 为路由表 100 设定规则
|
||||
|
||||
::: warning 注意
|
||||
nftables 配置与 iptables 配置二选一,不可同时使用。
|
||||
|
||||
将所选配置写入文件,赋予可执行权限后,再使用 root 权限执行该文件即可。
|
||||
:::
|
||||
|
||||
```nftables
|
||||
::: code-group
|
||||
|
||||
```bash [nftables.conf]
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
@@ -210,12 +214,7 @@ table ip xray {
|
||||
}
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
|
||||
将上述配置写入一个文件(如 `nft.conf`),之后将该文件赋予可执行权限,最后使用 root 权限执行该文件即可(`# ./nft.conf`)。
|
||||
:::
|
||||
|
||||
```bash
|
||||
```bash [iptables.sh]
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 10.0.0.0/8 -j RETURN
|
||||
iptables -t mangle -A XRAY -d 100.64.0.0/10 -j RETURN
|
||||
@@ -250,13 +249,31 @@ iptables -t mangle -A XRAY_SELF -p udp -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -j XRAY_SELF
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
配置完成后,将局域网内其它设备的默认网关改为该设备 IP,就可以直接翻墙了。在其它主机和本机皆测试成功后,可进行下一步配置。
|
||||
|
||||
## 配置永久化与开机自启
|
||||
|
||||
首先将已经编辑好的 nftables 配置文件移动到 `/etc` 目录下,并重命名为 `nftables.conf`。然后编辑 `/lib/systemd/system/nftables.service`。
|
||||
根据前面 Netfilter 配置中的选择,这里应使用对应的持久化方式。
|
||||
|
||||
```ini
|
||||
- **如果使用 `nftables`**
|
||||
|
||||
先将已经编辑好的配置文件移动到 `/etc` 目录下,然后编辑 `/lib/systemd/system/nftables.service`
|
||||
|
||||
- **如果使用 `iptables`**
|
||||
|
||||
建议直接安装 `iptables-persistent`
|
||||
|
||||
安装过程中会提示你选择“是否保存配置”,如果已经将 `iptables` 配置写入系统,那么此时选择“是”即可;如果尚未写入也没有关系,安装完毕后将配置写入,然后执行 `netfilter-persistent save` 即可(需要 root 权限)
|
||||
|
||||
之后编辑 `/lib/systemd/system/netfilter-persistent.service`
|
||||
|
||||
最后 enable 所选服务即可。
|
||||
|
||||
::: code-group
|
||||
|
||||
```ini [nftables.service]
|
||||
[Unit]
|
||||
Description=nftables
|
||||
Documentation=man:nft(8) http://wiki.nftables.org
|
||||
@@ -279,15 +296,7 @@ ExecStop=/usr/sbin/nft flush ruleset ; /usr/sbin/ip route del local default dev
|
||||
WantedBy=sysinit.target
|
||||
```
|
||||
|
||||
最后 enable 即可。
|
||||
|
||||
关于 iptables 的永久化,建议直接安装 `iptables-persistent`。
|
||||
|
||||
安装过程中会提示你选择“是否保存配置”,如果已经将 iptables 配置写入系统,那么此时选择“是”即可;如果尚未写入也没有关系,安装完毕后将配置写入,然后执行 `netfilter-persistent save` 即可(需要 root 权限)。
|
||||
|
||||
之后编辑 `/lib/systemd/system/netfilter-persistent.service`。
|
||||
|
||||
```ini
|
||||
```ini [netfilter-persistent.service]
|
||||
[Unit]
|
||||
Description=netfilter persistent configuration
|
||||
DefaultDependencies=no
|
||||
@@ -306,3 +315,5 @@ ExecStop=/usr/sbin/netfilter-persistent stop ; /usr/sbin/ip route flush dev lo t
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
@@ -260,7 +260,7 @@
|
||||
|
||||
### 首先设置策略路由
|
||||
|
||||
```bash
|
||||
```sh
|
||||
# 设置策略路由 v4
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
@@ -287,7 +287,7 @@ ip -6 route add default via fd00:6868:6868::1 #写主路由 ipv6, 采用局域
|
||||
|
||||
如果是在路由器上指定了默认网关为旁路由(亦即下述“局域网设备上网设置方法二”),那么就需要设置上述 `# 直连从主路由发出` ,除了通过 iproute2 命令行方式设置,也可以通过 dhcpcd 或者 systemctl-network 设置静态 IP,这里以 dhcpcd 为例,编辑 `/etc/dhcpcd.conf` 文件,在最下方加入如下配置,具体 IP 根据你的实际情况修改,其中 `interface` 可以通过 `# ip link show` 查看要设定的网口或者无线设备。
|
||||
|
||||
```
|
||||
```ini
|
||||
interface enp0s25
|
||||
static ip_address=192.168.31.100/24
|
||||
static ip6_address=fd00:6868:6868::8888/64
|
||||
