惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Security Latest
Security Latest
C
CXSECURITY Database RSS Feed - CXSecurity.com
AI
AI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
P
Palo Alto Networks Blog
Spread Privacy
Spread Privacy
Project Zero
Project Zero
Google Online Security Blog
Google Online Security Blog
The Cloudflare Blog
L
LangChain Blog
T
Tenable Blog
GbyAI
GbyAI
C
Cybersecurity and Infrastructure Security Agency CISA
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
量子位
Cloudbric
Cloudbric
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
S
Securelist
S
Schneier on Security
F
Full Disclosure
Engineering at Meta
Engineering at Meta
A
Arctic Wolf
Microsoft Security Blog
Microsoft Security Blog
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Privacy International News Feed
宝玉的分享
宝玉的分享
A
About on SuperTechFans
博客园 - 【当耐特】
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hugging Face - Blog
Hugging Face - Blog
Webroot Blog
Webroot Blog
Google DeepMind News
Google DeepMind News
H
Heimdal Security Blog
Y
Y Combinator Blog
月光博客
月光博客
H
Hacker News: Front Page
MongoDB | Blog
MongoDB | Blog
C
Check Point Blog
TaoSecurity Blog
TaoSecurity Blog
腾讯CDC
N
Netflix TechBlog - Medium

Mereith's Blog

记一次代理转发问题的排查与解决 PVE DataCenter Manager 端口号跳转错误修复 k8s + jenkins + gitlab 触发器 【转载】没有编程生产力这样的东西 【后续】居然被 ddos 了 居然被 ddos 了 Tagger - 让版本标签管理更简单 openclash 开启后端口转发失效 nextjs 启动时执行代码 买了太多VPS不知道干什么,干脆做个网站 juhost Level-1 测评 VMISS CN - Hong Kong VMISS JP - Tokyo - BGP 测评 VMISS CN - Hong Kong - BGP HomeLab 的终点是 最近在做的事情 因为选择艰难症,自己写了一套开源博客系统 手撸一个nodejs分布式爬虫,还要可视化 HomeLab 分享 我的个人工作流——开源项目推荐 动手写一个超简单的编译器 safari 插件开发 Safari Extensions Preferences 按钮无响应 设置移动端软键盘回车按钮文案 nginx proxy manager 非标准端口反代 Host 不对 监控 k8s ingress 自动添加域名 DNS 解析 使用 ingress 注解给 traefik ingress 添加中间件 使用流水线功能为文章添加固定结尾 为 VanBlog 添加一个小挂件 基于React/umi/egg自建博客系统 如何正确停止 NodeJS 子进程 k8s pod 替换策略 让威联通、pve 共享 ups 实现断电关机 Ubuntu 配置 samba 混合云部署k3s集群(基于wireguard) pve 无法启动 grub lvmid not found error antd Password 关闭自动补全 code-server node not found pve no quorum 错误 || 无法登录 pve Cannot Initiate CMAP Service pve 节点删不干净 PVE 指针(鼠标)漂移 pve 重启网络 Proxmox VE 直通显卡 ProxmoxVE (PVE) 7.0 换源升级 用 SOCAT 端口转发 git 无法 pull 仓库refusing to merge unrelated histories 用 vuepress 搭建私人知识库 js 防抖节流中的 this 与箭头函数 Dockerfile 给 Ubuntu 换源 docker 内访问宿主机 docker 删除无用镜像 css 实现展开收起动画 nginx 301 问题 Node.js 流式编程 关于我重写了三次博客项目这件事 css flex 布局超出隐藏 css 隐藏滚动条 css 文字超出隐藏并显示省略号 css 填充 svg 颜色 css 黑白滤镜 nginx 反代丢端口 docker-compose 部署 matomo 分析系统 基于 strapi 开发应用 strapi 关闭 Content Security Policy nginx 反代 rewite url ssh 通过跳板机访问目标机器 Cent os 7 安装 zsh 5.6 以上版本 win11 任务栏不合并 bash 数组操作 vim 修改文件格式为 unix k8s 集群 control-plane-endpoint 主机名 git https 保存密码 Bash 判断命令存在 & 重定向 python 导出项目依赖 cent os 7 安装 gcc 版本 9 System limit for number of file watchers reached cent os 7 安装 git 2.x css 下划线中间向两边滑动效果 linux 挂载 SMB/CIFS linux 清除 ACL windows 命令行安装 inf 驱动 css 文字不可选择 iperf3 网络测速工具 cent os 换源 k8s 1.21.3 从 docker 迁移到 containerd 解决Nginx安装错误:No package nginx available 问题 从pve的硬盘里导出数据 Errors were encountered while processing adguardhome配合clash pve中使用LXC容器安装OMV LXC直通硬盘 nginx反代模版 docker常用开启容器的命令 PVE的LXC容器中安装Docker ProxmoxVE系统分区相关 Portainer添加节点 linux声卡设置及录音音 OpenWrt用VLAN PVE换源及去掉订阅提示和改端口 adguardhome踩坑
基于clash搭建旁路网关
wanglu@mereith.com (mereith) · 2022-07-21 · via Mereith's Blog

