<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Fanx's Blog</title>
        <link>https://rushb.pro/</link>
        <description>记录一些有趣的 Moments</description>
        <lastBuildDate>Fri, 14 Aug 2026 02:40:52 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>zh-CN</language>
        <copyright>All rights reserved 2026, Fanx</copyright>
        <item>
            <title><![CDATA[软路由与 DNS 折腾笔记]]></title>
            <link>https://rushb.pro/article/router-dns</link>
            <guid>https://rushb.pro/article/router-dns</guid>
            <pubDate>Sat, 08 Apr 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[生命不息，折腾不止]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2f00209195a6801eb6eddde21a95d89b"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680629598f69eadab70ef" data-id="2f00209195a680629598f69eadab70ef"><span><div id="2f00209195a680629598f69eadab70ef" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680629598f69eadab70ef" title="前言"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>前言</b></span></span></h2><div class="notion-text notion-block-2f00209195a680bfa4b0fe6b4c41f28d">在几年前玩过软路由，配置是 J4125，当时觉得 OpenWrt 过于难配置、很多 Package 必须在编译的时候加上，当时是直接装了 Ubuntu 拨号，iptables 做 NAT 转发，再用 Docker 起一些服务，也够用，但是后来换了 AX3600 以后，就不想折腾送给朋友了。</div><div class="notion-text notion-block-2f00209195a6805f8724dc299c06e9cc">随着使用 NAS、Xbox、Apple TV 等对网络需求的日益提高，以及 ShellClash 的内存泄露和 AX3600 连开个源都要耍猴等诸多问题，去年中旬购入了一台畅网 N5105，从 OpenWrt 到 ESXI 到 PVE、再到编译固件、云编译、折腾 DNS，过程很有意思，也很久没写博客了，就记录一下。</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a68083b2f6f0a56144fb61" data-id="2f00209195a68083b2f6f0a56144fb61"><span><div id="2f00209195a68083b2f6f0a56144fb61" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68083b2f6f0a56144fb61" title="2024-05-12 更新："><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>2024-05-12 更新：</b></span></span></h2><div class="notion-text notion-block-2f00209195a680539304f88a08089ca7">更换 MosDNS 为 SmartDNS</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680019036eb6ebae6d3fb" data-id="2f00209195a680019036eb6ebae6d3fb"><span><div id="2f00209195a680019036eb6ebae6d3fb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680019036eb6ebae6d3fb" title="0x00 初见"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>0x00 初见</b></span></span></h2><div class="notion-text notion-block-2f00209195a6800baf66d8bc1a75cd7e">和大多数初次接触软路由的小白一样，用 U 盘安装 PE 以 img 写盘的方式写恩山上的镜像，问题在于：</div><ul class="notion-list notion-list-disc notion-block-2f00209195a680878af5c64b97e2d8fe"><li>硬件 OpenWrt 太浪费，另外很多小众功能在这种嵌入式系统中支持不友好。</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a680a9a56cd76866b539c3"><li>要什么软件包只能看作者有没有编译好，没有的话自己装有很多编译时就要加上的内核级依赖，安装时必出错。</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6805eb9e3cba89fe5a6c7"><li>一大堆功能自己用不上。</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6803da6c7cea6364056b0"><li>折腾完后再做改动可能出问题，一出问题又要重装重新配置。</li></ul><div class="notion-text notion-block-2f00209195a6807aa685d46c106597d9">那有没有一种方案可以解决这些问题，还能什么都能跑，又能随时恢复呢？</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680c692baced4b040eedf" data-id="2f00209195a680c692baced4b040eedf"><span><div id="2f00209195a680c692baced4b040eedf" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680c692baced4b040eedf" title="0x01 虚拟化"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>0x01 虚拟化</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680e3bfbacc0bbfb8f115" data-id="2f00209195a680e3bfbacc0bbfb8f115"><span><div id="2f00209195a680e3bfbacc0bbfb8f115" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680e3bfbacc0bbfb8f115" title="ESXI"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>ESXI</b></span></span></h3><div class="notion-text notion-block-2f00209195a680cfbb65f6b8ceaa87d4">中间学习编译固件和配置直通等基础操作也没什么讲的，网络上太多相关资料了，这里就不多说了。</div><div class="notion-text notion-block-2f00209195a68046bf27df79b2a25500">ESXI 解决了我几大问题：</div><ul class="notion-list notion-list-disc notion-block-2f00209195a680889b12fd57a3fc0842"><li>OpenWrt 系统只要 1 核 1G 内存就够用了，不浪费硬件，甚至对于不在 OpenWrt 上跑 Docker 的来说，1G 内存都是奢侈。资源得到了极大的节省。</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a68025b2fbe0b0c5431ff6"><li>虚拟机可以随时备份，不用担心出问题了重装，还可以随时恢复。</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a680b1881ccf5cd58de82c"><li>OpenWrt 跑不了的，或者不想破环 OpenWrt 系统环境，可以创建另外的虚拟机。</li></ul><div class="notion-text notion-block-2f00209195a68074992fe8b197432de3">已经很理想了对吧，直到家里断了一次电，ESXI 老牛拉破车般的启动速度也就不说了，甚至还把 OpenWrt 的虚拟磁盘搞挂了，顺便再记录一下修复命令吧：</div><div class="notion-text notion-block-2f00209195a680649424d35a39c11a9b">很幸运，这次只是小问题，但是在找解决方法的过程中，发现了还有人甚至 vmdk 都消失了。</div><div class="notion-text notion-block-2f00209195a6805aab59dd6f4c0f89c3">另外在 ESXI 中再启动其它虚拟机，如果运行时间比较长还有几率出现虚拟机内磁盘消失的情况，可能 N5105 对于企业级的平台来说还是太弱了，所以也就放弃了 ESXI。</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680c2a45ed5902a1a05c5" data-id="2f00209195a680c2a45ed5902a1a05c5"><span><div id="2f00209195a680c2a45ed5902a1a05c5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680c2a45ed5902a1a05c5" title="PVE"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>PVE</b></span></span></h3><div class="notion-text notion-block-2f00209195a680f09dc1cd91c8eb4879">直到遇见了 PVE，底层 Debian、LXC 模板一键部署虚拟机、惊人的启动速度、热修改虚拟机硬件配置，确实很强大</div><div class="notion-text notion-block-2f00209195a680b8880ef6ec87c43ce0">目前来说 PVE 使用上方便、稳定，暂时没有出现任何问题，最主要的就是不要什么东西都在 PVE 上跑，用 LXC 快速部署一台 Linux，用完就删，稳定性也非常好，温度表现上也比 ESXI 好太多。</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680dab6b7d3a4c00e7cd9"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/8c4bccb0-9041-4e42-b396-cfe5f2ed8787/image.png?table=block&amp;id=2f102091-95a6-80da-b6b7-d3a4c00e7cd9&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=0A6HJKDUTLisk6m91rUkm8-R9yCvVIcoEfrkmya4FCg&amp;t=2f102091-95a6-80da-b6b7-d3a4c00e7cd9" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a6804bbfd8c7cef133d7d5">至此，PVE 成为了我的主力虚拟化平台，接下来就是 OpenWrt 上令人头疼的 DNS 了。</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680239e83f8661e90f26c" data-id="2f00209195a680239e83f8661e90f26c"><span><div id="2f00209195a680239e83f8661e90f26c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680239e83f8661e90f26c" title="0x02 DNS"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>0x02 DNS</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680dab768e440c2890c31" data-id="2f00209195a680dab768e440c2890c31"><span><div id="2f00209195a680dab768e440c2890c31" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680dab768e440c2890c31" title="OpenClash 内置分流"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>OpenClash 内置分流</b></span></span></h3><div class="notion-text notion-block-2f00209195a68065a3a5ff0124f1ba5d">OpenClash 写好规则可以达到较为理想的分流效果，但是如果要加入去广告等功能，规则可能达到几万条，这在 PC 平台可能没什么问题，但是我一向习惯于统一管理，手机、路由器等设备都用同一份规则，不仅仅是路由器平台的处理效率低下，而且 iOS 对于 APP 的内存限制非常严格，并且 iOS 平台 stash 的处理性能也十分有限，于是使用了 AdGuardHome</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680a5a231f0224d8e3174" data-id="2f00209195a680a5a231f0224d8e3174"><span><div id="2f00209195a680a5a231f0224d8e3174" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680a5a231f0224d8e3174" title="AdGuardHome"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>AdGuardHome</b></span></span></h3><div class="notion-text notion-block-2f00209195a6807fb475dbd039669a1e">流程图：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a68026a53fdf7694d4afe1"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/62107bc1-51f9-446a-a157-3c1e5ea4dbe5/image.png?table=block&amp;id=2f102091-95a6-8026-a53f-df7694d4afe1&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=E_bQMpMp80NPWbtsDjw6e-YKUELBCdDJiRj5CoX1cig&amp;t=2f102091-95a6-8026-a53f-df7694d4afe1" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a680fd8a92e2f5ebd3ad74">似乎也很完美，但是不管是只使用 OpenClash 还是搭配 AdGuardHome，在使用过程中发现了两个问题：</div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-2f00209195a6808b8b74c34dbab358e9" data-id="2f00209195a6808b8b74c34dbab358e9"><span><div id="2f00209195a6808b8b74c34dbab358e9" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6808b8b74c34dbab358e9" title="1. 国际厂商 DNS 分流"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>1. 国际厂商 DNS 分流</b></span></span></h4><div class="notion-text notion-block-2f00209195a680b3abf4d87f1b32e103">例如 Apple、Microsoft，这两大厂商在大陆有 CDN 但是部分服务只有国外 IP，由于运营商优化了这一点使得不同地区解析到的 IP 虽然是国外的，但基本上是最优的（排除某些地区或某些运营商的垃圾 DNS 和线路）</div><div class="notion-text notion-block-2f00209195a680518a69edfd6fc6113d">那就出现了一个问题：</div><div class="notion-text notion-block-2f00209195a68097a59cdabfff4f4654">通常 Apple、Microsoft 服务是选直连，但是会触发 FallBack,使得请求变得非常慢，例如：</div><ul class="notion-list notion-list-disc notion-block-2f00209195a680d1a084fc2da4d71ca4"><li>外区 APP Store/Apple Music 中，部分国区没有的 APP/音乐，大陆的 CDN 中没有此资源，会导致请求变得非常慢，甚至下载失败。</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a680e7bf69c4b0f754a10d"><li>iOS 网络检测域名：<code class="notion-inline-code">captive.apple.com</code>，大陆的 CDN 中没有此资源，被 Fallback 到直连很差的 IP，导致网络检测失败，弹窗提示无法连接到互联网，Windows 网络检测域名：<code class="notion-inline-code">www.msftncsi.com</code> 也偶现此问题，但 Azure 线路比较好，出现的概率比 iOS 小很多。</li></ul><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-2f00209195a6805d8512d55306ff6c61" data-id="2f00209195a6805d8512d55306ff6c61"><span><div id="2f00209195a6805d8512d55306ff6c61" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6805d8512d55306ff6c61" title="2. 猝不及防的 iOS 16 DNS 安全更新"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>2. 猝不及防的 iOS 16 DNS 安全更新</b></span></span></h4><div class="notion-text notion-block-2f00209195a680e28b33f9c2eb35771e">如果说 OpenClash 启用 <code class="notion-inline-code">绕过中国大陆 IP</code>，再让 Microsoft、Apple 的域名走代理，那么有大陆 CDN 有资源的会直接直连，否则走代理，这样似乎又完美解决了，直到 iOS 16 的正式版发布，Apple 宣布了 DNS 安全更新：</div><blockquote class="notion-quote notion-block-2f00209195a68017a699e14a92dfe114"><div>如果您的网络支持发现指定解析器（也称为 DDR ），则 DNS 查询将自动使用 TLS 或 HTTPS。要使用加密的 DNS，您的设备需要知道解析器支持 TLS 或 HTTPS，并且可能还需要学习端口或 URL 路径。诸如 DHCP 或路由器播发等常见机制仅提供普通 IP 地址。DDR 是 Apple 与其他行业合作伙伴在 IETF 中开发的一种新协议。</div></blockquote><div class="notion-text notion-block-2f00209195a6801aaed3e88c243efb33">截止至写本文时（2023-04-09），AdGuardHome 对此支持仍不完善，导致 iOS 16 设备解析缓慢，甚至无法解析，日志中也有一大堆 SERVFAIL，Github 中也有人提出了这个问题，但是官方给出的解决方案与版本更新仍然不完美，即使使用了上面说的 <code class="notion-inline-code">绕过中国大陆 IP</code> &amp; <code class="notion-inline-code">Microsoft</code> 、<code class="notion-inline-code">Apple</code> 走代理，也会出现 DNS 解析缓慢的问题，并且还带来一个问题，如果节点不稳定或直接挂了，那 iOS 设备直接判断无网，导致频繁弹窗，或触发<a class="notion-link" href="https://support.apple.com/zh-cn/HT205296" target="_blank" rel="noopener noreferrer">无线局域网助理</a>功能，这样虽然 Wi-Fi 是已连接的状态，但是实际走的是蜂窝网络。</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680cfa907e39bec042707" data-id="2f00209195a680cfa907e39bec042707"><span><div id="2f00209195a680cfa907e39bec042707" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680cfa907e39bec042707" title="MosDNS"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>MosDNS</b></span></span></h3><div class="notion-text notion-block-2f00209195a680bdaf5cfb8cf8a9d025">综上所述，目前看来需要一个这样的 DNS 服务器：</div><ul class="notion-list notion-list-disc notion-block-2f00209195a6800ab80cebe4d9482ccd"><li>支持国际厂商 DNS 分流</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a68010b6cedd55d415f6ae"><li>支持 iOS 16 安全 DNS</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a68083b0f7cbd2562330cb"><li>支持去广告</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a68070b886f141ab6c6279"><li>支持 DNS 缓存</li></ul><div class="notion-text notion-block-2f00209195a680fab41ac4b22dc6da6c">于是找到了 MosDNS，目前来看是最完美的解决方案，它支持 DNS 缓存、DNSSEC、DOH/DOT 等功能，iOS 16 也完美支持，而且还支持域名分流。