Fix documents

- upgrade vuepress: close #27 #28 #29 #30 #31
- tweak homepage
- tweak dark theme
This commit is contained in:
hmol233
2021-05-06 19:31:05 +08:00
parent 2117297f7c
commit f68422788d
18 changed files with 714 additions and 747 deletions
+147 -149
View File
@@ -6,7 +6,7 @@
如果你用了《小小白白话文》中的[Xray 配置](../level-0/ch07-xray-server.md#_7-4-配置xray),并完成了[HTTP 自动跳转 HTTPS 优化](../level-0/ch07-xray-server.md#_7-8-服务器优化之二-开启http自动跳转https),那么你已经有了基于 `VLESS` 协议的简易回落:
```
```json5
"inbounds": [
{
"port": 443,
@@ -113,7 +113,7 @@
为什么又要再次认识回落呢? 因为,上面仅仅说清楚了基于“协议”的、抵抗【主动探测】的初版回落。
在 [rprx](https://github.com/rprx) 不断开发迭代 `VLESS` 协议及 `fallback` 功能的过程种,逐渐发现,回落完全可以更加灵活强大,只要在保证抵抗【主动探测】的前提下,充分利用数据首包中的信息,其实可以做到多元素、多层次的回落。(如 `path`, `alpn` 等)
在 [RPRX](https://github.com/rprx) 不断开发迭代 `VLESS` 协议及 `fallback` 功能的过程种,逐渐发现,回落完全可以更加灵活强大,只要在保证抵抗【主动探测】的前提下,充分利用数据首包中的信息,其实可以做到多元素、多层次的回落。(如 `path`, `alpn` 等)
基于这个开发理念,【回落】功能才逐渐成长为现在的完全体,即完成了 `纯伪装 --> ws分流 --> 多协议多特征分流` 的进化。最终版甚至完全替代了以前要用 Web 服务器、其他工具才能完成的分流的功能。且由于上述的【回落/分流】处理都在首包判断阶段以毫秒级的速度完成、不涉及任何数据操作,所以几乎没有任何过程损耗。
@@ -133,58 +133,56 @@
### 5.1 首先,我将服务器端配置的 443 监听段摘抄如下:
```
```json5
{
"port": 443,
"protocol": "vless",
"settings": {
"clients": [
{
"id": "", // 填写你的 UUID
"flow": "xtls-rprx-direct",
"level": 0,
"email": "love@example.com"
}
],
"decryption": "none",
"fallbacks": [
{
"dest": 1310, // 默认回落到 Xray 的 Trojan 协议
"xver": 1
},
{
"path": "/websocket", // 必须换成自定义的 PATH
"dest": 1234,
"xver": 1
},
{
"path": "/vmesstcp", // 必须换成自定义的 PATH
"dest": 2345,
"xver": 1
},
{
"path": "/vmessws", // 必须换成自定义的 PATH
"dest": 3456,
"xver": 1
}
]
port: 443,
protocol: "vless",
settings: {
clients: [
{
id: "", // 填写你的 UUID
flow: "xtls-rprx-direct",
level: 0,
email: "love@example.com",
},
],
decryption: "none",
fallbacks: [
{
dest: 1310, // 默认回落到 Xray 的 Trojan 协议
xver: 1,
},
{
path: "/websocket", // 必须换成自定义的 PATH
dest: 1234,
xver: 1,
},
{
path: "/vmesstcp", // 必须换成自定义的 PATH
dest: 2345,
xver: 1,
},
{
path: "/vmessws", // 必须换成自定义的 PATH
dest: 3456,
xver: 1,
},
],
},
streamSettings: {
network: "tcp",
security: "xtls",
xtlsSettings: {
alpn: ["http/1.1"],
certificates: [
{
certificateFile: "/path/to/fullchain.crt", // 换成你的证书,绝对路径
keyFile: "/path/to/private.key", // 换成你的私钥,绝对路径
},
],
},
"streamSettings": {
"network": "tcp",
"security": "xtls",
"xtlsSettings": {
"alpn": [
"http/1.1"
],
"certificates": [
{
"certificateFile": "/path/to/fullchain.crt", // 换成你的证书,绝对路径
"keyFile": "/path/to/private.key" // 换成你的私钥,绝对路径
}
]
}
}
},
},
}
```
这一段配置用人话要怎么解释呢?