请注意,本文编写于 1884 天前,最后修改于 1416 天前,其中某些信息可能已经过时。

clash是强大的开源代理软件,支持在各种平台上面运行,但默认的配置是socks代理和http代理,想拿它做旁路网关还需要一些操作。

github仓库

直接下载最新的 Release就行了。

配置文件在~/.config/clash/config.yaml <--! more -->

配置clash

添加服务

创建一个本地的systemd配置/etc/systemd/system/clash.service

[Unit] Description=clash service After=network.target [Service] Type=simple ExecStart=/usr/local/bin/clash -d /etc/clash/ Restart=on-failure [Install] WantedBy=multi-user.target

systemctl start clash.service systemctl enable clash.service # 然后测试下 socks 代理是否可用 curl --socks5 localhost:7891 google.com

配置文件

说明

clash里面有内置的dns,如果直接用那么大可不必开启内置的dns服务器,但是想用旁路网关,那么需要开启内置的dns。内置的dns服务器有redir-hostfake-ip两种模式:

  • redir-host对于转发过来的请求,一律先用nameserverfallback里面的dns服务器进行解析,如果是外国的地址,那么后续就用fallback里的dns服务器,如果是国内的那就直连。

  • fake-ip不管啥请求,先返回一个虚拟的ip,因为如果是代理,那么是代理服务器进行的远端解析,比redir-host节约一些开销。

  • 只要用了旁路网关,那就得把客户机的dns服务器也设置成clash的dns服务,因为clash需要用dns服务反推域名和ip的对应关系。

  • 可能我说的不清楚,我也理解的不太对,但是我在实际使用中发现,如果我把clash用做旁路网关,并且设置了fake-ip,那么我ping一个网址,或者wget下载一个东西,都直接对假ip进行连接了,换句话说除了浏览器之外别的服务不对劲了。所以旁路网关还是用redir-host模式吧,然后客户机的网关和dns都指向clash的主机,这样可以保证服务都没问题,udp的也ok。

所以我的解决方案就是:PVE里一个LXC容器里装Clash另一个装AdGuardHome,然后Clash里开启dns服务器,选择redir-host模式,不用fallback,就一个nameserver指向我的AdGuardHome。在AdGuardHome里,把dns设置成:

https://doh.pub/dns-query https://dns.alidns.com/dns-query

这两个都是支持DoH/DoT的,可以防止dns污染,这样所有的dns上游都是AdGuardHome了,可以用来防广告,就是不能根据客户端做单独的服务屏蔽了(这个我还没有好办法),但是我用iKuai做管控,所以没啥影响。

配置参考 配置完毕后就能用socks代理或者http代理直接用了,但是想要实现旁路网关,还需要设置转发。

设置旁路网关

参考:

旁路网关自身流量最好别走透明代理,为了实现旁路网关,我们需要转发流量,可以用iptalbes或者nftables,我用的后者而且测试ok,前者没试过.

nftables方案

  1. apt install nftables -y

  2. 创建私有地址定义文件/etc/nftables/private.nft(私有地址咱们不转发):

define private_list = { 0.0.0.0/8, 10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16, 224.0.0.0/4, 240.0.0.0/4 }

  1. 修改配置文件/etc/nftables.conf

#!/usr/sbin/nft -f include "/etc/nftables/private.nft" table ip nat { chain proxy { ip daddr $private_list return ip protocol tcp redirect to :7892 } chain prerouting { type nat hook prerouting priority 0; policy accept; jump proxy } }

  1. sudo sh -c "nft flush ruleset && nft -f /etc/nftables.conf"

设置服务:

systemctl enable nftables.service systemctl start nftables.service

  1. 开启ip转发

echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf sysctl -p

iptables实现

没用过,不保证效果

iptables -t nat -N CLASH # 私有 ip 流量不转发,完整的在下面 # 设置的 fake-ip 请注意检查这里 iptables -t nat -A CLASH -d 192.168.0.0/16 -j RETURN iptables -t nat -A CLASH -p tcp -j REDIRECT --to-ports 7892 iptables -t nat -A PREROUTING -p tcp -j CLASH

# 内部流量不转发给 CLASH 直通 iptables -t nat -A CLASH -d 0.0.0.0/8 -j RETURN iptables -t nat -A CLASH -d 10.0.0.0/8 -j RETURN iptables -t nat -A CLASH -d 127.0.0.0/8 -j RETURN iptables -t nat -A CLASH -d 169.254.0.0/16 -j RETURN iptables -t nat -A CLASH -d 172.16.0.0/12 -j RETURN iptables -t nat -A CLASH -d 192.168.0.0/16 -j RETURN iptables -t nat -A CLASH -d 224.0.0.0/4 -j RETURN iptables -t nat -A CLASH -d 240.0.0.0/4 -j RETURN

然后就是规则持久化,百度就行了。

留坑

这个nftables里面写的规则好像不包括udp协议,如果我想让clash接管udp流量,比如我p2p下载也想走代理,怎么搞……有空研究吧,我感觉我得多了解一下相关知识了。

更多参考

DNS污染对Clash(for Windows)的影响

使用 KoolClash 作为代理网关

在 Ubuntu18.04 上使用 clash 部署旁路代理网关(透明代理)

V2Ray 做透明代理

debian10 使用 nftables 替换 iptables

懒人规则合集

SS-Rule_Snippet

更新

我是基于懒人规则合集中例子配置的,最后我想配合adguardhome进行,所以我弄了俩,一个负责nameserver,里面都是国内的上游DoH和DoT,然后另一个负责fallback里面都是国外的。然后关闭fallback-filter,具体可以看我的另一片文章。