</div><blockquote class="notion-quote notion-block-2f00209195a680f28c1cfc79279fed60"><div>微软某些服务会验证返回 IP 真实性（Xbox 居多，例如微软模拟飞行），如果你出现了某些服务无法访问，除了真的可能是连接问题，还有可能是 DNS 验证失败，这时候你可以尝试检查一下你的 DNS 服务器是否支持 EDNS 和 DNSSEC。</div></blockquote><div class="notion-text notion-block-2f00209195a68095ac6ae4858f475cf9">流程图：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680d1bf1cd724a0cf43f8"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/98a3de55-79b8-472e-898d-cb865e518d0c/image.png?table=block&amp;id=2f102091-95a6-80d1-bf1c-d724a0cf43f8&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=24Xcw6fTRFkZPc0d6Og8UOQt5mdrGiThdCo3-tjx-IY&amp;t=2f102091-95a6-80d1-bf1c-d724a0cf43f8" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a680e78f2dd9e5c0a7ede6">对于我来说 MosDNS 内置的配置文件已经非常完善，只需要手动勾选 <code class="notion-inline-code">TCP/DoT 连接复用</code> 和 <code class="notion-inline-code">启用 EDNS 客户端子网</code> 完成功能性问题即可，并且内置了去广告规则，但是目前来看去广告需求不是那么大了，DNS 层只能去广告域名，还有很大一部分网站还是会通过 URL 的方式加载，所以我还是使用了浏览器插件的方式去广告</div><blockquote class="notion-quote notion-block-2f00209195a680b8bd8ac70a08899980"><div>MosDNS 设置远程 DNS 必须使用 DoT，如果你使用的是 DoH，那么 Bootstrap 最好也使用国外的，因为如果是大陆的 DNS 服务作为 Bootstrap，那么对于节点来说可能并不是最快的 IP，这样会影响本就不快的 Fallback 速度，如果使用的是 DoT，由于不需要被 Bootstrap 解析，所以可以被节点连接查询 IP，在 Clash 控制面板中也能看到 Process 为 MosDNS，对节点来说能拿到最快的 IP。</div></blockquote><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6805bae02f155a7f2c7c7" data-id="2f00209195a6805bae02f155a7f2c7c7"><span><div id="2f00209195a6805bae02f155a7f2c7c7" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6805bae02f155a7f2c7c7" title="SmartDNS"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>SmartDNS</b></span></span></h3><div class="notion-text notion-block-3bb0209195a68061a0a0f6d180057b80">在一段时间的使用下来，发现连接一些国内的网站并不能优选，且运营商 DNS 解析到的 IP 有时不是最优</div><div class="notion-text notion-block-3bb0209195a6801e81dacd2ddd81b963">为了更好的网络体验，调研一番以后，决定使用 SmartDNS + OpenClash 这样的组合</div><div class="notion-text notion-block-3bb0209195a680fd9c4ceb8f86646cb4">并且通过 OpenClash 分流国内外 DNS 查询</div><div class="notion-text notion-block-3bb0209195a6808d9bade6d456e2f00f">SmartDNS 服务使用的端口为：6053</div><div class="notion-text notion-block-3bb0209195a6800f86c0ca566d0c66cb">第二 DNS 服务器端口为：6153</div><div class="notion-text notion-block-3bb0209195a68070b659e0acbbefb5ed">流程图：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a680c29df6c8c93a5dea7b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/78838b09-6639-45ef-afbc-439e979f7967/image.png?table=block&amp;id=3bb02091-95a6-80c2-9df6-c8c93a5dea7b&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=ZdFUTdW8LAMXzF3-uMQ59fHOgEIU9-YDrH8XF2SlTYs&amp;t=3bb02091-95a6-80c2-9df6-c8c93a5dea7b" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-3bb0209195a680f684cac4d931975727">之前 ImmortalWrt 默认配置了 SmartDNS 的第二服务器，但是在最新的版本中已经删除了，所以我们需要手动配置一下</div><blockquote class="notion-quote notion-block-3bb0209195a680e5844ae0974d7fdb54"><div>已删除: <a class="notion-link" href="https://github.com/immortalwrt/packages/commit/f187ad1d5d5e86f37760631aef764c4f05dc709f" target="_blank" rel="noopener noreferrer">https://github.com/immortalwrt/packages/commit/f187ad1d5d5e86f37760631aef764c4f05dc709f</a></div></blockquote><div class="notion-text notion-block-3bb0209195a6804899eadb79239c2d58">首先设置好第二 DNS 服务器的端口和组名，我这里设置为 <code class="notion-inline-code">6153</code> 和 <code class="notion-inline-code">Global</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a680448e9dff8629a30b6a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/e2b036fc-d9b4-49c5-a070-92c456a888ad/image.png?table=block&amp;id=3bb02091-95a6-8044-8e9d-ff8629a30b6a&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=CtyJpx_Fi0h3d8Wpun0NPjyA5GFJy1o5fetn3mqkD2M&amp;t=3bb02091-95a6-8044-8e9d-ff8629a30b6a" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-3bb0209195a680f8b49be62494973912">然后在 <code class="notion-inline-code">高级设置</code> 里选择 <code class="notion-inline-code">测速模式</code> 为 <code class="notion-inline-code">tcp-syn:443,tcp-syn:80,ping</code>, 这样可以选择日常访问时最快的 IP 地址，再删除 <code class="notion-inline-code">域名TTL</code> 的默认值，默认 3600 太长了，删除后会使用上游 DNS 的 TTL，最小 TTL 我设置成了 3 秒（默认 600 秒），因为某些视频网站的 PCDN 的域名 TTL 可能会很短，所以设置成 3 秒，这样可以避免 DNS 缓存导致访问缓慢，，附上我的配置截图:</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a68087ae0fcf126cdf432b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:320px"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/c6d36aa0-bb08-4566-9442-b3325d68df10/68352593-800d-4124-a5fc-c06f5b9b7817.png?table=block&amp;id=3bb02091-95a6-8087-ae0f-cf126cdf432b&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=mcGOhlNA1AOOwaQOzowNekzYHuDYTwR3CNQc1xf3E2c&amp;t=3bb02091-95a6-8087-ae0f-cf126cdf432b" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a68038be73e2549ce43251"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:661.984375px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/70f77239-b6c7-49b5-9f67-efc8e928bf69/image.png?table=block&amp;id=3bb02091-95a6-8038-be73-e2549ce43251&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=CDadmxPNireJu9-XI0JDBBqRQIbGlJ9caRYvzgMfhAk&amp;t=3bb02091-95a6-8038-be73-e2549ce43251" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a6802e96d7f25a39b978fc"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:678.984375px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/956c6f73-ab69-429a-b541-195a69a3411a/image.png?table=block&amp;id=3bb02091-95a6-802e-96d7-f25a39b978fc&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=w0WzG_SoCcDrkSHNe9hS7vYAQB5zTrFhEAMSfQnC5gI&amp;t=3bb02091-95a6-802e-96d7-f25a39b978fc" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-3bb0209195a6802c9e1eff23cdb8f5fc">常规设置：（不勾选 <code class="notion-inline-code">自动设置 Dnsmasq</code>）（打码部分为运营商 DNS）：</div><blockquote class="notion-quote notion-block-3bb0209195a68017af2bd400eb4fba11"><div>你也可以填写你喜欢的国内公共 DNS 服务商</div></blockquote><div class="notion-text notion-block-3bb0209195a6801a9828dbb0d43fa441">注意这里的 DNS 配置最好填写 DOT，因为不需要额外 Bootstrap 解析和协议开销，国外组的服务器组名填写 <code class="notion-inline-code">Global</code>（和上一步设置的一样），另外在配置 <code class="notion-inline-code">Global</code> 组 DNS 服务器时，记得勾选 <code class="notion-inline-code">从默认组中排除</code>，以免影响到国内组解析</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a680009198e7c053e60c03"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/e7c23d72-4cf7-4d1f-ba2c-e19a2401ae46/image.png?table=block&amp;id=3bb02091-95a6-8000-9198-e7c053e60c03&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=A7U0zzConQoEIC8tf5AK8kBPYvcnMy1CxgVyznbZTTE&amp;t=3bb02091-95a6-8000-9198-e7c053e60c03" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a6809ab9f4f67fad2ba8af"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/1a7a1c8b-cd1c-44f9-86cf-b8860e0eb5dd/image.png?table=block&amp;id=3bb02091-95a6-809a-b9f4-f67fad2ba8af&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=tOhIKVXTeO_V85gPWGU9WicKdD62bt7CkLWF7rWLr6c&amp;t=3bb02091-95a6-809a-b9f4-f67fad2ba8af" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a680178abefe7602a52ca3">OpenClash 配置：</div><blockquote class="notion-quote notion-block-2f00209195a680779f5eeb74ea960362"><div>由于 Fallback 即将被弃用，我们将使用 nameserver-policy 来分流 DNS，达到 DNS 分流和防泄露的效果</div></blockquote><div class="notion-text notion-block-2f00209195a6804e92d1d6cef271d3f4">勾选 <code class="notion-inline-code">自定义上游 DNS 服务器</code></div><div class="notion-text notion-block-2f00209195a6802e8c05ebd0295f0e9e">不勾选 <code class="notion-inline-code">追加上游 DNS</code>、<code class="notion-inline-code">追加默认 DNS</code></div><div class="notion-text notion-block-2f00209195a680a7ac92ff9bd552aab6">NameServer 使用 SmartDNS 第二服务器</div><div class="notion-text notion-block-2f00209195a680d1be1bc5aec9349d7e">FallBack 和 Default-NameServer 可不填</div><div class="notion-text notion-block-2f00209195a6806db258ed11e2997b33">OpenClash 集成了 <code class="notion-inline-code">nameserver-policy</code> 的自定义功能，所以我们可以很方便的配置，在自定义选项中加入：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680a4964ed765c4811ae0"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/fe109caf-2add-46e4-951a-b7929dcc8bed/image.png?table=block&amp;id=2f102091-95a6-80a4-964e-d765c4811ae0&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=E0au4yLR5eh5AYBai3t6jnp2MWMpnp-hVN9XWOoiRRs&amp;t=2f102091-95a6-80a4-964e-d765c4811ae0" alt="notion image" loading="lazy" decoding="async"/></div></figure><blockquote class="notion-quote notion-block-2f00209195a68002ad10c8a0c419b52b"><div>如果你的订阅提供商的节点域名解析比较奇怪，可添加一个 SmartDNS 国内组或是任意你喜欢的国内 DNS 服务器到 <code class="notion-inline-code">default-nameserver</code> 并勾选 <code class="notion-inline-code">节点域名解析</code>
或在配置文件的 DNS 下添加类似下面的选项:</div></blockquote><div class="notion-text notion-block-2f00209195a68031b2b6e7c852e7e5be">以下为示例</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6805983b3d092da4b2469" data-id="2f00209195a6805983b3d092da4b2469"><span><div id="2f00209195a6805983b3d092da4b2469" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6805983b3d092da4b2469" title="为什么不用 fake-ip？"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>为什么不用 fake-ip？</b></span></span></h2><div class="notion-text notion-block-2f00209195a6808d97f3c1d03acdf27e">fake-ip 的优点是可以解决 DNS 污染、响应速度快等，但是缺点也很明显，无法解决国际厂商 DNS 分流，导致国际厂商的服务无法直连，而且也无法解决 iOS 16 的 DNS 问题、DNS 不能缓存、BT 下载无法使用、部分游戏无法连接、加速器的节点全是 1ms 等一大堆兼容性问题，当然这些问题都可以通过 <code class="notion-inline-code">fake-ip-filter</code> 解决，但是这样就失去了 fake-ip 的优点，而且维护起来也很麻烦，所以我还是选择了 redir-host 方案，只要配置正确也不会出现 DNS 污染的问题。</div><div class="notion-text notion-block-2f00209195a680b3b355d7220f050865">虽然 Clash 内核移除了 <code class="notion-inline-code">redir-host</code>，但是 OpenClash 作者在 <code class="notion-inline-code">v0.45.87-beta</code> 版本中解决了这个问题：</div><blockquote class="notion-quote notion-block-2f00209195a680dea0d5c2add63d680c"><div>除 Meta 内核，其他内核的 redir-host 模式均改为使用 fake-ip 进行模拟 （上游内核已移除 redir-host）</div></blockquote><div class="notion-text notion-block-2f00209195a680d08af2eed54793ff4f">所以 OpenClash 还是可以正常使用 redir-host 模式的。</div><div class="notion-text notion-block-2f00209195a680b08f81ecd22fa058d7">另外由于原版内核已停更，现更建议使用 Meta 内核</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6808487f8cad886ad9064" data-id="2f00209195a6808487f8cad886ad9064"><span><div id="2f00209195a6808487f8cad886ad9064" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6808487f8cad886ad9064" title="附：Clash DNS 防泄露最简配置"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>附：Clash DNS 防泄露最简配置</b></span></span></h2><blockquote class="notion-quote notion-block-2f00209195a6809baf78cd61a16a8b5f"><div>nameserver 中 &quot;#节点选择&quot; 这部分修改为你的策略组名称</div></blockquote><div class="notion-blank notion-block-2f00209195a6806099b9e746d902b70d"> </div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[OpenWrt 配置不完全指北]]></title>
            <link>https://rushb.pro/article/openwrt-config</link>
            <guid>https://rushb.pro/article/openwrt-config</guid>
