mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-09-28 01:47:59 +03:00
Fix json format
close https://github.com/XTLS/Xray-docs-next/pull/83 Thanks: @Johnshall
This commit is contained in:
@@ -6,27 +6,29 @@
|
||||
|
||||
如果你用了《小小白白话文》中的[Xray 配置](../level-0/ch07-xray-server.md#_7-4-配置xray),并完成了[HTTP 自动跳转 HTTPS 优化](../level-0/ch07-xray-server.md#_7-8-服务器优化之二-开启http自动跳转https),那么你已经有了基于 `VLESS` 协议的简易回落:
|
||||
|
||||
```json5
|
||||
"inbounds": [
|
||||
```json
|
||||
{
|
||||
"inbounds": [
|
||||
{
|
||||
"port": 443,
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"clients": [
|
||||
...
|
||||
],
|
||||
"decryption": "none",
|
||||
"fallbacks": [
|
||||
{
|
||||
"dest": 8080 // 默认回落到防探测的代理
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
...
|
||||
}
|
||||
"port": 443,
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"clients": [
|
||||
// ... ...
|
||||
],
|
||||
"decryption": "none",
|
||||
"fallbacks": [
|
||||
{
|
||||
"dest": 8080 // 默认回落到防探测的代理
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
// ... ...
|
||||
}
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
这一段配置用人话要怎么解释呢?
|
||||
@@ -133,55 +135,55 @@
|
||||
|
||||
### 5.1 首先,我将服务器端配置的 443 监听段摘抄如下:
|
||||
|
||||
```json5
|
||||
```json
|
||||
{
|
||||
port: 443,
|
||||
protocol: "vless",
|
||||
settings: {
|
||||
clients: [
|
||||
"port": 443,
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
id: "", // 填写你的 UUID
|
||||
flow: "xtls-rprx-direct",
|
||||
level: 0,
|
||||
email: "love@example.com",
|
||||
},
|
||||
"id": "", // 填写你的 UUID
|
||||
"flow": "xtls-rprx-direct",
|
||||
"level": 0,
|
||||
"email": "love@example.com"
|
||||
}
|
||||
],
|
||||
decryption: "none",
|
||||
fallbacks: [
|
||||
"decryption": "none",
|
||||
"fallbacks": [
|
||||
{
|
||||
dest: 1310, // 默认回落到 Xray 的 Trojan 协议
|
||||
xver: 1,
|
||||
"dest": 1310, // 默认回落到 Xray 的 Trojan 协议
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
path: "/websocket", // 必须换成自定义的 PATH
|
||||
dest: 1234,
|
||||
xver: 1,
|
||||
"path": "/websocket", // 必须换成自定义的 PATH
|
||||
"dest": 1234,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
path: "/vmesstcp", // 必须换成自定义的 PATH
|
||||
dest: 2345,
|
||||
xver: 1,
|
||||
"path": "/vmesstcp", // 必须换成自定义的 PATH
|
||||
"dest": 2345,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
path: "/vmessws", // 必须换成自定义的 PATH
|
||||
dest: 3456,
|
||||
xver: 1,
|
||||
},
|
||||
],
|
||||
"path": "/vmessws", // 必须换成自定义的 PATH
|
||||
"dest": 3456,
|
||||
"xver": 1
|
||||
}
|
||||
]
|
||||
},
|
||||
streamSettings: {
|
||||
network: "tcp",
|
||||
security: "xtls",
|
||||
xtlsSettings: {
|
||||
alpn: ["http/1.1"],
|
||||
certificates: [
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "xtls",
|
||||
"xtlsSettings": {
|
||||
"alpn": ["http/1.1"],
|
||||
"certificates": [
|
||||
{
|
||||
certificateFile: "/path/to/fullchain.crt", // 换成你的证书,绝对路径
|
||||
keyFile: "/path/to/private.key", // 换成你的私钥,绝对路径
|
||||
},
|
||||
],
|
||||
},
|
||||
},
|
||||
"certificateFile": "/path/to/fullchain.crt", // 换成你的证书,绝对路径
|
||||
"keyFile": "/path/to/private.key" // 换成你的私钥,绝对路径
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -228,32 +230,32 @@
|
||||
|
||||
1. 后续处理回落至 `1310` 端口的流量,按照下面的配置验证、处理:
|
||||
|
||||
```json5
|
||||
```json
|
||||