@@ -300,13 +300,13 @@ static domain_name_servers=192.168.31.1 fd00:6868:6868::1
|
||||
::: warning 注意
|
||||
|
||||
以下 nftables 配置与 iptables 配置二选一,不可同时使用。
|
||||
|
||||
将所选配置写入文件,赋予可执行权限后,再使用 root 权限执行该文件即可。
|
||||
:::
|
||||
|
||||
### 使用 iptables
|
||||
::: code-group
|
||||
|
||||
此处配置将 ipv4 与 ipv6 写在同一文件中。
|
||||
|
||||
```bash
|
||||
```bash [iptables.rules]
|
||||
# 代理局域网设备 v4
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 127.0.0.1/32 -j RETURN
|
||||
@@ -365,18 +365,7 @@ ip6tables -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
|
||||
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
|
||||
将上述配置写入一个文件(如 `iptables.rules`),之后将该文件赋予可执行权限`# chmod 700 ./iptables.rules`
|
||||
|
||||
最后使用 root 权限执行该文件即可:`# ./iptables.rules`或`# source iptables.rules`。
|
||||
:::
|
||||
|
||||
### 使用 nftables
|
||||
|
||||
此处合并 ipv4 与 ipv6
|
||||
|
||||
```
|
||||
```bash [nftables.rules]
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
@@ -415,11 +404,6 @@ table inet xray {
|
||||
|
||||
```
|
||||
|
||||
::: tip 使用方法
|
||||
|
||||
将上述配置写入一个文件(如 `nftables.rules`),之后将该文件赋予可执行权限`# chmod 700 ./nftables.rules`
|
||||
|
||||
最后使用 root 权限执行该文件即可:`# ./nftables.rules`或`# source nftables.rules`
|
||||
:::
|
||||
|
||||
其中,网关地址`192.168.0.0/16`, `fd00::/8`等可由`ip address | grep -w inet | awk '{print $2}'`以及`ip address | grep -w inet6 | awk '{print $2}'`[获得](https://xtls.github.io/document/level-2/iptables_gid.html#_4-%E8%AE%BE%E7%BD%AE-iptables-%E8%A7%84%E5%88%99)
|
||||
@@ -434,13 +418,19 @@ table inet xray {
|
||||
|
||||
首先确认已经运行过上述相应 Netfilter 命令,并且成功测试透明代理配置,以确保接下来输出正确的文件。
|
||||
|
||||
#### 若使用 iptables 配置
|
||||
- **如果使用 `iptables`**
|
||||
|
||||
1. 首先通过 `# iptables-save > /root/iptables.rulesv4` `# ip6tables-save > /root/iptables.rulesv6` 将 iptables 配置写入 `iptables.rulesv4` 和 `iptables.rulesv6` 文件中
|
||||
先通过 `# iptables-save > /root/iptables.rulesv4` `# ip6tables-save > /root/iptables.rulesv6` 将配置写入 `iptables.rulesv4` 和 `iptables.rulesv6`
|
||||
|
||||
2. 然后在 `/etc/systemd/system/` 目录下创建一个名为 `tproxyrules.service` 的文件,添加以下内容并保存
|
||||
- **如果使用 `nftables`**
|
||||
|
||||
```
|
||||
先通过 `# nft list ruleset > /root/nftables.rulesv46` 将配置写入 `nftables.rulesv46`
|
||||
|
||||
随后在 `/etc/systemd/system/` 目录下创建 `tproxyrules.service`,根据所选方案写入对应内容,最后执行 `systemctl enable tproxyrules`。
|
||||
|
||||
::: code-group
|
||||
|
||||
```ini [iptables tproxyrules.service]
|
||||
[Unit]
|
||||
Description=Tproxy rules
|
||||
|
||||
@@ -469,15 +459,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. 最后执行 `systemctl enable tproxyrules` 命令。
|
||||
|
||||
#### 如果使用 nftables 配置
|
||||
|
||||
1. 首先通过 `# nft list ruleset > /root/nftables.rulesv46` 将 nftables 配置写入 `nftables.rulesv46` 文件中
|
||||
|
||||
2. 在 `/etc/systemd/system/` 目录下创建一个名为 `tproxyrules.service` 的文件,然后添加以下内容并保存
|
||||
|
||||
```
|
||||
```ini [nftables tproxyrules.service]
|
||||
[Unit]
|
||||
Description=Tproxy rules
|
||||
|
||||
@@ -504,7 +486,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. 最后执行 `systemctl enable tproxyrules` 命令。
|
||||
:::
|
||||
|
||||
::: tip tproxyrules.service
|
||||
|
||||
|
||||
@@ -20,18 +20,18 @@ Configuration tutorial for Xray-based TProxy Transparent Proxy (IPv4 and IPv6).