            <pubDate>Fri, 21 Jul 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[基于 PVE + ImmortalWrt 23.05 编写，其他版本可能会有一些差异]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2f00209195a680a4bd48e09a2728de27"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6808280e3e90758350e94" data-id="2f00209195a6808280e3e90758350e94"><span><div id="2f00209195a6808280e3e90758350e94" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6808280e3e90758350e94" title="0x00 前言"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>0x00 前言</b></span></span></h2><div class="notion-text notion-block-2f00209195a680f68b38e60c1c00511d"><b>基于 PVE + ImmortalWrt 23.05 编写，其他版本可能会有一些差异。</b></div><div class="notion-text notion-block-2f00209195a6809eb8c8c8c95a6f9532">功能：路由器作为网关，通过 OpenClash 代理，同时支持 IPv4 和 IPv6，通过 SmartDNS 实现 DNS 分流和优选</div><div class="notion-text notion-block-2f00209195a68002b1f6c73f99b3dbff">关于为什么要使用 SmartDNS，可以参考我的另一篇文章: <a class="notion-link" href="https://rushb.pro/article/router-dns" target="_blank" rel="noopener noreferrer">软路由与 DNS 折腾笔记</a> 。当然如果你嫌麻烦也可以不用 SmartDNS，直接使用 OpenClash 的 DNS 功能。</div><blockquote class="notion-quote notion-block-2f00209195a680b6a925e27bc04ab99c"><div>本配置之所以称为 “指北”，是因为大多数人第一次接触 OpenWrt 时，看见 LuCI Web 界面里的各种配置选项会 “找不着北”，因此这篇文章命名为 《OpenWrt 配置指北》</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680b28c76f00ba8e57bac" data-id="2f00209195a680b28c76f00ba8e57bac"><span><div id="2f00209195a680b28c76f00ba8e57bac" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680b28c76f00ba8e57bac" title="0x01 PVE"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>0x01 PVE</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6807abf2ac0b2663c6b1b" data-id="2f00209195a6807abf2ac0b2663c6b1b"><span><div id="2f00209195a6807abf2ac0b2663c6b1b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6807abf2ac0b2663c6b1b" title="网卡直通"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>网卡直通</b></span></span></h3><div class="notion-text notion-block-2f00209195a68032ad63da9734db87a8">编辑文件: <code class="notion-inline-code">/etc/default/grub</code></div><div class="notion-text notion-block-2f00209195a6800a8c76e6cd46466517">找到以下行:</div><div class="notion-text notion-block-2f00209195a68034ac42e3bd87157b79">修改为</div><blockquote class="notion-quote notion-block-2f00209195a680f0a864c98b40878f88"><div>参考:</div><div class="notion-text notion-block-2f00209195a680dd9031db39fc1d7a87"><a class="notion-link" href="https://github.com/ivanhao/pvetools/issues/34" target="_blank" rel="noopener noreferrer">https://github.com/ivanhao/pvetools/issues/34</a></div></blockquote><div class="notion-text notion-block-2f00209195a680928c01cf3a8b1ecec0">更新 grub</div><div class="notion-text notion-block-2f00209195a680c8ac41f49a5e9515cc">重启</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680ef9783c9f1d68d48c5" data-id="2f00209195a680ef9783c9f1d68d48c5"><span><div id="2f00209195a680ef9783c9f1d68d48c5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680ef9783c9f1d68d48c5" title="常规"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>常规</b></span></span></h3><div class="notion-text notion-block-2f00209195a68093915ee5812a14ad16">只选择一个开机自启动就好</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a6801ab97fc62aa33830d0"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/7bb01ee7-7599-4549-b06c-53ae90920666/image.png?table=block&amp;id=2f102091-95a6-801a-b97f-c62aa33830d0&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=beSMZRs_BGSRMCtm73Qb_Fm07mpb6boyNPgQ04C0Cag&amp;t=2f102091-95a6-801a-b97f-c62aa33830d0" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680beadf6e8903d814777" data-id="2f00209195a680beadf6e8903d814777"><span><div id="2f00209195a680beadf6e8903d814777" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680beadf6e8903d814777" title="操作系统"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>操作系统</b></span></span></h3><div class="notion-text notion-block-2f00209195a6804f9ad3d4de54dac408">选择 <code class="notion-inline-code">不使用任何介质</code>，因为我们要导入 OpenWrt 直接作为磁盘</div><div class="notion-text notion-block-2f00209195a680afb969d93420f314b2">右边操作系统选择 <code class="notion-inline-code">Linux 6.x - 2.6 Kernel</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a6800fa4aad6802b250588"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/ed283b9c-9628-4f33-af1c-8a68a82d6646/image.png?table=block&amp;id=2f102091-95a6-800f-a4aa-d6802b250588&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=i__LdN4YnjPmIu-YuDhNWDwK4H84V6bNJ_pYwJrqLek&amp;t=2f102091-95a6-800f-a4aa-d6802b250588" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6804489acf2491a72ca98" data-id="2f00209195a6804489acf2491a72ca98"><span><div id="2f00209195a6804489acf2491a72ca98" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6804489acf2491a72ca98" title="系统"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>系统</b></span></span></h3><div class="notion-text notion-block-2f00209195a680078c3cdc75cd8b24f1">机型选择可选<code class="notion-inline-code">q35</code>和<code class="notion-inline-code">i440fx</code>，q35 更新一点，我更建议使用 q35</div><div class="notion-text notion-block-2f00209195a680b3bc0cda05dbfbf2a3">如果你使用的固件文件名中带有 <code class="notion-inline-code">combined-efi</code>，那么:</div><div class="notion-text notion-block-2f00209195a68062b875fb4f0d784de3">BIOS 选择 <code class="notion-inline-code">OVFM (UEFI)</code>，下面 <code class="notion-inline-code">添加 UEFI 磁盘</code> 取消勾选，因为 UEFI 分区已经在 OpenWrt 的磁盘中了, 但是在虚拟机启动时会有一条警告: <code class="notion-inline-code">WARN: no efidisk configured! Using temporary efivars disk.</code>，因为我们没有添加一块 UEFI 磁盘到虚拟机中，这是正常的，不影响使用。</div><div class="notion-text notion-block-2f00209195a680f2bfe1c218484e490e">如果固件中带有 <code class="notion-inline-code">qemu-ga</code>，那么勾选 <code class="notion-inline-code">Qemu 代理</code> (此软件包类似于 VMware Tools，可以实现虚拟机与宿主机的交互，例如关机、重启、获取 IP 等)</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680c9aab7c1fce03bebcb"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/4b06e7ce-8f78-4544-9a1b-75ffe0a70997/image.png?table=block&amp;id=2f102091-95a6-80c9-aab7-c1fce03bebcb&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=FrgaPy3J3zG_xU3DlXvpfZwXZ-MIBt_ommbn25aziM8&amp;t=2f102091-95a6-80c9-aab7-c1fce03bebcb" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6803ea728e7db682ccf8d" data-id="2f00209195a6803ea728e7db682ccf8d"><span><div id="2f00209195a6803ea728e7db682ccf8d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6803ea728e7db682ccf8d" title="磁盘"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>磁盘</b></span></span></h3><div class="notion-text notion-block-2f00209195a680e39330cca7fd5ec3e4">删除默认的磁盘，直接点击下一步，待会创建虚拟机后再导入 OpenWrt 磁盘</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680eeb5fcdd077fcd9bf0" data-id="2f00209195a680eeb5fcdd077fcd9bf0"><span><div id="2f00209195a680eeb5fcdd077fcd9bf0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680eeb5fcdd077fcd9bf0" title="CPU"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>CPU</b></span></span></h3><div class="notion-text notion-block-2f00209195a6804c9cd4c516d80eabd3">通俗的来讲，插槽就是 CPU 的数量，核心就是每个 CPU 的核心数，这里根据自己的需求选择，类别选择 <code class="notion-inline-code">host</code>，这样可以让虚拟机直接使用宿主机的 CPU，并且支持 CPU 的所有特性。</div><div class="notion-text notion-block-2f00209195a6800984b6c4a62bd53829">如果你使用的 CPU 性能比较差，可以增加这台虚拟机的 CPU 权重，这样当宿主机 CPU 负载比较高时，这台虚拟机会优先分配 CPU 资源。</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680eb901ec40d9676d693"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/808cdc2f-ffa0-4b20-9e38-6744bb0ccbaf/image.png?table=block&amp;id=2f102091-95a6-80eb-901e-c40d9676d693&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=WiyBFKf0RfL6AXrCKcVKuSGQb_K4QCZ0M8-Laiu_7II&amp;t=2f102091-95a6-80eb-901e-c40d9676d693" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680ea8196c7ab73d5eae9" data-id="2f00209195a680ea8196c7ab73d5eae9"><span><div id="2f00209195a680ea8196c7ab73d5eae9" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680ea8196c7ab73d5eae9" title="内存"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>内存</b></span></span></h3><div class="notion-text notion-block-2f00209195a680379990e10b5ad4529c">根据自己的需求选择</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680b8ade4da1001602326" data-id="2f00209195a680b8ade4da1001602326"><span><div id="2f00209195a680b8ade4da1001602326" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680b8ade4da1001602326" title="网络"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>网络</b></span></span></h3><div class="notion-text notion-block-2f00209195a680a59de0d2e40d8797b4">默认的虚拟网卡留着就行，不要删除，后面用于访问 PVE 管理界面</div><div class="notion-text notion-block-2f00209195a68054b7d1c980a563ebc7">创建完成后不要启动虚拟机，我们还要导入 OpenWrt 磁盘</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6802b901de0368f6a5ad5" data-id="2f00209195a6802b901de0368f6a5ad5"><span><div id="2f00209195a6802b901de0368f6a5ad5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6802b901de0368f6a5ad5" title="导入 OpenWrt 磁盘"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>导入 OpenWrt 磁盘</b></span></span></h3><div class="notion-text notion-block-2f00209195a680d6beefc7e8deb62175">注意：我这里使用的是 <code class="notion-inline-code">qcow2</code> 格式的磁盘，如果你使用的是 <code class="notion-inline-code">vmdk</code> 或 <code class="notion-inline-code">img</code> 格式的磁盘，请自行在网络上搜索如何导入，这里不再赘述。</div><div class="notion-text notion-block-2f00209195a68037a3bcc9991e52718a">使用 <code class="notion-inline-code">qm importdisk</code> 命令导入磁盘:</div><div class="notion-text notion-block-2f00209195a680a49fa2f00873e88024"><code class="notion-inline-code">100</code> 是虚拟机的 ID，<code class="notion-inline-code">/path/to/immortalwrt-x86-64-generic-squashfs-combined-efi.qcow2</code> 是 OpenWrt 的磁盘路径，<code class="notion-inline-code">local</code> 是 PVE 的存储空间，默认是 <code class="notion-inline-code">local-lvm</code>，如果你使用的是其他存储空间，请自行替换。(我合并了 <code class="notion-inline-code">local</code> 和 <code class="notion-inline-code">local-lvm</code>，所以我这里使用的是 <code class="notion-inline-code">local</code>，如果你也想整合自己的磁盘空间，也可以研究一下，这里不过多赘述)</div><div class="notion-text notion-block-2f00209195a680ecbeb4fbe010f87b9a">导入完成以后，在虚拟机的 <code class="notion-inline-code">硬件</code> 选项卡中，可以发现多了一块 <code class="notion-inline-code">未使用的磁盘</code>，我们选中它，点击 <code class="notion-inline-code">编辑</code>，然后在 <code class="notion-inline-code">总线/设备</code> 中选择 <code class="notion-inline-code">SATA</code>，如果你使用的是 <code class="notion-inline-code">SSD</code> 则可以进一步勾选 <code class="notion-inline-code">SSD 仿真</code>，这样可以提高性能。</div><div class="notion-text notion-block-2f00209195a6808eaeefd64de21dbbfe">导入完成后可以删除刚刚上传的磁盘文件，因为已经导入到 PVE 的存储空间中了。</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680a4b342ee1b5413bf5c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/790b1b8f-11ab-42e8-ad65-f336fc84c269/image.png?table=block&amp;id=2f102091-95a6-80a4-b342-ee1b5413bf5c&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=w5H2_swTcNUnerizrfF2bVSYuYfbpDshLVJAdxa0qGU&amp;t=2f102091-95a6-80a4-b342-ee1b5413bf5c" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680cabafcca38d1784981" data-id="2f00209195a680cabafcca38d1784981"><span><div id="2f00209195a680cabafcca38d1784981" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680cabafcca38d1784981" title="添加硬件直通的网卡"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>添加硬件直通的网卡</b></span></span></h3><div class="notion-text notion-block-2f00209195a680df94b8d469bc99b6bc">在虚拟机的 <code class="notion-inline-code">硬件</code> 选项卡中，点击 <code class="notion-inline-code">添加</code>，选择 <code class="notion-inline-code">PCI 设备</code>，然后选择你要直通的网卡。</div><blockquote class="notion-quote notion-block-2f00209195a68057b822df8c9fe4a639"><div>不要勾选所有功能</div></blockquote><div class="notion-text notion-block-2f00209195a6803bad76cefc01fbc26f">现在虚拟机有两种网卡，一种是显示为 <code class="notion-inline-code">网络设备 (net0)</code> 的虚拟网卡，用于访问 PVE 管理界面，另一种是显示为 <code class="notion-inline-code">PCI 设备 (net1)</code> 的直通网卡，用于 OpenWrt 直通硬件网卡作为 WAN 和 LAN 使用。