{
|
||||
port: 1310,
|
||||
listen: "127.0.0.1",
|
||||
protocol: "trojan",
|
||||
settings: {
|
||||
clients: [
|
||||
"port": 1310,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "trojan",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
password: "", // 填写你的密码
|
||||
level: 0,
|
||||
email: "love@example.com",
|
||||
},
|
||||
"password": "", // 填写你的密码
|
||||
"level": 0,
|
||||
"email": "love@example.com"
|
||||
}
|
||||
],
|
||||
fallbacks: [
|
||||
"fallbacks": [
|
||||
{
|
||||
dest: 80, // 或者回落到其它也防探测的代理
|
||||
},
|
||||
],
|
||||
},
|
||||
streamSettings: {
|
||||
network: "tcp",
|
||||
security: "none",
|
||||
tcpSettings: {
|
||||
acceptProxyProtocol: true,
|
||||
},
|
||||
"dest": 80 // 或者回落到其它也防探测的代理
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "none",
|
||||
"tcpSettings": {
|
||||
"acceptProxyProtocol": true
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -264,94 +266,94 @@
|
||||
|
||||
2. 后续处理回落至 `1234` 端口的流量,仔细看!它其实是 `vless+ws`:
|
||||
|
||||
```json5
|
||||
```json
|
||||
{
|
||||
port: 1234,
|
||||
listen: "127.0.0.1",
|
||||
protocol: "vless",
|
||||
settings: {
|
||||
clients: [
|
||||
"port": 1234,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
id: "", // 填写你的 UUID
|
||||
level: 0,
|
||||
email: "love@example.com",
|
||||
},
|
||||
"id": "", // 填写你的 UUID
|
||||
"level": 0,
|
||||
"email": "love@example.com"
|
||||
}
|
||||
],
|
||||
decryption: "none",
|
||||
},
|
||||
streamSettings: {
|
||||
network: "ws",
|
||||
security: "none",
|
||||
wsSettings: {
|
||||
acceptProxyProtocol: true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
|
||||
path: "/websocket", // 必须换成自定义的 PATH,需要和分流的一致
|
||||
},
|
||||
"decryption": "none"
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "ws",
|
||||
"security": "none",
|
||||
"wsSettings": {
|
||||
"acceptProxyProtocol": true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
|
||||
"path": "/websocket" // 必须换成自定义的 PATH,需要和分流的一致
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
3. 后续处理回落至 `2345` 端口的流量,仔细看!它其实是 `vmess直连`:
|
||||
|
||||
```json5
|
||||
```json
|
||||
{
|
||||
port: 2345,
|
||||
listen: "127.0.0.1",
|
||||
protocol: "vmess",
|
||||
settings: {
|
||||
clients: [
|
||||
"port": 2345,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "vmess",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
id: "", // 填写你的 UUID
|
||||
level: 0,
|
||||
email: "love@example.com",
|
||||
},
|
||||
],
|
||||
},
|
||||
streamSettings: {
|
||||
network: "tcp",
|
||||
security: "none",
|
||||
tcpSettings: {
|
||||
acceptProxyProtocol: true,
|
||||
header: {
|
||||
type: "http",
|
||||
request: {
|
||||
path: [
|
||||
"/vmesstcp", // 必须换成自定义的 PATH,需要和分流的一致
|
||||
],
|
||||
},
|
||||
},
|
||||
},
|
||||
"id": "", // 填写你的 UUID
|
||||
"level": 0,
|
||||
"email": "love@example.com"
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "none",
|
||||
"tcpSettings": {
|
||||
"acceptProxyProtocol": true,
|
||||
"header": {
|
||||
"type": "http",
|
||||
"request": {
|
||||
"path": [
|
||||
"/vmesstcp" // 必须换成自定义的 PATH,需要和分流的一致
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
4. 后续处理回落至 `3456` 端口的流量,再仔细看!它其实是是 `vmess+ws(+cdn)`。
|
||||
|
||||
::: warning 说明
|
||||
你没看错,这就是 v2fly 曾经的推荐组合之一,并可完整支持 `CDN`。现已加入完美回落套餐哦!