|
||||
|
||||
---
|
||||
|
||||
[Using Nginx or HAProxy to Build TLS Tunnels to Hide Fingerprints](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
Using Nginx or HAProxy on both ends to build a TLS tunnel for fingerprint hiding.
|
||||
|
||||
---
|
||||
|
||||
[[Transparent Proxy] Bypassing Xray Traffic via GID](./iptables_gid.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@kirin](https://github.com/kirin10000)
|
||||
|
||||
A new method to bypass Xray traffic in transparent proxies implemented via iptables/nftables.
|
||||
|
||||
---
|
||||
|
||||
[Using Nginx or HAProxy to Build TLS Tunnels to Hide Fingerprints](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
Using Nginx or HAProxy on both ends to build a TLS tunnel for fingerprint hiding.
|
||||
|
||||
---
|
||||
|
||||
[Directing Specific Traffic to Specific Exits via Xray for Global Routing "Traffic Splitting"](./redirect.md) by <img src="https://avatars.githubusercontent.com/u/28607089?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Zzz3m](https://github.com/Zzz3m)
|
||||
|
||||
Getting creative with Xray: Achieving "traffic splitting" based on fwmark, sendThrough, or sockopt.interface.
|
||||
@@ -50,6 +50,6 @@ Traffic statistics and scripts adapted for Xray.
|
||||
|
||||
---
|
||||
|
||||
[VLESS Reverse Proxy](./vless_reverse.md)
|
||||
[VLESS Reverse Proxy](./vless_reverse.md) by <img src="https://avatars.githubusercontent.com/u/197331664?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Meo597](https://github.com/Meo597)
|
||||
|
||||
VLESS reverse proxy tutorial.
|
||||
|
||||
@@ -161,7 +161,7 @@ This configuration hijacks all traffic sent to port 53 to solve DNS pollution is
|
||||
|
||||
## Policy Routing Configuration
|
||||
|
||||
```bash
|
||||
```sh
|
||||
sudo ip route add local default dev lo table 100 # Add routing table 100
|
||||
sudo ip rule add fwmark 1 table 100 # Set rules for routing table 100
|
||||
```
|
||||
@@ -170,9 +170,13 @@ sudo ip rule add fwmark 1 table 100 # Set rules for routing table 100
|
||||
|
||||
::: warning Note
|
||||
Choose either **nftables** or **iptables** configuration. Do not use both simultaneously.
|
||||
|
||||
Write the selected configuration to a file, make it executable, and then run that file as root.
|
||||
:::
|
||||
|
||||
```nftables
|
||||
::: code-group
|
||||
|
||||
```bash [nftables.conf]
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
@@ -210,12 +214,7 @@ table ip xray {
|
||||
}
|
||||
```
|
||||
|
||||
::: tip Usage
|
||||
|
||||
Write the above configuration to a file (e.g., `nft.conf`), then give the file executable permissions, and finally execute the file with root privileges (`# ./nft.conf`).
