Refine tproxy article layout

This commit is contained in:
Meow
2026-05-10 07:25:25 +08:00
parent 95b918b8c8
commit f1b565ac1e
12 changed files with 180 additions and 206 deletions
+7 -7
View File
@@ -20,18 +20,18 @@ Configuration tutorial for Xray-based TProxy Transparent Proxy (IPv4 and IPv6).
---
[Using Nginx or HAProxy to Build TLS Tunnels to Hide Fingerprints](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
Using Nginx or HAProxy on both ends to build a TLS tunnel for fingerprint hiding.
---
[[Transparent Proxy] Bypassing Xray Traffic via GID](./iptables_gid.md) by <img src="https://avatars2.githubusercontent.com/u/57820613?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@kirin](https://github.com/kirin10000)
A new method to bypass Xray traffic in transparent proxies implemented via iptables/nftables.
---
[Using Nginx or HAProxy to Build TLS Tunnels to Hide Fingerprints](./nginx_or_haproxy_tls_tunnel.md) by <img src="https://avatars.githubusercontent.com/u/110686480?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@SQLimit](https://github.com/SQLimit)
Using Nginx or HAProxy on both ends to build a TLS tunnel for fingerprint hiding.
---
[Directing Specific Traffic to Specific Exits via Xray for Global Routing "Traffic Splitting"](./redirect.md) by <img src="https://avatars.githubusercontent.com/u/28607089?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Zzz3m](https://github.com/Zzz3m)
Getting creative with Xray: Achieving "traffic splitting" based on fwmark, sendThrough, or sockopt.interface.
@@ -50,6 +50,6 @@ Traffic statistics and scripts adapted for Xray.
---
[VLESS Reverse Proxy](./vless_reverse.md)
[VLESS Reverse Proxy](./vless_reverse.md) by <img src="https://avatars.githubusercontent.com/u/197331664?s=32" width="24" height="24" alt="a" style="display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.25em;"/> [@Meo597](https://github.com/Meo597)
VLESS reverse proxy tutorial.
+30 -19
View File
@@ -161,7 +161,7 @@ This configuration hijacks all traffic sent to port 53 to solve DNS pollution is
## Policy Routing Configuration
```bash
```sh
sudo ip route add local default dev lo table 100 # Add routing table 100
sudo ip rule add fwmark 1 table 100 # Set rules for routing table 100
```
@@ -170,9 +170,13 @@ sudo ip rule add fwmark 1 table 100 # Set rules for routing table 100
::: warning Note
Choose either **nftables** or **iptables** configuration. Do not use both simultaneously.
Write the selected configuration to a file, make it executable, and then run that file as root.
:::
```nftables
::: code-group
```bash [nftables.conf]
#!/usr/sbin/nft -f
flush ruleset
@@ -210,12 +214,7 @@ table ip xray {
}
```
::: tip Usage
Write the above configuration to a file (e.g., `nft.conf`), then give the file executable permissions, and finally execute the file with root privileges (`# ./nft.conf`).
:::
```bash
```bash [iptables.sh]
iptables -t mangle -N XRAY
iptables -t mangle -A XRAY -d 10.0.0.0/8 -j RETURN
iptables -t mangle -A XRAY -d 100.64.0.0/10 -j RETURN
@@ -250,13 +249,31 @@ iptables -t mangle -A XRAY_SELF -p udp -j MARK --set-mark 1
iptables -t mangle -A OUTPUT -j XRAY_SELF
```
:::
After the configuration is complete, change the default gateway of other devices in the LAN to the IP of this device to bypass the firewall directly. After successfully testing on both other hosts and the local machine, you can proceed to the next step.
## Persistence and Auto-start
First, move the edited `nftables` configuration file to the `/etc` directory and rename it to `nftables.conf`. Then edit `/lib/systemd/system/nftables.service`.
Depending on which Netfilter option you selected above, use the corresponding persistence method here.
```ini
- **If using `nftables`**
Move the edited configuration file to the `/etc` directory, then edit `/lib/systemd/system/nftables.service`.
- **If using `iptables`**
It is recommended to install `iptables-persistent` directly.
During the installation process, you will be prompted whether to save the current configuration. If the `iptables` rules have already been applied to the system, select "Yes". If not, that is fine too; after installation, apply the configuration and then execute `netfilter-persistent save` (root privileges required).
After that, edit `/lib/systemd/system/netfilter-persistent.service`.
Finally, enable the selected service.
::: code-group
```ini [nftables.service]
[Unit]
Description=nftables
Documentation=man:nft(8) http://wiki.nftables.org
@@ -279,15 +296,7 @@ ExecStop=/usr/sbin/nft flush ruleset ; /usr/sbin/ip route del local default dev
WantedBy=sysinit.target
```
Finally, enable it.
For persistence with `iptables`, it is recommended to install `iptables-persistent` directly.
During the installation process, you will be prompted to "Save current IPv4 rules?". If you have already applied the iptables configuration to the system, select "Yes". If not, it doesn't matter; after installation, apply the configuration and then execute `netfilter-persistent save` (root privileges required).
After that, edit `/lib/systemd/system/netfilter-persistent.service`.