</div><div class="notion-text notion-block-2f00209195a68054a7eee66344ecf966">OpenWrt 中的网络结构如下:</div><ul class="notion-list notion-list-disc notion-block-2f00209195a680a8b71ee854a182a8b8"><li>eth0: 虚拟网卡，用于访问 PVE 管理界面</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a68077a512f5bf7102188d"><li>eth1: 直通网卡，用于 WAN</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6802b883ac66ad53a3ac8"><li>eth2 - ethx: 直通网卡，用于 LAN</li></ul><blockquote class="notion-quote notion-block-2f00209195a680a3b3eed0c72d0ea447"><div>OpenWrt 中的网卡配置会在此文中的下半部分提及</div></blockquote><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a68072be91d7d3fd799265" data-id="2f00209195a68072be91d7d3fd799265"><span><div id="2f00209195a68072be91d7d3fd799265" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68072be91d7d3fd799265" title="设置开机引导"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>设置开机引导</b></span></span></h3><div class="notion-text notion-block-2f00209195a68065b25ee5ccb9393d8b">在虚拟机的 <code class="notion-inline-code">选项</code> 选项卡中，选中 <code class="notion-inline-code">引导顺序</code> 并编辑，启用刚刚导入的 OpenWrt 磁盘，如果有其它磁盘或设备被勾选可以取消勾选</div><div class="notion-text notion-block-2f00209195a68087b14adeec75915f7e">这样就完成了 OpenWrt 的安装，现在可以启动虚拟机了</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6800192afc0b76aa644bb" data-id="2f00209195a6800192afc0b76aa644bb"><span><div id="2f00209195a6800192afc0b76aa644bb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6800192afc0b76aa644bb" title="0x02 OpenWrt"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>0x02 OpenWrt</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680529feacc5a48708e97" data-id="2f00209195a680529feacc5a48708e97"><span><div id="2f00209195a680529feacc5a48708e97" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680529feacc5a48708e97" title="网络配置"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>网络配置</b></span></span></h3><div class="notion-text notion-block-2f00209195a680d299f9f7227fcc50ce">默认有一个 <code class="notion-inline-code">WAN6</code> 网卡，将其删除，以免干扰后面的配置</div><div class="notion-text notion-block-2f00209195a6807f886fdc9d21f4b4bc">在 <code class="notion-inline-code">全局网络选项</code> 中，将 <code class="notion-inline-code">IPv6 ULA 前缀</code> 删除。</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6805292eef0527d88ded8" data-id="2f00209195a6805292eef0527d88ded8"><span><div id="2f00209195a6805292eef0527d88ded8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6805292eef0527d88ded8" title="WAN"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>WAN</b></span></span></h3><div class="notion-text notion-block-2f00209195a6806fae9dc241c932de83">协议选择 <code class="notion-inline-code">PPPoE</code>,填写你的宽带账号和密码即可，<code class="notion-inline-code">高级设置</code> 中的 <code class="notion-inline-code">获取 IPv6 地址</code> 选择自动，勾选 <code class="notion-inline-code">使用默认网关</code> 和 <code class="notion-inline-code">委托 IPv6 前缀</code>; <code class="notion-inline-code">IPV6 分配长度</code> 选择 <code class="notion-inline-code">已禁用</code></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6807d9a14d73f29c0342b" data-id="2f00209195a6807d9a14d73f29c0342b"><span><div id="2f00209195a6807d9a14d73f29c0342b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6807d9a14d73f29c0342b" title="LAN"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>LAN</b></span></span></h3><div class="notion-text notion-block-2f00209195a680c1a796cf1531e0e653">首先在 <code class="notion-inline-code">设备</code> 中，配置设备 <code class="notion-inline-code">br-lan</code>，网桥端口选择希望作为 LAN 口的网口，上面提到的用于 LAN 的直通网卡和 eth0 虚拟网卡在这里可以全部勾选</div><div class="notion-text notion-block-2f00209195a680e6b319e2f773baab9a">在 <code class="notion-inline-code">高级设置</code> 中，<code class="notion-inline-code">IPV6 分配长度</code> 选择 <code class="notion-inline-code">64</code>，<code class="notion-inline-code">IPv6 后缀</code> 填写 <code class="notion-inline-code">eui64</code></div><div class="notion-text notion-block-2f00209195a680dbb07afe4ef4a1d03b">在 <code class="notion-inline-code">DHCP 服务器</code> -&gt; <code class="notion-inline-code">IPv6设置</code> 中，<code class="notion-inline-code">RA 服务</code> 选择 <code class="notion-inline-code">服务器模式</code>，禁用 <code class="notion-inline-code">DHCPv6 服务</code> 和 <code class="notion-inline-code">NDP 代理</code> 还有 <code class="notion-inline-code">本地 IPV6 DNS 服务器</code> (IPV4 的 DNS 服务器地址可以提供 AAAA 解析，而且运营商给的 IPV6 前缀变化时，会有一小部分时间路由器的 IPV6 地址变化，而客户端没有及时更新，所以这里干脆禁用 IPV6 DNS 服务器地址，A 解析和 AAAA 解析都通过 IPV4 DNS 服务器地址解析)，<code class="notion-inline-code">IPV6 RA 设置</code> 中，<code class="notion-inline-code">默认路由器</code> 选择 <code class="notion-inline-code">在可用的前缀上</code>，勾选 <code class="notion-inline-code">启用 SLAAC</code>，取消勾选 <code class="notion-inline-code">RA标记</code> 中的所有选项</div><blockquote class="notion-quote notion-block-2f00209195a680a2a664f353633bb96e"><div>注意: <code class="notion-inline-code">RA 服务</code> 和 <code class="notion-inline-code">DHCPv6 服务</code> 以及 <code class="notion-inline-code">NDP 代理</code> 这三个选项在更新 OpenWrt 后可能会自动启用，所以每次更新后都务必检查一下。</div></blockquote><div class="notion-text notion-block-2f00209195a6809ea281cb7e760615a1">详细设置如图:</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a68089b8e6f8317c6979e2"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/d573f0b5-bec8-4d08-b86e-75c9b3a32b33/image.png?table=block&amp;id=2f102091-95a6-8089-b8e6-f8317c6979e2&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=-ham1minfLV9twGddtl6SpL7q4Dp1Z4QkDRdpnVfiwU&amp;t=2f102091-95a6-8089-b8e6-f8317c6979e2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a6804d818cd2152c1f36ea">另外如果想访问光猫，可以添加一个新接口，名称随意，协议选择 <code class="notion-inline-code">DHCP 客户端</code> 或自行配置静态 IP，设备选择连接光猫的网口，然后在编辑接口 -&gt; <code class="notion-inline-code">高级配置</code> 中，取消勾选 <code class="notion-inline-code">使用默认网关</code>，配置 <code class="notion-inline-code">使用网关跃点</code> 为 <code class="notion-inline-code">99</code>，在 <code class="notion-inline-code">防火墙设置</code> 选项卡中，<code class="notion-inline-code">创建/分配防火墙区域</code> 选择 <code class="notion-inline-code">WAN</code>，这样就可以访问光猫了。</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6808ba424f31b3f54dcb1" data-id="2f00209195a6808ba424f31b3f54dcb1"><span><div id="2f00209195a6808ba424f31b3f54dcb1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6808ba424f31b3f54dcb1" title="DNS"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>DNS</b></span></span></h3><div class="notion-text notion-block-2f00209195a6801fbcffead140994cc1">在 <code class="notion-inline-code">网络</code> -&gt; <code class="notion-inline-code">DHCP/DNS</code> 的 <code class="notion-inline-code">过滤器</code> 选项中，取消勾选 <code class="notion-inline-code">重绑定保护</code> 和 <code class="notion-inline-code">禁止解析 IPv6 DNS 记录</code>，这样解析到内网的域名和 AAAA 记录可以被正常解析</div><div class="notion-text notion-block-2f00209195a6808091b2cbafa13ae3a0">例如 <code class="notion-inline-code">www.example.com</code> 解析到 <code class="notion-inline-code">192.168.1.254</code>，我们在内网可以通过域名正常访问</div><div class="notion-text notion-block-2f00209195a680eab7e2d08e921fb3f3">另外在 <code class="notion-inline-code">限制</code> 选项中，删除默认的 <code class="notion-inline-code">最小缓存 TTL</code> （默认为60， 部分固件会存在一个 3600 的默认选项，所以要把 DNS 最小 TTL 设置项删除）</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6807ea91eedee6d3bf721" data-id="2f00209195a6807ea91eedee6d3bf721"><span><div id="2f00209195a6807ea91eedee6d3bf721" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6807ea91eedee6d3bf721" title="SmartDNS"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>SmartDNS</b></span></span></h2><div class="notion-text notion-block-2f00209195a6803e835bd173a1027396">在一段时间的使用下来，发现连接一些国内的网站并不能优选，且运营商 DNS 解析到的 IP 有时不是最优</div><div class="notion-text notion-block-2f00209195a68043a098ef306542885d">为了更好的网络体验，调研一番以后，决定使用 SmartDNS + OpenClash 这样的组合</div><div class="notion-text notion-block-2f00209195a680759766ee4ee57c5a06">并且通过 OpenClash 分流国内外 DNS 查询</div><div class="notion-text notion-block-2f00209195a680e9af52cd4a9ac8e67a">SmartDNS 服务使用的端口为：6053</div><div class="notion-text notion-block-2f00209195a68047bdbfe90501028f90">第二 DNS 服务器端口为：6153</div><div class="notion-text notion-block-2f00209195a6809ea74ff552efb4e39a">流程图：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a6801da5e6e03c064a4676"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/78838b09-6639-45ef-afbc-439e979f7967/image.png?table=block&amp;id=2f102091-95a6-801d-a5e6-e03c064a4676&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=tCRaLTdg8H6uklUnsQxuP748wyO4UUyF5R3sQyQOtKw&amp;t=2f102091-95a6-801d-a5e6-e03c064a4676" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a6801d8a2cee699839d9f5">之前 ImmortalWrt 默认配置了 SmartDNS 的第二服务器，但是在最新的版本中已经删除了，所以我们需要手动配置一下</div><blockquote class="notion-quote notion-block-2f00209195a6800eb538db301659e29a"><div>已删除: <a class="notion-link" href="https://github.com/immortalwrt/packages/commit/f187ad1d5d5e86f37760631aef764c4f05dc709f" target="_blank" rel="noopener noreferrer">https://github.com/immortalwrt/packages/commit/f187ad1d5d5e86f37760631aef764c4f05dc709f</a></div></blockquote><div class="notion-text notion-block-2f00209195a680b58312ec6a86cf83ac">首先设置好第二 DNS 服务器的端口和组名，我这里设置为 <code class="notion-inline-code">6153</code> 和 <code class="notion-inline-code">Global</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680c49301c4aad08d3566"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/e2b036fc-d9b4-49c5-a070-92c456a888ad/image.png?table=block&amp;id=2f102091-95a6-80c4-9301-c4aad08d3566&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=kGMG0FJ0ulBCA_qaUSkTjt45aBInknm5hULkCFM7pe4&amp;t=2f102091-95a6-80c4-9301-c4aad08d3566" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a68085977cedf145212a34">然后在 <code class="notion-inline-code">高级设置</code> 里选择 <code class="notion-inline-code">测速模式</code> 为 <code class="notion-inline-code">tcp-syn:443,tcp-syn:80,ping</code>, 这样可以选择日常访问时最快的 IP 地址，再删除 <code class="notion-inline-code">域名TTL</code> 的默认值，默认 3600 太长了，删除后会使用上游 DNS 的 TTL，最小 TTL 我设置成了 3 秒（默认 600 秒），因为某些视频网站的 PCDN 的域名 TTL 可能会很短，所以设置成 3 秒，这样可以避免 DNS 缓存导致访问缓慢，，附上我的配置截图:</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a6805f841ffde269c27145"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:320px"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/c6d36aa0-bb08-4566-9442-b3325d68df10/68352593-800d-4124-a5fc-c06f5b9b7817.png?table=block&amp;id=3bb02091-95a6-805f-841f-fde269c27145&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=7JXM_KOAvdDYfK7_ZZdL9d_Mr-WrTs-saJDRXW_ZYy4&amp;t=3bb02091-95a6-805f-841f-fde269c27145" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a68097a8f6d39aa516879a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:661.984375px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/70f77239-b6c7-49b5-9f67-efc8e928bf69/image.png?table=block&amp;id=3bb02091-95a6-8097-a8f6-d39aa516879a&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=VVbDPwxd_xuH2XZXSIxBU4ZkLIvxJ3M847klUOvNlS0&amp;t=3bb02091-95a6-8097-a8f6-d39aa516879a" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a6807db4c8d47e94a43e1a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:678.984375px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/956c6f73-ab69-429a-b541-195a69a3411a/image.png?table=block&amp;id=3bb02091-95a6-807d-b4c8-d47e94a43e1a&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=75IxbuxMKFwbeIXiKvByMvDaZJ9adTbfg2iWnWHKwuA&amp;t=3bb02091-95a6-807d-b4c8-d47e94a43e1a" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a680c6aa39c07a3a8a208d">常规设置：（不勾选 <code