|
||||
你没看错,这就是 v2fly 曾经推荐的组合之一,并可完整支持 `CDN`。现已加入完美回落套餐哦!
|
||||
:::
|
||||
|
||||
```json5
|
||||
```json
|
||||
{
|
||||
port: 3456,
|
||||
listen: "127.0.0.1",
|
||||
protocol: "vmess",
|
||||
settings: {
|
||||
clients: [
|
||||
"port": 3456,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "vmess",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
id: "", // 填写你的 UUID
|
||||
level: 0,
|
||||
email: "love@example.com",
|
||||
},
|
||||
],
|
||||
},
|
||||
streamSettings: {
|
||||
network: "ws",
|
||||
security: "none",
|
||||
wsSettings: {
|
||||
acceptProxyProtocol: true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
|
||||
path: "/vmessws", // 必须换成自定义的 PATH,需要和分流的一致
|
||||
},
|
||||
"id": "", // 填写你的 UUID
|
||||
"level": 0,
|
||||
"email": "love@example.com"
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "ws",
|
||||
"security": "none",
|
||||
"wsSettings": {
|
||||
"acceptProxyProtocol": true, // 提醒:若你用 Nginx/Caddy 等反代 WS,需要删掉这行
|
||||
"path": "/vmessws" // 必须换成自定义的 PATH,需要和分流的一致
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
@@ -74,91 +74,91 @@ acme.sh --install-cert -d example.com --fullchain-file /etc/ssl/xray/cert.pem --
|
||||
|
||||
## Xray 配置
|
||||
|
||||
```json5
|
||||
```json
|
||||
{
|
||||
log: {
|
||||
loglevel: "warning",
|
||||
"log": {
|
||||
"loglevel": "warning"
|
||||
},
|
||||
inbounds: [
|
||||
"inbounds": [
|
||||
{
|
||||
port: 443,
|
||||
protocol: "vless",
|
||||
settings: {
|
||||
clients: [
|
||||
"port": 443,
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
id: "UUID",
|
||||
flow: "xtls-rprx-direct",
|
||||
},
|
||||
"id": "UUID",
|
||||
"flow": "xtls-rprx-direct"
|
||||
}
|
||||
],
|
||||
decryption: "none",
|
||||
fallbacks: [
|
||||
"decryption": "none",
|
||||
"fallbacks": [
|
||||
{
|
||||
name: "example.com",
|
||||
path: "/vmessws",
|
||||
dest: 5000,
|
||||
xver: 1,
|
||||
"name": "example.com",
|
||||
"path": "/vmessws",
|
||||
"dest": 5000,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
dest: 5001,
|
||||
xver: 1,
|
||||
"dest": 5001,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
alpn: "h2",
|
||||
dest: 5002,
|
||||
xver: 1,
|
||||
"alpn": "h2",
|
||||
"dest": 5002,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
name: "blog.example.com",
|
||||
dest: 5003,
|
||||
xver: 1,
|
||||
"name": "blog.example.com",
|
||||
"dest": 5003,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
name: "blog.example.com",
|
||||
alpn: "h2",
|
||||
dest: 5004,
|
||||
xver: 1,
|
||||
},
|
||||
],
|
||||
"name": "blog.example.com",
|
||||
"alpn": "h2",
|
||||
"dest": 5004,
|
||||
"xver": 1
|
||||
}
|
||||
]
|
||||
},
|
||||
streamSettings: {
|
||||
network: "tcp",
|
||||
security: "xtls",
|
||||
xtlsSettings: {
|
||||
alpn: ["h2", "http/1.1"],
|
||||
certificates: [
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "xtls",