@@ -230,33 +228,33 @@
1. 后续处理回落至 `1310` 端口的流量,按照下面的配置验证、处理:
```
```json5
{
"port": 1310,
"listen": "127.0.0.1",
"protocol": "trojan",
"settings": {
"clients": [
{
"password": "", // 填写你的密码
"level": 0,
"email": "love@example.com"
}
],
"fallbacks": [
{
"dest": 80 // 或者回落到其它也防探测的代理
}
]
port: 1310,
listen: "127.0.0.1",
protocol: "trojan",
settings: {
clients: [
{
password: "", // 填写你的密码
level: 0,
email: "love@example.com",
},
],
fallbacks: [
{
dest: 80, // 或者回落到其它也防探测的代理
},
],
},
streamSettings: {
network: "tcp",
security: "none",
tcpSettings: {
acceptProxyProtocol: true,
},
"streamSettings": {
"network": "tcp",
"security": "none",
"tcpSettings": {
"acceptProxyProtocol": true
}
}
},
},
}
```
看,神奇的事情发生了, `trojan` 协议这里又出现了一个新的 `fallbacks`。前面已经说过,`xray` 中的 `trojan` 协议也具有完整的回落能力,所以,此时 `trojan` 协议可以再次做判断和回落(这也就是传说中的套娃回落了):
@@ -266,94 +264,94 @@
2. 后续处理回落至 `1234` 端口的流量,仔细看!它其实是 `vless+ws`:
```
```json5
{
"port": 1234,
"listen": "127.0.0.1",
"protocol": "vless",
"settings": {
"clients": [
{
"id": "", // 填写你的 UUID
"level": 0,
"email": "love@example.com"
}
],
"decryption": "none"
port: 1234,
listen: "127.0.0.1",
protocol: "vless",
settings: {
clients: [
{
id: "", // 填写你的 UUID
level: 0,
email: "love@example.com",
},
],
decryption: "none",
},
streamSettings: {
network: "ws",
security: "none",
wsSettings: {
acceptProxyProtocol: true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
path: "/websocket", // 必须换成自定义的 PATH,需要和分流的一致
},
"streamSettings": {
"network": "ws",
"security": "none",
"wsSettings": {
"acceptProxyProtocol": true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
"path": "/websocket" // 必须换成自定义的 PATH,需要和分流的一致
}
}
},
},
}
```
3. 后续处理回落至 `2345` 端口的流量,仔细看!它其实是 `vmess直连`:
```
```json5
{
"port": 2345,
"listen": "127.0.0.1",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "", // 填写你的 UUID
"level": 0,
"email": "love@example.com"
}
]
port: 2345,
listen: "127.0.0.1",
protocol: "vmess",
settings: {
clients: [
{
id: "", // 填写你的 UUID
level: 0,
email: "love@example.com",
},
],
},
streamSettings: {
network: "tcp",
security: "none",
tcpSettings: {
acceptProxyProtocol: true,
header: {
type: "http",
request: {
path: [
"/vmesstcp", // 必须换成自定义的 PATH,需要和分流的一致
],
},
},
},
"streamSettings": {
"network": "tcp",
"security": "none",
"tcpSettings": {
"acceptProxyProtocol": true,
"header": {
"type": "http",
"request": {
"path": [
"/vmesstcp" // 必须换成自定义的 PATH,需要和分流的一致
]
}
}
}
}
},
},
}
```
4. 后续处理回落至 `3456` 端口的流量,再仔细看!它其实是是 `vmess+ws(+cdn)`。
::: warning
**说明:** 你没看错,这就是 v2fly 曾经的推荐组合之一,并可完整支持 `CDN`。现已加入完美回落套餐哦!
::: warning 说明
你没看错,这就是 v2fly 曾经的推荐组合之一,并可完整支持 `CDN`。现已加入完美回落套餐哦!
:::
```
```json5
{
"port": 3456,
"listen": "127.0.0.1",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "", // 填写你的 UUID
"level": 0,
"email": "love@example.com"
}
]
port: 3456,
listen: "127.0.0.1",
protocol: "vmess",
settings: {
clients: [
{
id: "", // 填写你的 UUID
level: 0,
email: "love@example.com",
},
],
},
streamSettings: {
network: "ws",
security: "none",
wsSettings: {
acceptProxyProtocol: true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
path: "/vmessws", // 必须换成自定义的 PATH,需要和分流的一致
},
"streamSettings": {
"network": "ws",
"security": "none",
"wsSettings": {
"acceptProxyProtocol": true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
"path": "/vmessws" // 必须换成自定义的 PATH,需要和分流的一致
}
}
},
}
```
+68 -64
View File
@@ -1,3 +1,7 @@
---
title: SNI 回落
---
# 通过 SNI 回落功能实现伪装与按域名分流
VLESS 是一种很轻的协议,和 Trojan 一样,不对流量进行复杂的加密和混淆,而是大隐隐于市,通过 TLS 协议加密,混杂在其他 HTTPS 流量中,在墙内外穿进穿出。为了更好的伪装以应对主动探测,Fallbacks 回落功能随 VLESS 同时出现。这篇教程将演示如何使用 Xray 中 VLESS 入站协议的回落功能配合 Nginx 或 Caddy 在保证伪装完全的前提下实现按域名分流。
@@ -70,91 +74,91 @@ acme.sh --install-cert -d example.com --fullchain-file /etc/ssl/xray/cert.pem --
## Xray 配置
```json
```json5
{
"log": {
"loglevel": "warning"