class="notion-inline-code">自动设置 Dnsmasq</code>）（打码部分为运营商 DNS）：</div><blockquote class="notion-quote notion-block-2f00209195a6802282d2fcfc8969782d"><div>你也可以填写你喜欢的国内公共 DNS 服务商</div></blockquote><div class="notion-text notion-block-2f00209195a68097864cc41750996022">注意这里的 DNS 配置最好填写 DOT，因为不需要额外 Bootstrap 解析和协议开销，国外组的服务器组名填写 <code class="notion-inline-code">Global</code>（和上一步设置的一样），另外在配置 <code class="notion-inline-code">Global</code> 组 DNS 服务器时，记得勾选 <code class="notion-inline-code">从默认组中排除</code>，以免影响到国内组解析</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a68037a945c0dc3d72882d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/e7c23d72-4cf7-4d1f-ba2c-e19a2401ae46/image.png?table=block&amp;id=3bb02091-95a6-8037-a945-c0dc3d72882d&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=QpLGiskZtYeZpMCvluC5bckgqaVcu1G5IIRwkH4XGRU&amp;t=3bb02091-95a6-8037-a945-c0dc3d72882d" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3bb0209195a6806c873cfef3769eec43"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/1a7a1c8b-cd1c-44f9-86cf-b8860e0eb5dd/image.png?table=block&amp;id=3bb02091-95a6-806c-873c-fef3769eec43&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=4CypHW2IVAZxa1sJDxrSojIbGvBFOaXy2rTFtLbmiwo&amp;t=3bb02091-95a6-806c-873c-fef3769eec43" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680a18bb8fedebc56c3e0" data-id="2f00209195a680a18bb8fedebc56c3e0"><span><div id="2f00209195a680a18bb8fedebc56c3e0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680a18bb8fedebc56c3e0" title="OpenClash"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>OpenClash</b></span></span></h2><div class="notion-text notion-block-2f00209195a680248521d8541ac6b646">这里的配置比较多且复杂，有几个常见的 Q&amp;A：</div><div class="notion-text notion-block-2f00209195a68007b327cde71ba38e5b"><b>Q: 节点不支持 UDP 代理，勾选 </b><code class="notion-inline-code"><b>UDP 流量转发</b></code><b> 有什么用？</b></div><div class="notion-text notion-block-2f00209195a68057be3fed9e6c979812">A: 启用 <code class="notion-inline-code">UDP 流量转发</code> 只是为了让 OpenClash 支持 UDP，如果节点不支持 UDP 代理，那么 UDP 流量会自动被节点 Block，不会影响使用，但是有一些海外的游戏可能会无法连接，你可能需要使用支持 UDP 代理的节点，但游戏加速我更推荐使用加速器。</div><div class="notion-text notion-block-2f00209195a68025a27cc81aef5ca320"><b>Q: 为什么要勾选 </b><code class="notion-inline-code"><b>绕过中国大陆 IP</b></code><b>?</b></div><div class="notion-text notion-block-2f00209195a6805e875cf2b9d505b0b7">A: 如果不勾选，国内的流量也会走 Clash 内核进行直连，虽然不会影响使用，但是会降低一点性能，缺点就是关于国内网站的分流会不起作用，比如分流 bilibili 番剧到 HK，在进入 Clash 内核前就被判断为中国大陆 IP，所以不会走代理，关于这种特殊情况你可以考虑不使用此选项。</div><div class="notion-text notion-block-2f00209195a680dba877db0552230980"><b>Q: 节点不支持 IPv6，勾选 </b><code class="notion-inline-code"><b>IPv6流量代理</b></code><b> 有什么用？</b></div><div class="notion-text notion-block-2f00209195a68073b6e0de847f166fbf">A: 如果你的网络环境支持 IPv6，那么可以勾选 <code class="notion-inline-code">IPv6流量代理</code>，这样 OpenClash 会将 IPv6 流量代理到节点，如果节点不支持 IPv6，那么会自动切换为 IPv4 代理，不会影响使用，并且由于勾选了 <code class="notion-inline-code">绕过中国大陆 IPv6</code>，所以国内 IPv6 流量不会受到影响。如果你的网络环境支持 IPv6，并且你没有勾选 <code class="notion-inline-code">IPv6流量代理</code>，那部分海外网站会直接通过 IPv6 访问，可能会影响到你的网络冲浪；如果你对访问中国大陆的 IPv6 网站没有需求，你可以考虑禁止 IPv6 的解析，同时不勾选 <code class="notion-inline-code">IPv6流量代理</code>，这样既不会影响到 BT 连接 IPv6 下载，也不会影响你 IPv4 的网络冲浪。</div><div class="notion-text notion-block-2f00209195a68085a8ffd6a5478ca275"><b>Q: 为什么我使用 </b><b><a class="notion-link" href="https://test-ipv6.com/" target="_blank" rel="noopener noreferrer">https://test-ipv6.com</a></b><b> 检测我不支持 IPv6？</b></div><div class="notion-text notion-block-2f00209195a680f281a4ebf07a7a3742">A: 和上面的问题一样，由于 test-ipv6.com 是海外网站，你的节点如果不支持 IPv6，那么会自动切换为 IPv4 代理，所以 test-ipv6.com 检测不到你的 IPv6 地址，你可以使用以下位于中国大陆的 IPv6 测试网站:</div><ul class="notion-list notion-list-disc notion-block-2f00209195a680c580c6eb34dd04a01b"><li><a class="notion-link" href="https://testipv6.cn/" target="_blank" rel="noopener noreferrer">https://testipv6.cn</a></li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6802c911ccbccb3931c7f"><li><a class="notion-link" href="https://ipw.cn/" target="_blank" rel="noopener noreferrer">https://ipw.cn</a></li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6804592a2f844a26a5c03"><li><a class="notion-link" href="https://test6.ustc.edu.cn/" target="_blank" rel="noopener noreferrer">https://test6.ustc.edu.cn</a></li></ul><div class="notion-text notion-block-2f00209195a680e3bfedfb96d2e2fb5b"><b>Q: 为什么我的 Instagram/YouTube 客户端 无法加载 / 访问很慢？</b></div><div class="notion-text notion-block-2f00209195a680c48c2ccb18db262311">A: 确保勾选了 <code class="notion-inline-code">禁用 QUIC</code>，如果 Instagram 还是无法加载，说明 Instagram 已经将 QUIC 的相关域名或连接资源缓存到了本地，可以尝试卸载重装 (Meta 系的 APP 基本都有这个问题，尽量避免在裸连环境下打开 Instagram)</div><div class="notion-text notion-block-2f00209195a680a8bfd4fc083acfa828"><b>Q: 为什么 Microsoft Copilot in Bing 无法使用？</b></div><div class="notion-text notion-block-2f00209195a6805f83a1cc726402ed22">A: 因为 Microsoft 域名默认解析是国内 IP，且 GeoSite 为 CN，默认会绕过内核，可通过配置 <code class="notion-inline-code">绕过中国大陆 IPv4 黑名单</code> 和 <code class="notion-inline-code">绕过中国大陆 IPv6 黑名单</code> 加入域名: <code class="notion-inline-code">bing.com</code> 解决</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680e5b3f7f3cbf9349d2a" data-id="2f00209195a680e5b3f7f3cbf9349d2a"><span><div id="2f00209195a680e5b3f7f3cbf9349d2a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680e5b3f7f3cbf9349d2a" title="插件设置 - 模式设置"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>插件设置 - 模式设置</b></span></span></h3><div class="notion-text notion-block-2f00209195a68056aabadae63490bd68">勾选 <code class="notion-inline-code">使用 Meta 内核</code> （原版内核已停更）</div><div class="notion-text notion-block-2f00209195a680cf94b2f3dbf8d97eb6">运行模式中，Redir-Host 的兼容模式和混合模式根据自己的网络环境选择</div><div class="notion-text notion-block-2f00209195a6809c88c0f24cc8b5274e">如果你选择的是兼容模式，勾选 <code class="notion-inline-code">UDP 流量转发</code></div><blockquote class="notion-quote notion-block-2f00209195a680c399fad206614d80e9"><div>我更推荐使用兼容模式，为了避免一些意想不到的 bug</div></blockquote><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680808175eba5dae78124" data-id="2f00209195a680808175eba5dae78124"><span><div id="2f00209195a680808175eba5dae78124" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680808175eba5dae78124" title="插件设置 - 流量控制"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>插件设置 - 流量控制</b></span></span></h3><div class="notion-text notion-block-2f00209195a6803981f0d5f9a4237d85">勾选 <code class="notion-inline-code">禁用 QUIC</code>、<code class="notion-inline-code">绕过中国大陆 IP</code>，<code class="notion-inline-code">仅允许常用端口</code> 选择 <code class="notion-inline-code">默认常用端口</code></div><div class="notion-text notion-block-2f00209195a680b79c2ee3918bf94c87">如果你希望通过 OpenClash 代理内网设备的 Apple 推送通知服务（APNs）流量，可以选择以下任一方式：</div><ol start="1" class="notion-list notion-list-numbered notion-block-2f00209195a680edbde1dd142ba94b59" style="list-style-type:decimal"><li>将 OpenClash 更新至 <b>v0.47.133</b> 或更高版本。从该版本开始，<code class="notion-inline-code">默认常用端口</code> 已包含 APNs 所需的 <code class="notion-inline-code">2197</code> 和 <code class="notion-inline-code">5223</code> 端口</li></ol><ol start="2" class="notion-list notion-list-numbered notion-block-2f00209195a68072ba25f2a7dc280e29" style="list-style-type:decimal"><li>如果暂时不想更新 OpenClash，可以在 <code class="notion-inline-code">仅允许常用端口流量</code> 的端口列表中手动加入 <code class="notion-inline-code">2197</code> 和 <code class="notion-inline-code">5223</code>：</li></ol><div class="notion-text notion-block-3780209195a6802fa5ecfa4414db8970"><a class="notion-link" href="https://support.apple.com/zh-cn/101555" target="_blank" rel="noopener noreferrer">https://support.apple.com/zh-cn/101555</a></div><div class="notion-text notion-block-3780209195a6804e9cc7e26cc8c56fc7">以上列表整合了 OpenClash 的默认常用端口，以及 Apple 推送通知服务所需的端口</div><blockquote class="notion-quote notion-block-35b0209195a680acbd88f3d3e9618c88"><div>参考链接: <a class="notion-link" href="https://github.com/vernesong/OpenClash/blob/master/luci-app-openclash/luasrc/model/cbi/openclash/settings.lua#L492" target="_blank" rel="noopener noreferrer">https://github.com/vernesong/OpenClash/blob/master/luci-app-openclash/luasrc/model/cbi/openclash/settings.lua#L492</a></div></blockquote><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a68054a703f80baed94fe1" data-id="2f00209195a68054a703f80baed94fe1"><span><div id="2f00209195a68054a703f80baed94fe1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68054a703f80baed94fe1" title="插件设置 - DNS 设置"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>插件设置 - DNS 设置</b></span></span></h3><div class="notion-text notion-block-2f00209195a680498714e057de711df3"><code class="notion-inline-code">本地 DNS 劫持</code> 选择 <code class="notion-inline-code">使用 Dnsmasq 转发</code></div><div class="notion-text notion-block-2f00209195a680738931c984818324bd">勾选 <code class="notion-inline-code">禁止 Dnsmasq 缓存 DNS</code></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a68057bb7bdd5178322a8c" data-id="2f00209195a68057bb7bdd5178322a8c"><span><div id="2f00209195a68057bb7bdd5178322a8c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68057bb7bdd5178322a8c" title="插件设置 - IPv6 设置"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>插件设置 - IPv6 设置</b></span></span></h3><div class="notion-text notion-block-2f00209195a6808abf94d2400a1c5e2c">勾选 <code class="notion-inline-code">IPv6流量代理</code>、<code class="notion-inline-code">UDP 流量转发</code>、<code class="notion-inline-code">允许 IPv6 类型 DNS 解析</code>、<code class="notion-inline-code">绕过中国大陆 IPv6</code></div><div class="notion-text notion-block-2f00209195a680cfa74eec4aa5e8b9bb"><code class="notion-inline-code">IPv6代理模式</code> 选择 <code class="notion-inline-code">TProxy 模式</code></div><div class="notion-text notion-block-2f00209195a6809c9690c78ca355707d"><code class="notion-inline-code">GEO 数据库订阅</code>、<code class="notion-inline-code">大陆白名单订阅</code> 选择一个自己喜欢的时间自动更新</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6809c9480c0537d5a5020" data-id="2f00209195a6809c9480c0537d5a5020"><span><div id="2f00209195a6809c9480c0537d5a5020" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6809c9480c0537d5a5020" title="覆写设置 - DNS 设置"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>覆写设置 - DNS 设置</b></span></span></h3><blockquote class="notion-quote notion-block-2f00209195a68080aa52e7f2042f4574"><div>由于 Fallback 即将被弃用，我们将使用 nameserver-policy 来分流 DNS，达到 DNS 分流和防泄露的效果</div></blockquote><div class="notion-text notion-block-2f00209195a680e7a030c9e0ab08afa7">勾选 <code class="notion-inline-code">自定义上游 DNS 服务器</code></div><div class="notion-text notion-block-2f00209195a68086b990eb6b5048fd58">不勾选 <code class="notion-inline-code">追加上游 DNS</code>、<code class="notion-inline-code">追加默认 DNS</code></div><div class="notion-text notion-block-2f00209195a68007b1def9c37f0074d2">NameServer 使用 SmartDNS 第二服务器</div><div class="notion-text notion-block-2f00209195a680b1a193f0bbf2851a76">FallBack 和 Default-NameServer 可不填</div><div class="notion-text notion-block-2f00209195a680debc0de1f33cbf0002">OpenClash 集成了 <code class="notion-inline-code">nameserver-policy</code> 的自定义功能，所以我们可以很方便的配置，在自定义选项中加入：</div><div class="notion-text notion-block-2f00209195a680618431d558aaff20c9">OpenClash 集成了 <code class="notion-inline-code">nameserver-policy</code> 的自定义功能，所以我们可以很方便的配置，在自定义选项中加入：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a6807fa8edef277e522ff5"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/d3bf1450-238b-4803-b199-38ecd1adcbb4/image.png?table=block&amp;id=2f102091-95a6-807f-a8ed-ef277e522ff5&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=IrPQQDB00_CkoXpOzTUBJPfi3aUKWJdfULZ9AYqglFE&amp;t=2f102091-95a6-807f-a8ed-ef277e522ff5" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a680fcae79d5c096f5676f">这样，SmartDNS 就会接管所有的 DNS 请求，也就做到了 DNS 分流和优选解析的目的。</div><div class="notion-text notion-block-2f00209195a6801c8272e1d610eb682a">至此，OpenClash 已经配置完成，在配置订阅里添加自己的订阅链接并更新订阅就能正常使用了。</div><blockquote class="notion-quote notion-block-2f00209195a68026a7f2f6a0ecc8fe6e"><div>注意: OpenClash 在更新系统后不会自动启动，需要手动启动一次。