|
||||
"xtlsSettings": {
|
||||
"alpn": ["h2", "http/1.1"],
|
||||
"certificates": [
|
||||
{
|
||||
certificateFile: "/etc/ssl/xray/cert.pem",
|
||||
keyFile: "/etc/ssl/xray/privkey.key",
|
||||
},
|
||||
],
|
||||
},
|
||||
},
|
||||
"certificateFile": "/etc/ssl/xray/cert.pem",
|
||||
"keyFile": "/etc/ssl/xray/privkey.key"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
listen: "127.0.0.1",
|
||||
port: 5000,
|
||||
protocol: "vmess",
|
||||
settings: {
|
||||
clients: [
|
||||
"listen": "127.0.0.1",
|
||||
"port": 5000,
|
||||
"protocol": "vmess",
|
||||
"settings": {
|
||||
"clients": [
|
||||
{
|
||||
id: "UUID",
|
||||
},
|
||||
],
|
||||
"id": "UUID"
|
||||
}
|
||||
]
|
||||
},
|
||||
streamSettings: {
|
||||
network: "ws",
|
||||
wsSettings: {
|
||||
acceptProxyProtocol: true,
|
||||
path: "/vmessws",
|
||||
},
|
||||
},
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "ws",
|
||||
"wsSettings": {
|
||||
"acceptProxyProtocol": true,
|
||||
"path": "/vmessws"
|
||||
}
|
||||
}
|
||||
}
|
||||
],
|
||||
outbounds: [
|
||||
"outbounds": [
|
||||
{
|
||||
protocol: "freedom",
|
||||
},
|
||||
],
|
||||
"protocol": "freedom"
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
@@ -192,24 +192,26 @@ acme.sh --install-cert -d example.com --fullchain-file /etc/ssl/xray/cert.pem --
|
||||
|
||||
如果使用 Caddy 就大可不必如此繁杂了,因为它**可以**在同一端口上同时监听 HTTP/1.1 和 h2c,配置改动如下:
|
||||
|
||||
```json5
|
||||
"fallbacks": [
|
||||
```json
|
||||
{
|
||||
"fallbacks": [
|
||||
{
|
||||
"name": "example.com",
|
||||
"path": "/vmessws",
|
||||
"dest": 5000,
|
||||
"xver": 1
|
||||
"name": "example.com",
|
||||
"path": "/vmessws",
|
||||
"dest": 5000,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
"dest": 5001,
|
||||
"xver": 1
|
||||
"dest": 5001,
|
||||
"xver": 1
|
||||
},
|
||||
{
|
||||
"name": "blog.example.com",
|
||||
"dest": 5002,
|
||||
"xver": 1
|
||||
"name": "blog.example.com",
|
||||
"dest": 5002,
|
||||
"xver": 1
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
## Nginx 配置
|
||||
|
||||
@@ -51,18 +51,20 @@
|
||||
|
||||
下面的入站配置示例,用大白话说就是:数据按照 `socks` 协议,通过 `10808` 端口,从本机 `127.0.0.1` 流入`Xray`。同时,`Xray` 将这个入站用 `[tag]` 命名为 `inbound-10808`。
|
||||
|
||||
```json5
|
||||
"inbounds": [
|
||||
```json
|
||||
{
|
||||
"inbounds": [
|
||||
{
|
||||
"tag": "inbound-10808",
|
||||
"protocol": "socks",
|
||||
"listen": "127.0.0.1",
|
||||
"port": 10808,
|
||||
"settings": {
|
||||
"udp": true
|
||||
}
|
||||
"tag": "inbound-10808",
|
||||
"protocol": "socks",
|
||||
"listen": "127.0.0.1",
|
||||
"port": 10808,
|
||||
"settings": {
|
||||
"udp": true
|
||||
}
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
**2.2 出站**
|
||||
@@ -73,36 +75,38 @@
|
||||
|
||||
下面的出站配置示例,用大白话说就是:数据按照 `VLESS` 协议,以 `tcp + xtls (direct)` 的方式、及其他相关设置,把流量发送给对应的 VPS。同时,`Xray` 将这个出站用 `[tag]` 命名为 `proxy-out-vless`:
|
||||
|