```ini
```ini [netfilter-persistent.service]
[Unit]
Description=netfilter persistent configuration
DefaultDependencies=no
@@ -306,3 +315,5 @@ ExecStop=/usr/sbin/netfilter-persistent stop ; /usr/sbin/ip route flush dev lo t
[Install]
WantedBy=multi-user.target
```
:::
@@ -262,7 +262,7 @@ If the Xray program is not installed on the side router, you can manually downlo
### First, Set Policy Routing
```bash
```sh
# Set policy routing v4
ip rule add fwmark 1 table 100
ip route add local 0.0.0.0/0 dev lo table 100
@@ -291,7 +291,7 @@ If you use **Method 2** below, the `default via` would be the side router's IP.
If you specified the default gateway as the side router on the main router (i.e., "LAN Device Internet Setup Method 2" below), then you need to set the above `# Direct connection goes out from the main router`. besides setting it via `iproute2` command line, you can also set a static IP via `dhcpcd` or `systemctl-network`. Here we take `dhcpcd` as an example. Edit the `/etc/dhcpcd.conf` file and add the following configuration at the bottom. Modify the specific IP according to your actual situation. The `interface` can be viewed via `# ip link show` to see the network port or wireless device to be configured.
```
```ini
interface enp0s25
static ip_address=192.168.31.100/24
static ip6_address=fd00:6868:6868::8888/64
@@ -304,13 +304,13 @@ By setting the IP and gateway via static IP this way, there is no need to set `#
::: warning Note
Choose **either** the following nftables configuration **or** iptables configuration. Do not use both simultaneously.
Write the selected configuration to a file, make it executable, and then run that file as root.
:::
### Using iptables
::: code-group
This configuration writes IPv4 and IPv6 into the same file.
```bash
```bash [iptables.rules]
# Proxy LAN devices v4
iptables -t mangle -N XRAY
iptables -t mangle -A XRAY -d 127.0.0.1/32 -j RETURN
@@ -369,18 +369,7 @@ ip6tables -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
```
::: tip Usage
Write the above configuration into a file (e.g., `iptables.rules`), then grant executable permission to the file: `# chmod 700 ./iptables.rules`.
Finally, execute the file with root privileges: `# ./iptables.rules` or `# source iptables.rules`.
:::
### Using nftables
This merges IPv4 and IPv6.
```
```bash [nftables.rules]
#!/usr/sbin/nft -f
flush ruleset
@@ -419,11 +408,6 @@ table inet xray {
```
::: tip Usage
Write the above configuration into a file (e.g., `nftables.rules`), then grant executable permission to the file: `# chmod 700 ./nftables.rules`.
Finally, execute the file with root privileges: `# ./nftables.rules` or `# source nftables.rules`.
:::
Where gateway addresses `192.168.0.0/16`, `fd00::/8`, etc., can be [obtained](https://xtls.github.io/document/level-2/iptables_gid.html#_4-%E8%AE%BE%E7%BD%AE-iptables-%E8%A7%84%E5%88%99) by `ip address | grep -w inet | awk '{print $2}'` and `ip address | grep -w inet6 | awk '{print $2}'`.
@@ -438,13 +422,19 @@ If the prefixes `192.168`, `fd00:` are the same, you don't need to change them.
First, confirm that you have run the corresponding Netfilter commands above and successfully tested the transparent proxy configuration to ensure the output files are correct.
#### If using iptables configuration
- **If using `iptables`**
1. First, save the iptables configuration to `iptables.rulesv4` and `iptables.rulesv6` files: `# iptables-save > /root/iptables.rulesv4` and `# ip6tables-save > /root/iptables.rulesv6`.
First, save the configuration to `iptables.rulesv4` and `iptables.rulesv6` with `# iptables-save > /root/iptables.rulesv4` and `# ip6tables-save > /root/iptables.rulesv6`.
2. Then create a file named `tproxyrules.service` in the `/etc/systemd/system/` directory, add the following content, and save it:
- **If using `nftables`**
```
First, save the configuration to `nftables.rulesv46` with `# nft list ruleset > /root/nftables.rulesv46`.
Then create `tproxyrules.service` under `/etc/systemd/system/`, write the corresponding content for the chosen option, and finally run `systemctl enable tproxyrules`.
::: code-group
```ini [iptables tproxyrules.service]
[Unit]
Description=Tproxy rules
@@ -473,15 +463,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
WantedBy=multi-user.target
```
1. Finally, execute the command `systemctl enable tproxyrules`.
#### If using nftables configuration
1. First, write the nftables configuration to the `nftables.rulesv46` file: `# nft list ruleset > /root/nftables.rulesv46`.
2. Create a file named `tproxyrules.service` in the `/etc/systemd/system/` directory, then add the following content and save it:
```
```ini [nftables tproxyrules.service]
[Unit]
Description=Tproxy rules
@@ -508,7 +490,7 @@ ExecStop=/sbin/ip rule del fwmark 1 table 100 ; \
WantedBy=multi-user.target
```
1. Finally, execute the command `systemctl enable tproxyrules`.
:::
::: tip tproxyrules.service