如果你的订阅提供商的节点域名解析比较奇怪，可添加一个 SmartDNS 国内组或是任意你喜欢的国内 DNS 服务器到 <code class="notion-inline-code">default-nameserver</code> 并勾选 <code class="notion-inline-code">节点域名解析</code>
或在配置文件的 DNS 下添加类似下面的选项:</div></blockquote><div class="notion-text notion-block-2f00209195a6804baeb6ff40822cc6cb">以下为示例：</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680919a1ee0161ae08359" data-id="2f00209195a680919a1ee0161ae08359"><span><div id="2f00209195a680919a1ee0161ae08359" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680919a1ee0161ae08359" title="UPnP"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>UPnP</b></span></span></h2><div class="notion-text notion-block-2f00209195a6800ab1f2f209be51fd82">由于 OpenWrt 现已使用 nftables 作为默认防火墙，如果你没有公网 IPv4 地址，启用 UPnP 有一定的可能性会无法自动配置端口映射，可以在 UPnP 的高级设置选项卡中，启用 <code class="notion-inline-code">使用 STUN</code> 碰碰运气，如果还是无法自动配置端口映射，那么只能在防火墙中手动设置端口映射了。</div><div class="notion-text notion-block-2f00209195a68019936ed94987bf1b05">常用的国内 STUN 服务器:</div><ul class="notion-list notion-list-disc notion-block-2f00209195a6808ab90ffdb3197ba047"><li>stun.qq.com</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6802fb958f17365f5cef4"><li>stun.miwifi.com</li></ul><blockquote class="notion-quote notion-block-2f00209195a68006bc18f2082ed99519"><div>端口均为 3478</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6806f8d87fbd7c75a2137" data-id="2f00209195a6806f8d87fbd7c75a2137"><span><div id="2f00209195a6806f8d87fbd7c75a2137" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6806f8d87fbd7c75a2137" title="关于 BBR"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>关于 BBR</b></span></span></h2><div class="notion-text notion-block-2f00209195a680a59a95e9c75bd873c0">开启 BBR 可能会导致长连接挂掉，可能会让你的网络体验变差，所以不推荐开启或是在编译中启用，家用路由不像 VPS，不需要考虑 TCP 的拥塞控制。</div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[解决软路由环境中 Safari 无法通过 Cloudflare 人机验证]]></title>
            <link>https://rushb.pro/article/openclash-cloudflare_challenges</link>
            <guid>https://rushb.pro/article/openclash-cloudflare_challenges</guid>
            <pubDate>Sun, 19 Nov 2023 00:00:00 GMT</pubDate>
            <description><![CDATA[一个完美耦合的 bug]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2f00209195a6808b9f5cc64eaa7b567a"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680098361f116f98e2d3f" data-id="2f00209195a680098361f116f98e2d3f"><span><div id="2f00209195a680098361f116f98e2d3f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680098361f116f98e2d3f" title="原因"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>原因</b></span></span></h2><div class="notion-text notion-block-2f00209195a68093ad54cd5d64aeee08">在 iOS 15 和 macOS Ventura 中，新增了一个功能：<a class="notion-link" href="https://support.apple.com/zh-cn/102022" target="_blank" rel="noopener noreferrer">限制 IP 地址跟踪</a></div><div class="notion-text notion-block-2f00209195a6804a9918cfa6dd96e579">而这个功能虽然在中国大陆无法完整使用，但是能使用部分功能（对网站跟踪器隐藏 IP 地址） 这就使得在非 Cloudflare 的第三方网站中的人机验证器 (域名：challenges.cloudflare.com) 被识别为跟踪器，而在 OpenClash 中，为了防止 YouTube 等使用 QUIC 导致速度不佳，通常会 <code class="notion-inline-code">禁用 QUIC</code>，而恰好 <a class="notion-link" href="https://developer.apple.com/cn/support/prepare-your-network-for-icloud-private-relay" target="_blank" rel="noopener noreferrer">iCloud 专用代理使用了 QUIC</a></div><blockquote class="notion-quote notion-block-2f00209195a68032a1bec1f0692beae9"><div>iCloud 专用代理使用 QUIC，这是一种基于 UDP 的全新标准传输协议。专用代理中的 QUIC 连接需要使用端口 443 和 TLS 1.3 建立，因此请确保你的网络和服务器已准备好处理此类连接。</div></blockquote><div class="notion-text notion-block-2f00209195a680bf8a72d5f1c0248356">一个完美耦合的 bug 就这样出现了:</div><blockquote class="notion-quote notion-block-2f00209195a680518854ced925f69257"><div>访问带有 Cloudflare 人机验证的网站 --&gt; Safari 判断 <code class="notion-inline-code">challenges.cloudflare.com</code> 为跟踪器，使用 <code class="notion-inline-code">iCloud Private Relay</code> 连接此域名 --&gt; OpenClash 配置的防火墙规则禁止 QUIC 连接</div></blockquote><div class="notion-text notion-block-2f00209195a68076a723f6635d6db52a">导致人机验证卡在 “正在验证” 状态:</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680bfaf07c8d337e3070f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:635.9921875px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/8fdaa408-de8e-4804-b911-fe57e95aada4/image.png?table=block&amp;id=2f102091-95a6-80bf-af07-c8d337e3070f&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=CxZWdsvrErw3NTpyx3_LUqQQsO_KBXIvLZsGOyVmvaE&amp;t=2f102091-95a6-80bf-af07-c8d337e3070f" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a68044acbbdf90f293b84c" data-id="2f00209195a68044acbbdf90f293b84c"><span><div id="2f00209195a68044acbbdf90f293b84c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68044acbbdf90f293b84c" title="解决"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>解决</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6807dac14d3e9e73c10af" data-id="2f00209195a6807dac14d3e9e73c10af"><span><div id="2f00209195a6807dac14d3e9e73c10af" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6807dac14d3e9e73c10af" title="方法一"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>方法一</b></span></span></h3><div class="notion-text notion-block-2f00209195a68000a48ee59032b7e0eb">在 无线局域网 设置中，关闭 <code class="notion-inline-code">限制 IP 地址跟踪</code> 功能</div><ul class="notion-list notion-list-disc notion-block-2f00209195a68001a631eff5a2873251"><li>缺点: 无法使用自带邮件 APP 和 Safari 对于跟踪器和广告收集器的隐藏 IP 地址功能</li></ul><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680eaaec1fc7b13383779"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/2fe04e8b-9f28-4289-a50e-5f8047a5a422/image.png?table=block&amp;id=2f102091-95a6-80ea-aec1-fc7b13383779&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=Dt-Jla929D47Ok6sloq-drGBJz7Kf2pveTEcdTBs8Ow&amp;t=2f102091-95a6-80ea-aec1-fc7b13383779" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a68069b4c4c8e77b4e44ad" data-id="2f00209195a68069b4c4c8e77b4e44ad"><span><div id="2f00209195a68069b4c4c8e77b4e44ad" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68069b4c4c8e77b4e44ad" title="方法二"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>方法二</b></span></span></h3><div class="notion-text notion-block-2f00209195a68053b15dff5607fa6f8e">关闭 Safari 浏览器的 <code class="notion-inline-code">隐藏 IP 地址</code> 功能</div><ul class="notion-list notion-list-disc notion-block-2f00209195a680879dc1fe50a85d3db4"><li>缺点: 无法对于其它跟踪器和广告收集器隐藏 IP 地址</li></ul><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680438babfa1fcd0633f7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/69b28350-9a8e-48de-8517-99af1857d2cf/image.png?table=block&amp;id=2f102091-95a6-8043-8bab-fa1fcd0633f7&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=mxnv0kcs6a_3IRqBEPiF7kuAxNwpr7nuSsjo43bfFW4&amp;t=2f102091-95a6-8043-8bab-fa1fcd0633f7" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6809baa85fa0e881d9df2" data-id="2f00209195a6809baa85fa0e881d9df2"><span><div id="2f00209195a6809baa85fa0e881d9df2" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6809baa85fa0e881d9df2" title="方法三"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>方法三</b></span></span></h3><div class="notion-text notion-block-2f00209195a680ee8268f08df256f894">在 dnsmasq 中添加以下域名到 IPSet <code class="notion-inline-code">china_ip_route</code> 和 <code class="notion-inline-code">china_ip6_route</code> 中:</div><blockquote class="notion-quote notion-block-2f00209195a680d29a75c92fe76fc5e2"><div>域名来源:</div><div class="notion-text notion-block-2f00209195a6801199e6df47b82a76a9"><a class="notion-link" href="https://developer.apple.com/cn/support/prepare-your-network-for-icloud-private-relay" target="_blank" rel="noopener noreferrer">为 iCloud 专用代理准备网络或网页服务器 - Apple Developer</a></div></blockquote><div class="notion-text notion-block-2f00209195a68011bbb0d9a2c8d61558">原理:</div><div class="notion-text notion-block-2f00209195a6806ab8e0c786ea94e1c5">让 iCloud Private Relay 的流量不经过内核直连，这样能让它们正常使用 QUIC 连接，也不会影响到禁用其它网站的 QUIC</div><blockquote class="notion-quote notion-block-2f00209195a680c0aba0fa164d9da30a"><div>OpenClash 的 <code class="notion-inline-code">本地 IPv4 绕过地址</code> 设置中只能添加 IP/IP-CIDR，不支持域名，所以要通过 dnsmasq 设置</div></blockquote><div class="notion-text notion-block-2f00209195a680e28805e50df46f2188">在 OpenWrt 的 <code class="notion-inline-code">网络</code> --&gt; <code class="notion-inline-code">DHCP/DNS</code> --&gt; 中的 <code class="notion-inline-code">IP 集合</code> 中，添加域名:</div><div class="notion-text notion-block-2f00209195a680b1a61bec36f38a6ee3">到</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680028d0cffab529ed5be"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/4d6b1e71-5bc6-45a5-9b5d-77c496e51945/image.png?table=block&amp;id=2f102091-95a6-8002-8d0c-ffab529ed5be&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=Kw6mzy7o1_78u9bhoULQdeoAni8htk3gYkChpLW3Xss&amp;t=2f102091-95a6-8002-8d0c-ffab529ed5be" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680f1867cf6844cff78ff"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/6c3f21ab-beee-4913-987e-24912985e2fa/image.png?table=block&amp;id=2f102091-95a6-80f1-867c-f6844cff78ff&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=CFPp3o7plf5iKOrfu26QUk1A2daHCGYD1ZcJly4rDf4&amp;t=2f102091-95a6-80f1-867c-f6844cff78ff" alt="notion image" loading="lazy" decoding="async"/></div></figure></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Magisk 搭配 UnblockNeteaseMusic 无感知解锁网易云音乐客户端变灰歌曲]]></title>
            <link>https://rushb.pro/article/Magisk-ub</link>
            <guid>https://rushb.pro/article/Magisk-ub</guid>
            <pubDate>Sat, 14 Mar 2020 00:00:00 GMT</pubDate>