||||
```json5
|
||||
"outbounds": [
|
||||
```json
|
||||
{
|
||||
"outbounds": [
|
||||
{
|
||||
"tag": "proxy-out-vless",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"vnext": [
|
||||
{
|
||||
"address": "a-name.yourdomain.com",
|
||||
"port": 443,
|
||||
"users": [
|
||||
{
|
||||
"id": "uuiduuid-uuid-uuid-uuid-uuiduuiduuid",
|
||||
"flow": "xtls-rprx-direct",
|
||||
"encryption": "none",
|
||||
"level": 0
|
||||
}
|
||||
]
|
||||
}
|
||||
"tag": "proxy-out-vless",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"vnext": [
|
||||
{
|
||||
"address": "a-name.yourdomain.com",
|
||||
"port": 443,
|
||||
"users": [
|
||||
{
|
||||
"id": "uuiduuid-uuid-uuid-uuid-uuiduuiduuid",
|
||||
"flow": "xtls-rprx-direct",
|
||||
"encryption": "none",
|
||||
"level": 0
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "xtls",
|
||||
"xtlsSettings": {
|
||||
"serverName": "a-name.yourdomain.com"
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "xtls",
|
||||
"xtlsSettings": {
|
||||
"serverName": "a-name.yourdomain.com"
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
### 2.3 路由
|
||||
@@ -113,18 +117,18 @@
|
||||
|
||||
下面的路由配置示例,用大白话说就是:把所有通过 `[tag]="inbound-10808"` 入站流入 `Xray` 的流量,`100%` 全部流转导入 `[tag]="proxy-out-vless"` 的出站,没有任何分流或其他操作。
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": [
|
||||
"inbound-10808"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": ["inbound-10808"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -201,21 +205,23 @@
|
||||
|
||||
在上例的基础上,我们已经有了 `[proxy]` 的出站 `"proxy-out-vless"`,所以它保持不变。显而易见,我们需要加入两个新的出站方式:`[block]` 和 `[direct]`,如下:
|
||||
|
||||
```json5
|
||||
"outbounds": [
|
||||
```json
|
||||
{
|
||||
"outbounds": [
|
||||
{
|
||||
"tag": "proxy-out-vless",
|
||||
......
|
||||
"tag": "proxy-out-vless"
|
||||
// ... ...
|
||||
},
|
||||
{
|
||||
"tag": "block",
|
||||
"protocol": "blackhole"
|
||||
"tag": "block",
|
||||
"protocol": "blackhole"
|
||||
},
|
||||
{
|
||||
"tag": "direct-out",
|
||||
"protocol": "freedom"
|
||||
"tag": "direct-out",
|
||||
"protocol": "freedom"
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
上面的配置用大白话翻译如下:
|
||||
@@ -228,32 +234,28 @@
|
||||
|
||||
接下来就是见证奇迹的时刻了,我们可以用【路由】的配置把这些连接起来!
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:category-ads-all"
|
||||
],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:cn"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:geolocation-!cn"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -362,21 +364,23 @@
|
||||
|
||||
是不是,非常地简单?
|
||||
|
||||
```json5
|
||||
"outbounds": [
|
||||
```json
|
||||
{
|
||||
"outbounds": [
|
||||
{
|
||||
"tag": "direct-out",
|
||||
"protocol": "freedom"
|
||||
"tag": "direct-out",
|
||||
"protocol": "freedom"
|
||||
},
|
||||
{
|
||||
"tag": "proxy-out-vless",
|
||||
......
|
||||
"tag": "proxy-out-vless"
|
||||
// ... ...