|
||||
:::
|
||||
|
||||
```bash
|
||||
```bash [iptables.sh]
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 10.0.0.0/8 -j RETURN
|
||||
iptables -t mangle -A XRAY -d 100.64.0.0/10 -j RETURN
|
||||
@@ -250,13 +249,31 @@ iptables -t mangle -A XRAY_SELF -p udp -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -j XRAY_SELF
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
After the configuration is complete, change the default gateway of other devices in the LAN to the IP of this device to bypass the firewall directly. After successfully testing on both other hosts and the local machine, you can proceed to the next step.
|
||||
|
||||
## Persistence and Auto-start
|
||||
|
||||
First, move the edited `nftables` configuration file to the `/etc` directory and rename it to `nftables.conf`. Then edit `/lib/systemd/system/nftables.service`.
|
||||
Depending on which Netfilter option you selected above, use the corresponding persistence method here.
|
||||
|
||||
```ini
|
||||
- **If using `nftables`**
|
||||
|
||||
Move the edited configuration file to the `/etc` directory, then edit `/lib/systemd/system/nftables.service`.
|
||||
|
||||
- **If using `iptables`**
|
||||
|
||||
It is recommended to install `iptables-persistent` directly.
|
||||
|
||||
During the installation process, you will be prompted whether to save the current configuration. If the `iptables` rules have already been applied to the system, select "Yes". If not, that is fine too; after installation, apply the configuration and then execute `netfilter-persistent save` (root privileges required).
|
||||
|
||||
After that, edit `/lib/systemd/system/netfilter-persistent.service`.
|
||||
|
||||
Finally, enable the selected service.
|
||||
|
||||
::: code-group
|
||||
|
||||
```ini [nftables.service]
|
||||
[Unit]
|
||||
Description=nftables
|
||||
Documentation=man:nft(8) http://wiki.nftables.org
|
||||
@@ -279,15 +296,7 @@ ExecStop=/usr/sbin/nft flush ruleset ; /usr/sbin/ip route del local default dev
|
||||
WantedBy=sysinit.target
|
||||
```
|
||||
|
||||
Finally, enable it.
|
||||
|
||||
For persistence with `iptables`, it is recommended to install `iptables-persistent` directly.
|
||||
|
||||
During the installation process, you will be prompted to "Save current IPv4 rules?". If you have already applied the iptables configuration to the system, select "Yes". If not, it doesn't matter; after installation, apply the configuration and then execute `netfilter-persistent save` (root privileges required).
|
||||
|
||||
After that, edit `/lib/systemd/system/netfilter-persistent.service`.
|
||||
|
||||
```ini
|
||||
```ini [netfilter-persistent.service]
|
||||
[Unit]
|
||||
Description=netfilter persistent configuration
|
||||
DefaultDependencies=no
|
||||
@@ -306,3 +315,5 @@ ExecStop=/usr/sbin/netfilter-persistent stop ; /usr/sbin/ip route flush dev lo t
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
@@ -262,7 +262,7 @@ If the Xray program is not installed on the side router, you can manually downlo
|
||||
|
||||
### First, Set Policy Routing
|
||||
|
||||
```bash
|
||||
```sh
|
||||
# Set policy routing v4
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
@@ -291,7 +291,7 @@ If you use **Method 2** below, the `default via` would be the side router's IP.
|
||||
|
||||
If you specified the default gateway as the side router on the main router (i.e., "LAN Device Internet Setup Method 2" below), then you need to set the above `# Direct connection goes out from the main router`. besides setting it via `iproute2` command line, you can also set a static IP via `dhcpcd` or `systemctl-network`. Here we take `dhcpcd` as an example. Edit the `/etc/dhcpcd.conf` file and add the following configuration at the bottom. Modify the specific IP according to your actual situation. The `interface` can be viewed via `# ip link show` to see the network port or wireless device to be configured.
|
||||
|
||||
```
|
||||
```ini
|
||||
interface enp0s25
|
||||
static ip_address=192.168.31.100/24
|
||||
static ip6_address=fd00:6868:6868::8888/64
|
||||
@@ -304,13 +304,13 @@ By setting the IP and gateway via static IP this way, there is no need to set `#
|
||||
::: warning Note
|
||||
|
||||
Choose **either** the following nftables configuration **or** iptables configuration. Do not use both simultaneously.
|
||||
|
||||
Write the selected configuration to a file, make it executable, and then run that file as root.
|
||||
:::
|
||||
|
||||
### Using iptables
|
||||
::: code-group
|
||||
|
||||
This configuration writes IPv4 and IPv6 into the same file.