            <description><![CDATA[有国内服务器并且手机 root 了的话不妨来试试看？]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2f00209195a680d6a0f8dfbe969c44ba"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a6808e812ddd040ee53716" data-id="2f00209195a6808e812ddd040ee53716"><span><div id="2f00209195a6808e812ddd040ee53716" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6808e812ddd040ee53716" title="前言"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>前言</b></span></span></h2><div class="notion-text notion-block-2f00209195a680e5b3e4dc0db8acf865">这次使用的是服务端部署 UnblockNeteaseMusic + 本地 iptables 转发流量的实现方法。</div><div class="notion-text notion-block-2f00209195a68041b0b6f72f558def9b">原理上来讲是可以做到本地部署的，这样的话可以做到无成本，因为空余时间没那么多，就没去研究。</div><div class="notion-text notion-block-2f00209195a680eda4c3dd501b787f30">具体可以参考 <a class="notion-link" href="https://github.com/Flysky12138/UnblockNeteaseMusic-Android" target="_blank" rel="noopener noreferrer">https://github.com/Flysky12138/UnblockNeteaseMusic-Android</a> 项目。</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a68033b9ebfaad9b14b38d" data-id="2f00209195a68033b9ebfaad9b14b38d"><span><div id="2f00209195a68033b9ebfaad9b14b38d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68033b9ebfaad9b14b38d" title="准备"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>准备</b></span></span></h2><ul class="notion-list notion-list-disc notion-block-2f00209195a680629e8def14203430ec"><li>一台位于大陆的服务器（必须是国内的，因为很多歌曲都只是买了大陆版权）</li><ul class="notion-list notion-list-disc notion-block-2f00209195a680629e8def14203430ec"><blockquote class="notion-quote notion-block-2f00209195a68093abb5c72d00cc23d6"><div>其实国外的服务器也可以，UnblockNeteaseMusic 提供了使用上游代理的方法，具体请查阅官方食用指南。</div></blockquote></ul></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a680cd9626fad18b28e7aa"><li>一台已 root 并安装了 Magisk 的手机</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a680239ff5de20baae002c"><li>将网易云音乐移出 Magisk Hide 名单（未设置请忽略）</li><ul class="notion-list notion-list-disc notion-block-2f00209195a680239ff5de20baae002c"><blockquote class="notion-quote notion-block-2f00209195a68017984fdce22d6d915b"><div>如果网易云音乐客户端在 Magisk Hide 名单内会导致证书不生效</div></blockquote><h2 class="notion-h notion-h1 notion-block-2f00209195a680d88749da95b1b4d204" data-id="2f00209195a680d88749da95b1b4d204"><span><div id="2f00209195a680d88749da95b1b4d204" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680d88749da95b1b4d204" title="服务端部署 UnblockNeteaseMusic"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>服务端部署 UnblockNeteaseMusic</b></span></span></h2><div class="notion-text notion-block-2f00209195a6804da323c70253ef6dcf">这个应该不用多说了，<a class="notion-link" href="https://github.com/nondanee/UnblockNeteaseMusic" target="_blank" rel="noopener noreferrer">https://github.com/nondanee/UnblockNeteaseMusic</a> 官方搭建方法已经写的很明白了，不过需要注意的是必须开启 HTTPS 并导入证书（接下来会讲到），否则会导致网易云音乐客户端个人页面和登录无法正常使用</div></ul></ul><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a68066a07cdcd73b804234" data-id="2f00209195a68066a07cdcd73b804234"><span><div id="2f00209195a68066a07cdcd73b804234" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a68066a07cdcd73b804234" title="Magisk 模块编写"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>Magisk 模块编写</b></span></span></h2><div class="notion-text notion-block-2f00209195a680fbbb7dfc6a3db35982">这个的话我已经写好了，改一下配置即可</div><div class="notion-text notion-block-2f00209195a680518098c03431965eba">模块模板下载链接：<a class="notion-link" href="https://rushb.lanzout.com/iFzY6cgsqkh" target="_blank" rel="noopener noreferrer">https://rushb.lanzout.com/iFzY6cgsqkh</a> 密码: <code class="notion-inline-code">6e01</code></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6803d9b49cd6268d2b412" data-id="2f00209195a6803d9b49cd6268d2b412"><span><div id="2f00209195a6803d9b49cd6268d2b412" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6803d9b49cd6268d2b412" title="修改 iptables 脚本"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>修改 iptables 脚本</b></span></span></h3><div class="notion-text notion-block-2f00209195a680cda184e172fa1e6db4">编辑 <code class="notion-inline-code">post-fs-data.sh</code> 文件</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a680d18816f7e6d59740ba" data-id="2f00209195a680d18816f7e6d59740ba"><span><div id="2f00209195a680d18816f7e6d59740ba" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680d18816f7e6d59740ba" title="修改证书"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>修改证书</b></span></span></h3><div class="notion-text notion-block-2f00209195a680b990e7ff9cbdded50e">我们知道，如果应用的 Target API 在 24 以上的话，应用就只会信任系统证书而不会信任用户证书，而刚好我们是 Magisk 模块，就可以顺便把系统证书也写进去</div><div class="notion-text notion-block-2f00209195a680b3a189e56e8bb86823">打开文件夹 <code class="notion-inline-code">system\etc\security\cacerts</code> 我们以 UnblockNeteaseMusic 证书为例，他的证书为 <a class="notion-link" href="https://raw.githubusercontent.com/nondanee/UnblockNeteaseMusic/master/ca.crt" target="_blank" rel="noopener noreferrer">ca.crt</a></div><div class="notion-text notion-block-2f00209195a6807cad8ed0c1e1f6753d">我们把它下载下来，转换为pem格式：</div><div class="notion-text notion-block-2f00209195a68078a26dca1a537c2b42">以hash方式重命名文件（Android 系统要求）</div><div class="notion-text notion-block-2f00209195a680c88927f0381e34ad66">得到证书的 hash 之后将证书 <code class="notion-inline-code">ca.pem</code> 重命名为 <code class="notion-inline-code">557de9dd.0</code> 放入模块的 <code class="notion-inline-code">system\etc\security\cacerts</code> 文件夹，再把模块打包即可</div><div class="notion-text notion-block-2f00209195a680fc83aecd94ecee41df">模块的其他信息可在 <code class="notion-inline-code">module.prop</code> 修改</div><blockquote class="notion-quote notion-block-2f00209195a680cc98e3f27318e0e1f1"><div>如果是你自己的证书也可以通过此方法算出 hash 进行替换</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680e78511e706a6c80647" data-id="2f00209195a680e78511e706a6c80647"><span><div id="2f00209195a680e78511e706a6c80647" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680e78511e706a6c80647" title="效果图"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>效果图</b></span></span></h2><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f00209195a6808dae02c44b6dcbf6b4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/f4db3a0a-f35c-4e3a-ae9d-76f83cf6fb75/image.png?table=block&amp;id=2f002091-95a6-808d-ae02-c44b6dcbf6b4&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=mz_5qa91BpWgVpOnjIhhSNQl7TtZXeRNFiwxOyg_s3c&amp;t=2f002091-95a6-808d-ae02-c44b6dcbf6b4" alt="notion image" loading="lazy" decoding="async"/></div></figure><blockquote class="notion-quote notion-block-2f00209195a68078ac31c353d79fc9d7"><div>系统证书正常</div></blockquote><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f00209195a6809b9b7aed162375199c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/1f8a727d-44fe-4807-93bf-14d77f03656e/image.png?table=block&amp;id=2f002091-95a6-809b-9b7a-ed162375199c&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=4pgxqwUr_U_t1DzfR4ojYZoY53Eb1hgT_GxsT9SUcdw&amp;t=2f002091-95a6-809b-9b7a-ed162375199c" alt="notion image" loading="lazy" decoding="async"/></div></figure><blockquote class="notion-quote notion-block-2f00209195a6809b8cbacccd96682ab5"><div>解锁网易云音乐客户端变灰歌曲正常</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680dd8bd0e2114f87ae24" data-id="2f00209195a680dd8bd0e2114f87ae24"><span><div id="2f00209195a680dd8bd0e2114f87ae24" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680dd8bd0e2114f87ae24" title="Changelog"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>Changelog</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6809e8580c232fde0fc5f" data-id="2f00209195a6809e8580c232fde0fc5f"><span><div id="2f00209195a6809e8580c232fde0fc5f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6809e8580c232fde0fc5f" title="20200510"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>20200510</b></span></span></h3><ul class="notion-list notion-list-disc notion-block-2f00209195a680109ea7c2ef58455768"><li>将 iptables 配置从 <code class="notion-inline-code">post-fs-data.sh</code> 移动到 <code class="notion-inline-code">service.sh</code></li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a68082a1b3d3462eb3bda4"><li>去除无用配置</li></ul><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680deba6de7b40f90c84b" data-id="2f00209195a680deba6de7b40f90c84b"><span><div id="2f00209195a680deba6de7b40f90c84b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680deba6de7b40f90c84b" title="参考"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>参考</b></span></span></h2><div class="notion-text notion-block-2f00209195a6802584f4eb274071d0f5"><a class="notion-link" href="https://github.com/nondanee/UnblockNeteaseMusic" target="_blank" rel="noopener noreferrer">https://github.com/nondanee/UnblockNeteaseMusic</a></div><div class="notion-text notion-block-2f00209195a6803ba73ccd3e8c8094b1"><a class="notion-link" href="https://github.com/Flysky12138/UnblockNeteaseMusic-Android" target="_blank" rel="noopener noreferrer">https://github.com/Flysky12138/UnblockNeteaseMusic-Android</a></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[UU 加速器在新版 OpenWrt nftables 环境中的使用技巧 (不全开防火墙的方法)]]></title>
            <link>https://rushb.pro/article/openwrt-uugamebooster</link>
            <guid>https://rushb.pro/article/openwrt-uugamebooster</guid>
            <pubDate>Tue, 10 Dec 2024 00:00:00 GMT</pubDate>
            <description><![CDATA[UU 加速器终于支持 nftables 了！]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-2f00209195a680b0b26cd8095472d68d"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680209002f0b4496fbcdd" data-id="2f00209195a680209002f0b4496fbcdd"><span><div id="2f00209195a680209002f0b4496fbcdd" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680209002f0b4496fbcdd" title="前言"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>前言</b></span></span></h2><div class="notion-text notion-block-2f00209195a680618d61e26be2ae02a3">前段时间 UU 加速器更新了 v8.0.12 版本，支持了 OpenWrt 23 及以上的 nftables 环境，官方说明：<a class="notion-link" href="https://router.uu.163.com/app/html/online/baike_share.html?baike_id=5f963c9304c215e129ca40e8" target="_blank" rel="noopener noreferrer">https://router.uu.163.com/app/html/online/baike_share.html?baike_id=5f963c9304c215e129ca40e8</a></div><div class="notion-text notion-block-2f00209195a680339fe8f272c02bd71a">但是，官方的说明文档中，要求防火墙全开，这就有点让人难以接受了。</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680f092d6d61c3a8107f5"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:720px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/657d8d19-71fb-4e27-ac7b-bdb17854e8e4/image.png?table=block&amp;id=2f102091-95a6-80f0-92d6-d61c3a8107f5&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=-MFSo9kDp7Wcy8OPom-UVMij_kw3I0ELFjhOPXqrdQA&amp;t=2f102091-95a6-80f0-92d6-d61c3a8107f5" alt="notion image" loading="lazy" decoding="async"/></div></figure><blockquote class="notion-quote notion-block-2f00209195a680638a9dddfd1de75ace"><div>依次进入【网络】 - 【防火墙】 - 将【入站数据】、【出站数据】、【转发】都改为接受，并且点击Accept保存</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680968bc7e486430a045a" data-id="2f00209195a680968bc7e486430a045a"><span><div id="2f00209195a680968bc7e486430a045a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680968bc7e486430a045a" title="解决方法"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>解决方法</b></span></span></h2><div class="notion-text notion-block-2f00209195a680a9af16cb8e140f3142">既然 UU 加速器是使用 tun 设备来管理网络的，那我们可以针对 UU 创建的 tun 设备来设置防火墙规则。</div><div class="notion-text notion-block-2f00209195a680ab866cd67749d7e56c">可以看到，开启 UU 加速器后，系统会生成一个 <code class="notion-inline-code">tun163</code> 的设备</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f10209195a680e58cb0ededeb20a577"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/19e63c71-6418-4735-b1ce-1c695df66d5d/image.png?table=block&amp;id=2f102091-95a6-80e5-8cb0-ededeb20a577&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=EucOGJgeFGSkIDWv04P93A_ZLumJX0OdUc8hZVbcfAY&amp;t=2f102091-95a6-80e5-8cb0-ededeb20a577" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-2f00209195a680d5a5def1237e16cc01">那么就可以针对这个设备来设置防火墙规则了</div><div class="notion-text notion-block-2f00209195a680b6973ac6974625526c">在 【网络】 -&gt; 【防火墙】 -&gt; 【通信规则】中，添加三条规则</div><div class="notion-text notion-block-2f00209195a68095991ec0fb01fa5cdb">依次是:</div><ul class="notion-list notion-list-disc notion-block-2f00209195a6803da081d04a6ab960d9"><li>允许 tun163 的入站数据</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a680fcb70aebb4c576a286"><li>允许来自 tun163 的转发数据</li></ul><ul class="notion-list notion-list-disc notion-block-2f00209195a6807a92dcfe7eb2df930f"><li>允许转发到 tun163 的数据</li></ul><blockquote class="notion-quote notion-block-2f00209195a6800392f0f049eeb2434f"><div>⚠️ 注意，如果要加速两台设备，还需要加 <code class="notion-inline-code">tun164</code> 设备的规则！！！