|
||||
},
|
||||
{
|
||||
"tag": "block",
|
||||
"protocol": "blackhole"
|
||||
"tag": "block",
|
||||
"protocol": "blackhole"
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
此时,路由规则其实变成了:
|
||||
|
||||
@@ -50,35 +50,31 @@
|
||||
|
||||
上述配置如下:
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
// 指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"full:direct.yourdomain.com"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定子域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"full:proxy.yourdomain.com"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// 指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"yourdomain.com"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
// 指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定子域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:proxy.yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// 指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["yourdomain.com"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -92,27 +88,25 @@
|
||||
|
||||
上述配置如下:
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
// 本机内部地址、局域网地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:private"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 国内IP集直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:cn"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
// 本机内部地址、局域网地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 国内IP集直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:cn"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -125,27 +119,25 @@
|
||||
|
||||
上述配置如下:
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
// 指定IP地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"223.5.5.5"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定IP地址转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"1.1.1.1"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
// 指定IP地址直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 指定IP地址转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -157,19 +149,19 @@
|
||||
你需要打开入站代理中的 `sniffing` 才能使用此种方式分流。
|
||||
:::
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
// 指定 BT 协议直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
// 指定 BT 协议直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -205,69 +197,58 @@
|
||||
`[1-block] --> [2-direct] --> [3-proxy] --> [4-first-outbound]`
|
||||
:::
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
// [1-block 广告流量屏蔽]
|
||||
// 1.1 广告域名集屏蔽
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:category-ads-all"
|
||||
],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// [2-direct 国内流量直连]
|
||||
// 2.1 国内域名集、指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:cn",
|
||||
"full:direct.yourdomain.com"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.2 本机内部地址+局域网、国内IP、指定IP直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"geoip:private",
|
||||
"geoip:cn",
|
||||
"223.5.5.5"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.3 BT协议流量直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": [
|
||||
"bittorrent"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// [3-proxy 国外流量转发VPS]
|
||||
// 3.1 国外域名集、指定子域名、指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"full:proxy.yourdomain.com",
|
||||
"yourdomain.com"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// 3.2 指定IP转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"1.1.1.1"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
// [4-default-routing 第一条出站]
|
||||
// 没有匹配到任何规则的流量,默认使用第一条出站处理
|
||||
// [1-block 广告流量屏蔽]
|
||||
// 1.1 广告域名集屏蔽
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:category-ads-all"],
|
||||
"outboundTag": "block"
|
||||
},
|
||||
// [2-direct 国内流量直连]
|
||||
// 2.1 国内域名集、指定子域名直连
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["geosite:cn", "full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.2 本机内部地址+局域网、国内IP、指定IP直连
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["geoip:private", "geoip:cn", "223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// 2.3 BT协议流量直连
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
// [3-proxy 国外流量转发VPS]
|
||||
// 3.1 国外域名集、指定子域名、指定泛域名转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"geosite:geolocation-!cn",
|
||||
"full:proxy.yourdomain.com",
|
||||
"yourdomain.com"
|
||||
],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
},
|
||||
// 3.2 指定IP转发VPS
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["1.1.1.1"],
|
||||
"outboundTag": "proxy-out-vless"
|
||||
}
|
||||
// [4-default-routing 第一条出站]
|
||||
// 没有匹配到任何规则的流量,默认使用第一条出站处理
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -325,21 +306,19 @@
|
||||
|
||||
为了实现上面的目标,他写出了以下路由规则:
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"223.5.5.5"
|
||||
],
|
||||
"domain": [
|
||||
"full:direct.yourdomain.com"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -357,25 +336,23 @@
|
||||
|
||||
正确示范,自然就是将不同的匹配依据独立出来:
|
||||
|
||||
```json5
|
||||
"routing": {
|
||||
```json
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"ip": [
|
||||
"223.5.5.5"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": [
|
||||
"full:direct.yourdomain.com"
|
||||
],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
{
|
||||
"type": "field",
|
||||
"ip": ["223.5.5.5"],
|
||||
"outboundTag": "direct-out"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"domain": ["full:direct.yourdomain.com"],
|
||||
"outboundTag": "direct-out"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user