|
||||
|
||||
```bash
|
||||
```bash [iptables.rules]
|
||||
# Proxy LAN devices v4
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 127.0.0.1/32 -j RETURN
|
||||
@@ -369,18 +369,7 @@ ip6tables -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
|
||||
|
||||
```
|
||||
|
||||
::: tip Usage
|
||||
|
||||
Write the above configuration into a file (e.g., `iptables.rules`), then grant executable permission to the file: `# chmod 700 ./iptables.rules`.
|
||||
|
||||
Finally, execute the file with root privileges: `# ./iptables.rules` or `# source iptables.rules`.
|
||||
:::
|
||||
|
||||
### Using nftables
|
||||
|
||||
This merges IPv4 and IPv6.
|
||||
|
||||
```
|
||||
```bash [nftables.rules]
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
@@ -419,11 +408,6 @@ table inet xray {
|
||||
|
||||
```
|
||||
|
||||
::: tip Usage
|
||||
|
||||
Write the above configuration into a file (e.g., `nftables.rules`), then grant executable permission to the file: `# chmod 700 ./nftables.rules`.
|
||||
|
||||
Finally, execute the file with root privileges: `# ./nftables.rules` or `# source nftables.rules`.
|
||||
:::
|
||||
|
||||
Where gateway addresses `192.168.0.0/16`, `fd00::/8`, etc., can be [obtained](https://xtls.github.io/document/level-2/iptables_gid.html#_4-%E8%AE%BE%E7%BD%AE-iptables-%E8%A7%84%E5%88%99) by `ip address | grep -w inet | awk '{print $2}'` and `ip address | grep -w inet6 | awk '{print $2}'`.
|
||||
@@ -438,13 +422,19 @@ If the prefixes `192.168`, `fd00:` are the same, you don't need to change them.
|
||||
|
||||
First, confirm that you have run the corresponding Netfilter commands above and successfully tested the transparent proxy configuration to ensure the output files are correct.
|
||||
|
||||
#### If using iptables configuration
|
||||
- **If using `iptables`**
|
||||
|
||||
1. First, save the iptables configuration to `iptables.rulesv4` and `iptables.rulesv6` files: `# iptables-save > /root/iptables.rulesv4` and `# ip6tables-save > /root/iptables.rulesv6`.
|
||||
First, save the configuration to `iptables.rulesv4` and `iptables.rulesv6` with `# iptables-save > /root/iptables.rulesv4` and `# ip6tables-save > /root/iptables.rulesv6`.
|
||||
|
||||
2. Then create a file named `tproxyrules.service` in the `/etc/systemd/system/` directory, add the following content, and save it:
|
||||
- **If using `nftables`**
|
||||
|
||||
```
|
||||
First, save the configuration to `nftables.rulesv46` with `# nft list ruleset > /root/nftables.rulesv46`.
|
||||
|
||||
Then create `tproxyrules.service` under `/etc/systemd/system/`, write the corresponding content for the chosen option, and finally run `systemctl enable tproxyrules`.
|
||||
|
||||
::: code-group
|
||||
|
||||
```ini [iptables tproxyrules.service]
|
||||
[Unit]
|
||||
Description=Tproxy rules
|
||||
|
||||
@@ -473,15 +463,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
1. Finally, execute the command `systemctl enable tproxyrules`.
|
||||
|
||||
#### If using nftables configuration
|
||||
|
||||
1. First, write the nftables configuration to the `nftables.rulesv46` file: `# nft list ruleset > /root/nftables.rulesv46`.
|
||||
|
||||
2. Create a file named `tproxyrules.service` in the `/etc/systemd/system/` directory, then add the following content and save it:
|
||||
|
||||
```
|
||||
```ini [nftables tproxyrules.service]
|
||||
[Unit]
|
||||
Description=Tproxy rules
|
||||
|
||||
@@ -508,7 +490,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
1. Finally, execute the command `systemctl enable tproxyrules`.
|
||||
:::
|
||||
|
||||
::: tip tproxyrules.service
|
||||
|
||||
|
||||
@@ -20,18 +20,18 @@
|
||||
|
||||
---
|
||||
|
||||
[Создание TLS-туннеля с помощью Nginx или Haproxy для скрытия отпечатков](./nginx_or_haproxy_tls_tunnel.md) от <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
Создание TLS-туннеля с помощью Nginx или Haproxy на стороне клиента и сервера для скрытия отпечатков.