log: {
loglevel: "warning",
},
"inbounds": [
inbounds: [
{
"port": 443,
"protocol": "vless",
"settings": {
"clients": [
port: 443,
protocol: "vless",
settings: {
clients: [
{
"id": "UUID",
"flow": "xtls-rprx-direct"
}
id: "UUID",
flow: "xtls-rprx-direct",
},
],
"decryption": "none",
"fallbacks": [
decryption: "none",
fallbacks: [
{
"name": "example.com",
"path": "/vmessws",
"dest": 5000,
"xver": 1
name: "example.com",
path: "/vmessws",
dest: 5000,
xver: 1,
},
{
"dest": 5001,
"xver": 1
dest: 5001,
xver: 1,
},
{
"alpn": "h2",
"dest": 5002,
"xver": 1
alpn: "h2",
dest: 5002,
xver: 1,
},
{
"name": "blog.example.com",
"dest": 5003,
"xver": 1
name: "blog.example.com",
dest: 5003,
xver: 1,
},
{
"name": "blog.example.com",
"alpn": "h2",
"dest": 5004,
"xver": 1
}
]
name: "blog.example.com",
alpn: "h2",
dest: 5004,
xver: 1,
},
],
},
"streamSettings": {
"network": "tcp",
"security": "xtls",
"xtlsSettings": {
"alpn": ["h2", "http/1.1"],
"certificates": [
streamSettings: {
network: "tcp",
security: "xtls",
xtlsSettings: {
alpn: ["h2", "http/1.1"],
certificates: [
{
"certificateFile": "/etc/ssl/xray/cert.pem",
"keyFile": "/etc/ssl/xray/privkey.key"
}
]
}
}
certificateFile: "/etc/ssl/xray/cert.pem",
keyFile: "/etc/ssl/xray/privkey.key",
},
],
},
},
},
{
"listen": "127.0.0.1",
"port": 5000,
"protocol": "vmess",
"settings": {
"clients": [
listen: "127.0.0.1",
port: 5000,
protocol: "vmess",
settings: {
clients: [
{
"id": "UUID"
}
]
id: "UUID",
},
],
},
"streamSettings": {
"network": "ws",
"wsSettings": {
"acceptProxyProtocol": true,
"path": "/vmessws"
}
}
}
streamSettings: {
network: "ws",
wsSettings: {
acceptProxyProtocol: true,
path: "/vmessws",
},
},
},
],
"outbounds": [
outbounds: [
{
"protocol": "freedom"
}
]
protocol: "freedom",
},
],
}
```
@@ -188,7 +192,7 @@ acme.sh --install-cert -d example.com --fullchain-file /etc/ssl/xray/cert.pem --
如果使用 Caddy 就大可不必如此繁杂了,因为它**可以**在同一端口上同时监听 HTTP/1.1 和 h2c,配置改动如下:
```json
```json5
"fallbacks": [
{
"name": "example.com",
+7 -7
View File
@@ -51,7 +51,7 @@
下面的入站配置示例,用大白话说就是:数据按照 `socks` 协议,通过 `10808` 端口,从本机 `127.0.0.1` 流入`Xray`。同时,`Xray` 将这个入站用 `[tag]` 命名为 `inbound-10808`。
```
```json5
"inbounds": [
{
"tag": "inbound-10808",
@@ -73,7 +73,7 @@
下面的出站配置示例,用大白话说就是:数据按照 `VLESS` 协议,以 `tcp + xtls (direct)` 的方式、及其他相关设置,把流量发送给对应的 VPS。同时,`Xray` 将这个出站用 `[tag]` 命名为 `proxy-out-vless`:
```
```json5
"outbounds": [
{
"tag": "proxy-out-vless",
@@ -113,7 +113,7 @@
下面的路由配置示例,用大白话说就是:把所有通过 `[tag]="inbound-10808"` 入站流入 `Xray` 的流量,`100%` 全部流转导入 `[tag]="proxy-out-vless"` 的出站,没有任何分流或其他操作。
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -201,7 +201,7 @@
在上例的基础上,我们已经有了 `[proxy]` 的出站 `"proxy-out-vless"`,所以它保持不变。显而易见,我们需要加入两个新的出站方式:`[block]` 和 `[direct]`,如下:
```
```json5
"outbounds": [
{
"tag": "proxy-out-vless",
@@ -228,7 +228,7 @@
接下来就是见证奇迹的时刻了,我们可以用【路由】的配置把这些连接起来!
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -360,9 +360,9 @@
上一步我们已经配置出了 **【默认科学上网、国内网站白名单直连】** 的规则。那么现在只要 **【把直连规则放在第一位】**,就立即变成了正好相反的 **【默认直连、国外网站白名单科学上网】** 规则。
是不是,非常的简单?
是不是,非常地简单?
```
```json5
"outbounds": [
{
"tag": "direct-out",
+7 -7
View File
@@ -50,7 +50,7 @@
上述配置如下:
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -92,7 +92,7 @@
上述配置如下:
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -125,7 +125,7 @@
上述配置如下:
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -157,7 +157,7 @@
你需要打开入站代理中的 `sniffing` 才能使用此种方式分流。
:::
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -205,7 +205,7 @@
`[1-block] --> [2-direct] --> [3-proxy] --> [4-first-outbound]`
:::
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -325,7 +325,7 @@
为了实现上面的目标,他写出了以下路由规则:
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [
@@ -357,7 +357,7 @@
正确示范,自然就是将不同的匹配依据独立出来:
```
```json5
"routing": {
"domainStrategy": "AsIs",
"rules": [