|
||||
|
||||
---
|
||||
|
||||
[[Прозрачное проксирование] Исключение трафика Xray с помощью GID](./iptables_gid.md) от <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@kirin](https://github.com/kirin10000)
|
||||
|
||||
Новый способ исключения трафика Xray при реализации прозрачного проксирования с помощью iptables/nftables.
|
||||
|
||||
---
|
||||
|
||||
[Создание TLS-туннеля с помощью Nginx или Haproxy для скрытия отпечатков](./nginx_or_haproxy_tls_tunnel.md) от <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
|
||||
|
||||
Создание TLS-туннеля с помощью Nginx или Haproxy на стороне клиента и сервера для скрытия отпечатков.
|
||||
|
||||
---
|
||||
|
||||
[Направление определенного трафика через определенный выходной узел с помощью Xray для реализации "разделения" глобальной маршрутизации](./redirect.md) от <img src="https://avatars.githubusercontent.com/u/28607089?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Zzz3m](https://github.com/Zzz3m)
|
||||
|
||||
Использование Xray по максимуму: реализация "разделения" трафика на основе fwmark, sendThrough или sockopt.interface.
|
||||
@@ -50,6 +50,6 @@
|
||||
|
||||
---
|
||||
|
||||
[Обратный прокси VLESS](./vless_reverse.md)
|
||||
[Обратный прокси VLESS](./vless_reverse.md) by <img src="https://avatars.githubusercontent.com/u/197331664?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Meo597](https://github.com/Meo597)
|
||||
|
||||
Руководство по обратному проксированию VLESS.
|
||||
|
||||
@@ -162,7 +162,7 @@ sudo curl -oL /usr/local/share/xray/geosite.dat https://github.com/Loyalsoldier/
|
||||
|
||||
## Настройка маршрутизации по политике
|
||||
|
||||
```
|
||||
```sh
|
||||
sudo ip route add local default dev lo table 100 # Добавить таблицу маршрутизации 100
|
||||
sudo ip rule add fwmark 1 table 100 # Добавить правило для таблицы маршрутизации 100
|
||||
```
|
||||
@@ -171,9 +171,13 @@ sudo ip rule add fwmark 1 table 100 # Добавить правило для т
|
||||
|
||||
::: warning Внимание
|
||||
Выберите одну из следующих конфигураций: nftables или iptables. Не используйте обе одновременно.
|
||||
|
||||
Запишите выбранную конфигурацию в файл, выдайте ему права на выполнение и затем запустите этот файл от имени root.
|
||||
:::
|
||||
|
||||
```nftables
|
||||
::: code-group
|
||||
|
||||
```bash [nftables.conf]
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
@@ -211,14 +215,7 @@ table ip xray {
|
||||
}
|
||||
```
|
||||
|
||||
::: tip Использование
|
||||
|
||||
Запишите приведенную выше конфигурацию в файл (например, `nft.conf`), затем предоставьте файлу права на выполнение и выполните его от имени пользователя root ( `# ./nft.conf` ).
|
||||
:::
|
||||
|
||||
>
|
||||
|
||||
```bash
|
||||
```bash [iptables.sh]
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 10.0.0.0/8 -j RETURN
|
||||
iptables -t mangle -A XRAY -d 100.64.0.0/10 -j RETURN
|
||||
@@ -253,14 +250,31 @@ iptables -t mangle -A XRAY_SELF -p udp -j MARK --set-mark 1
|
||||
iptables -t mangle -A OUTPUT -j XRAY_SELF
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
После завершения настройки измените шлюз по умолчанию на других устройствах в локальной сети на IP-адрес этого устройства, и они смогут использовать VPN. После того, как вы проверите, что все работает правильно на других хостах и на самом устройстве, перейдите к следующему шагу.
|
||||
|
||||
## Настройка автозагрузки и сохранения конфигурации
|
||||
|
||||
Сначала переместите отредактированный файл конфигурации nftables в каталог `/etc` и переименуйте его в `nftables.conf`.
|
||||
Затем отредактируйте файл `/lib/systemd/system/nftables.service`.
|
||||
В зависимости от того, какой вариант Netfilter вы выбрали выше, используйте соответствующий способ сохранения конфигурации.
|
||||
|
||||
```ini
|
||||
- **Если используется `nftables`**
|
||||
|
||||
Сначала переместите подготовленный файл конфигурации в каталог `/etc`, затем отредактируйте `/lib/systemd/system/nftables.service`.
|
||||
|
||||
- **Если используется `iptables`**
|
||||
|
||||
Рекомендуется сразу установить `iptables-persistent`.
|
||||
|
||||
Во время установки система спросит, нужно ли сохранить текущую конфигурацию. Если правила `iptables` уже применены, выберите «Да». Если еще нет, это не проблема: после установки примените конфигурацию и выполните `netfilter-persistent save` (требуются права root).
|
||||
|
||||
После этого отредактируйте `/lib/systemd/system/netfilter-persistent.service`.
|
||||
|
||||
В конце включите выбранный сервис.
|
||||
|
||||
::: code-group
|
||||
|
||||
```ini [nftables.service]
|
||||
[Unit]
|
||||
Description=nftables
|
||||
Documentation=man:nft(8) http://wiki.nftables.org
|
||||
@@ -283,17 +297,7 @@ ExecStop=/usr/sbin/nft flush ruleset ; /usr/sbin/ip route del local default dev
|
||||
WantedBy=sysinit.target
|
||||
```
|
||||
|
||||
Наконец, выполните команду `systemctl enable nftables`.
|
||||
|
||||
Для сохранения конфигурации iptables рекомендуется установить пакет `iptables-persistent`.
|
||||
|
||||
Во время установки вам будет предложено сохранить конфигурацию.
|
||||
Если вы уже записали конфигурацию iptables в систему, выберите "Да".
|
||||
Если вы еще не записали конфигурацию, это не проблема. После установки запишите конфигурацию и выполните команду `netfilter-persistent save` (требуются права root).
|
||||
|
||||
Затем отредактируйте файл `/lib/systemd/system/netfilter-persistent.service`.
|
||||
|
||||
```ini
|
||||
```ini [netfilter-persistent.service]
|
||||
[Unit]
|
||||
Description=netfilter persistent configuration
|
||||
DefaultDependencies=no
|
||||
@@ -312,3 +316,5 @@ ExecStop=/usr/sbin/netfilter-persistent stop ; /usr/sbin/ip route flush dev lo t
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
@@ -266,7 +266,7 @@
|
||||
|
||||
### Настройка маршрутизации по политике
|
||||
|
||||
```bash
|
||||
```sh
|
||||
# Настройка маршрутизации по политике для IPv4
|
||||
ip rule add fwmark 1 table 100
|
||||
ip route add local 0.0.0.0/0 dev lo table 100
|
||||
@@ -299,7 +299,7 @@ ip -6 route add default via fd00:6868:6868::1 # Укажите IPv6-адрес
|
||||
В качестве примера рассмотрим dhcpcd. Отредактируйте файл `/etc/dhcpcd.conf` и добавьте следующие строки в конец файла. Измените IP-адреса в соответствии с вашей конфигурацией.
|
||||
`interface` - это имя сетевого интерфейса или беспроводного устройства, которое можно узнать с помощью команды `# ip link show`.
|
||||
|
||||
```
|
||||
```ini
|
||||
interface enp0s25
|
||||
static ip_address=192.168.31.100/24
|
||||
static ip6_address=fd00:6868:6868::8888/64
|
||||
@@ -312,13 +312,13 @@ static domain_name_servers=192.168.31.1 fd00:6868:6868::1
|
||||
::: warning Внимание
|
||||
|
||||
Выберите одну из следующих конфигураций: nftables или iptables. Не используйте обе одновременно.
|
||||
|
||||
Запишите выбранную конфигурацию в файл, выдайте ему права на выполнение и затем запустите этот файл от имени root.
|
||||
:::
|
||||
|
||||
### Использование iptables
|
||||
::: code-group
|
||||
|
||||
В этой конфигурации IPv4 и IPv6 объединены в одном файле.
|
||||
|
||||
```bash
|
||||
```bash [iptables.rules]
|
||||
# Проксирование устройств локальной сети (IPv4)
|
||||
iptables -t mangle -N XRAY
|
||||
iptables -t mangle -A XRAY -d 127.0.0.1/32 -j RETURN
|
||||
@@ -377,18 +377,7 @@ ip6tables -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
|
||||
|
||||
```
|
||||
|
||||
::: tip Использование
|
||||
|
||||
Запишите приведенную выше конфигурацию в файл (например, `iptables.rules`), затем предоставьте файлу права на выполнение `# chmod 700 ./iptables.rules`.
|
||||
|
||||
Наконец, выполните файл от имени пользователя root: `# ./iptables.rules` или `# source iptables.rules`.
|
||||
:::
|
||||
|
||||
### Использование nftables
|
||||
|
||||
В этой конфигурации IPv4 и IPv6 объединены.
|
||||
|
||||
```
|
||||
```bash [nftables.rules]
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
@@ -427,11 +416,6 @@ table inet xray {
|
||||
|
||||
```
|
||||
|
||||
::: tip Использование
|
||||
|
||||
Запишите приведенную выше конфигурацию в файл (например, `nftables.rules`), затем предоставьте файлу права на выполнение `# chmod 700 ./nftables.rules`.
|
||||
|
||||
Наконец, выполните файл от имени пользователя root: `# ./nftables.rules` или `# source nftables.rules`.
|
||||
:::
|
||||
|
||||
Адреса шлюза `192.168.0.0/16`, `fd00::/8` и т.д. можно получить с помощью команд `ip address | grep -w inet | awk '{print $2}'` и `ip address | grep -w inet6 | awk '{print $2}'` [ссылка](https://xtls.github.io/document/level-2/iptables_gid.html#_4-%E8%AE%BE%E7%BD%AE-iptables-%E8%A7%84%E5%88%99).
|
||||
@@ -448,13 +432,19 @@ table inet xray {
|
||||
|
||||
Сначала убедитесь, что вы выполнили соответствующие команды Netfilter, описанные выше, и успешно протестировали настройку прозрачного проксирования, чтобы убедиться, что в дальнейшем будет сгенерирован правильный файл.
|
||||
|
||||
#### При использовании конфигурации iptables
|
||||
- **Если используется `iptables`**
|
||||
|
||||
1. Сохраните конфигурацию iptables в файлы `iptables.rulesv4` и `iptables.rulesv6` с помощью команд `# iptables-save > /root/iptables.rulesv4` и `# ip6tables-save > /root/iptables.rulesv6`.
|
||||
Сначала сохраните конфигурацию в `iptables.rulesv4` и `iptables.rulesv6` с помощью команд `# iptables-save > /root/iptables.rulesv4` и `# ip6tables-save > /root/iptables.rulesv6`.
|
||||
|
||||
2. Создайте файл с именем `tproxyrules.service` в каталоге `/etc/systemd/system/` и добавьте следующее содержимое:
|
||||
- **Если используется `nftables`**
|
||||
|
||||
```
|
||||
Сначала сохраните конфигурацию в `nftables.rulesv46` с помощью команды `# nft list ruleset > /root/nftables.rulesv46`.
|
||||
|
||||
Затем создайте `tproxyrules.service` в каталоге `/etc/systemd/system/`, запишите соответствующее содержимое для выбранного варианта и в конце выполните `systemctl enable tproxyrules`.
|
||||
|
||||
::: code-group
|
||||
|
||||
```ini [iptables tproxyrules.service]
|
||||
[Unit]
|
||||
Description=Tproxy rules
|
||||
|
||||
@@ -483,15 +473,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. Выполните команду `systemctl enable tproxyrules`.
|
||||
|
||||
#### При использовании конфигурации nftables
|
||||
|
||||
1. Сохраните конфигурацию nftables в файл `nftables.rulesv46` с помощью команды `# nft list ruleset > /root/nftables.rulesv46`.
|
||||
|
||||
2. Создайте файл с именем `tproxyrules.service` в каталоге `/etc/systemd/system/` и добавьте следующее содержимое:
|
||||
|
||||
```
|
||||
```ini [nftables tproxyrules.service]
|
||||
[Unit]
|
||||
Description=Tproxy rules
|
||||
|
||||
@@ -518,7 +500,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
3. Выполните команду `systemctl enable tproxyrules`.
|
||||
:::
|
||||
|
||||
::: tip tproxyrules.service
|
||||
|
||||
|
||||
Reference in New Issue
Block a user