</div></blockquote><div class="notion-text notion-block-2f00209195a680f8b2efdd565b06c859">根据我使用 PlayStation 5 的测试，不添加防火墙规则会造成 NAT 测试失败</div><div class="notion-text notion-block-2f00209195a680c0b41adcb132fef722">添加第一条: <code class="notion-inline-code">允许 tun163 的入站数据</code> 后，NAT 测试成功。经过测试 GT7 可以正常进入围场，但是战地 2042 无法进入游戏。</div><div class="notion-text notion-block-2f00209195a680b0858bede95406f7c6">添加第二条: <code class="notion-inline-code">允许来自 tun163 的转发数据</code> 后，战地 2042 可以正常进入游戏。其它联机游戏也能正常运行，但是使用 PS Remote Play 连接 PS5 时，会提示连接失败，需要添加第三条规则： <code class="notion-inline-code">允许转发到 tun163 的数据</code></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6802ab9e9c4ff6503d5e3" data-id="2f00209195a6802ab9e9c4ff6503d5e3"><span><div id="2f00209195a6802ab9e9c4ff6503d5e3" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6802ab9e9c4ff6503d5e3" title="注意"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>注意</b></span></span></h3><div class="notion-text notion-block-2f00209195a68071b01ff7a091f7f59f">UU 会在 /usr/bin 目录下找 <code class="notion-inline-code">xtables-nft-multi</code>，官方安装方法可能没问题，我是自己编译的时候把 UU 加进去的，需要自己手动复制一下</div><div class="notion-text notion-block-2f00209195a680a390b7fa584742c7f7">使用过程中发现访问 PlayStation 商店无法加载，结果看日志发现了 UU 用了这些地址导致了和 OpenClash 的冲突</div><div class="notion-text notion-block-2f00209195a6801c9cc0dd67c5acf269">通过与网易工作人员交流以后，给出解决方法：</div><div class="notion-text notion-block-2f00209195a68081ab79fbeb07f49d99">在 【插件设置】 -&gt; 【流量控制】 里的本地 IPv4 绕过地址中加入：</div><blockquote class="notion-quote notion-block-2f00209195a6801b998dfb388fdbec75"><div>如果这里有更好的方法，欢迎补充</div></blockquote><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-2f00209195a680f8b714c16f6bf57756" data-id="2f00209195a680f8b714c16f6bf57756"><span><div id="2f00209195a680f8b714c16f6bf57756" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a680f8b714c16f6bf57756" title="懒人包"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>懒人包</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-2f00209195a6804398fcfa985b92697b" data-id="2f00209195a6804398fcfa985b92697b"><span><div id="2f00209195a6804398fcfa985b92697b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2f00209195a6804398fcfa985b92697b" title="修改文件版"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>修改文件版</b></span></span></h3><div class="notion-text notion-block-2f00209195a6809492f7eef2af0cdb19">如果你觉得 luci 界面太麻烦，可以直接修改 <code class="notion-inline-code">/etc/config/firewall</code> 文件，添加如下内容：</div><div class="notion-text notion-block-2f00209195a680b9b189fc7e0f6375da">开始愉快的玩耍吧！</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2f00209195a680c68098c09e8c985466"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:240px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/d388b216-e286-45c0-b6e0-bef7fc196f35/image.png?table=block&amp;id=2f002091-95a6-80c6-8098-c09e8c985466&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=a8mYCXjbzmV6qauFcXBzBkTv_OVxtjRyVQX3SlTxMpk&amp;t=2f002091-95a6-80c6-8098-c09e8c985466" alt="notion image" loading="lazy" decoding="async"/></div></figure></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[通过 Cloudflare Tunnel 实现 EasyTier 无公网自建中转服务器]]></title>
            <link>https://rushb.pro/article/Cloudflare-Tunnel-EasyTier</link>
            <guid>https://rushb.pro/article/Cloudflare-Tunnel-EasyTier</guid>
            <pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[没有公网 IP，又不想买 VPS 不妨来试试看]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-3030209195a680a4927ada2beab78116"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-text notion-block-3030209195a680b4ad00eb258dddbc6b">最近 EasyTier 的公共服务器频繁出现问题，于是在搜索资料以后，找到了使用 Cloudflare Tunnel 转发 websocket 端口实现中转服务器打洞的效果</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-3030209195a680e18096da5600324a6f" data-id="3030209195a680e18096da5600324a6f"><span><div id="3030209195a680e18096da5600324a6f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a680e18096da5600324a6f" title="前提条件"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">前提条件</span></span></h2><ol start="1" class="notion-list notion-list-numbered notion-block-3030209195a680048561e12346a34b7b" style="list-style-type:decimal"><li>Cloudflare 启用了 WebSockets 功能 (在 Cloudflare 仪表板的“网络”选项里能看到 WebSockets 选项是否打开)</li></ol><ol start="2" class="notion-list notion-list-numbered notion-block-3030209195a68003b7bcd0da8b21bf50" style="list-style-type:decimal"><li>Cloudflare 仪表板中的 SSL/TLS 加密模式选择：<b>完全</b></li></ol><ol start="3" class="notion-list notion-list-numbered notion-block-3030209195a680718cbdfa72191573ad" style="list-style-type:decimal"><li>本地安装了 cloudflared 和 easytier</li></ol><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-3030209195a6803ab1cbcd7d4b36d58d" data-id="3030209195a6803ab1cbcd7d4b36d58d"><span><div id="3030209195a6803ab1cbcd7d4b36d58d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a6803ab1cbcd7d4b36d58d" title="配置方法"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">配置方法</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-3030209195a680a39a65d949c6df169e" data-id="3030209195a680a39a65d949c6df169e"><span><div id="3030209195a680a39a65d949c6df169e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a680a39a65d949c6df169e" title="Easytier"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">Easytier</span></span></h3><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-3030209195a68034b6c0d2b60813eec4" data-id="3030209195a68034b6c0d2b60813eec4"><span><div id="3030209195a68034b6c0d2b60813eec4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a68034b6c0d2b60813eec4" title="命令行"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">命令行</span></span></h4><div class="notion-text notion-block-3030209195a680279e4df3d0efb02cdf">只需要确保 EasyTier 正在监听 WebSocket 协议，命令行参数:</div><div class="notion-text notion-block-3030209195a6802da2dbdfcd93a0399a">当然，如果你希望你的网络更安全一点可以启用私有模式：<code class="notion-inline-code">--private-mode</code> ，开启了私有模式以后不会允许与本网络不同的网络名称和密码的客户点通过本服务器进行握手</div><div class="notion-text notion-block-3110209195a6808bbd73e9f4253081f5">或者通过 <code class="notion-inline-code">--relay-network-whitelist</code> 参数限定可被转发的网络名白名单（空格分割的通配符列表，如 <code class="notion-inline-code">&quot;ab* abc&quot;</code>）</div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-3030209195a680d6901ccc7653054999" data-id="3030209195a680d6901ccc7653054999"><span><div id="3030209195a680d6901ccc7653054999" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a680d6901ccc7653054999" title="luci app"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">luci app</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3030209195a68097a3f4f4071180db8a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:346.984375px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/dd31ff1e-d147-4a82-95d6-fc2fa21e1158/image.png?table=block&amp;id=30302091-95a6-8097-a3f4-f4071180db8a&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=pU3lcdvSspG7u9ze4iHZ3gY7HGT08dND4pqrudpL6ok&amp;t=30302091-95a6-8097-a3f4-f4071180db8a" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3030209195a680488ec4d437ee8ec29b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/d9c82960-d54a-411a-9c2f-e95d6a432168/image.png?table=block&amp;id=30302091-95a6-8048-8ec4-d437ee8ec29b&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=ABOjzVO3Vo2J78ML5LfVGrcrxDHmx61mSK-VX1NdnUU&amp;t=30302091-95a6-8048-8ec4-d437ee8ec29b" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-3030209195a680939c0be1f0d9da8fa0" data-id="3030209195a680939c0be1f0d9da8fa0"><span><div id="3030209195a680939c0be1f0d9da8fa0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a680939c0be1f0d9da8fa0" title="Cloudflare Tunnel"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">Cloudflare Tunnel</span></span></h3><div class="notion-text notion-block-3030209195a680dfa43ed3053b40a397">将 Cloudflare Tunnel 配置好以后，进入 Cloudflare 仪表板 - Zero Trust - 网络 - 连接器</div><div class="notion-text notion-block-3030209195a68044bcafcc4503e53f19">选中刚刚创建的隧道，添加一个已发布应用程序路由</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3030209195a680a68a7ecee313a259cf"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:347px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/acd55635-1807-41d4-b144-3413d63f86ad/image.png?table=block&amp;id=30302091-95a6-80a6-8a7e-cee313a259cf&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=Q33IsGJcfOMs_CwFOSgdIUjOxraR5esiveVyMqbDSU8&amp;t=30302091-95a6-80a6-8a7e-cee313a259cf" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-3030209195a6801396a7ec56a69651b3">填写好你想要的子域名，服务选择<code class="notion-inline-code">HTTP</code> 并且指向刚刚配置的 Easytier 监听的端口</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3030209195a680b899ade784ab0d051a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/dec95091-6a5d-461d-94e5-57a170982b2d/image.png?table=block&amp;id=30302091-95a6-80b8-99ad-e784ab0d051a&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=Bp8P2qGGeQtULIi-VM0sZW2ZPTNsCdHd9pndmpkcl40&amp;t=30302091-95a6-80b8-99ad-e784ab0d051a" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-3030209195a6806bb6b1f53bf699d140" data-id="3030209195a6806bb6b1f53bf699d140"><span><div id="3030209195a6806bb6b1f53bf699d140" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a6806bb6b1f53bf699d140" title="为什么选择 HTTP?"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">为什么选择 HTTP?</span></span></h4><div class="notion-text notion-block-3030209195a6806ca1dcda0dbf8548e8">EasyTier 监听的是 WebSocket, 但 Cloudflare Tunnel 的配置里填写 HTTP 即可, Cloudflare 会自动识别并处理协议升级请求
</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-3030209195a68046af60c2ab1e18a561" data-id="3030209195a68046af60c2ab1e18a561"><span><div id="3030209195a68046af60c2ab1e18a561" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3030209195a68046af60c2ab1e18a561" title="Easytier 客户端连接"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">Easytier 客户端连接</span></span></h3><div class="notion-text notion-block-3030209195a680b88688e0d2bffb664d">由于服务端监听的 11011 端口现在已被 Cloudflare 中转，客户端现在只需填写刚刚创建好的域名即可</div><blockquote class="notion-quote notion-block-3030209195a680d184d0e172d56046a4"><div>注意，现在 ws 被 Cloudflare 中转以后自动进行了加密和套了证书，所以客户端需要使用 wss 进行连接</div></blockquote><div class="notion-text notion-block-3030209195a680c7adb2c899c4ae0b67">客户端对等节点 (-p 参数）填写：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3030209195a68064aed1d6e2a4314db8"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:347px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://file.notion.com/f/f/2884ddb6-419c-4648-ba7a-da0802542fd6/898df6a7-b905-43e5-8630-354858e02d50/image.png?table=block&amp;id=30302091-95a6-8064-aed1-d6e2a4314db8&amp;spaceId=2884ddb6-419c-4648-ba7a-da0802542fd6&amp;expirationTimestamp=1786701600000&amp;signature=bH0leW6RsmtnloTnRc2Da94PAQeGvfQH4YyKpYMHLPc&amp;t=30302091-95a6-8064-aed1-d6e2a4314db8" alt="notion image" loading="lazy" decoding="async"/></div></figure><blockquote class="notion-quote notion-block-3030209195a6808faeebf36e75eae3a5"><div>如果你使用的 EasyTier 版本 &lt; 2.5.0，这里需要填写端口号：<code class="notion-inline-code">wss://easytier.example.com:0</code> 或者是<code class="notion-inline-code">ws://easytier.example.com:0</code>
EasyTier 会根据协议类型尝试使用默认端口，在新版本中没这个要求了</div></blockquote><div class="notion-blank notion-block-3030209195a68099a2f5efeab903300a"> </div><div class="notion-text notion-block-3030209195a680e98800e7c044e9981a">现在，你的服务器已经可以通过 Cloudflare 全球边缘节点随时随地进行连接，无需任何公共服务器</div><div class="notion-blank notion-block-3030209195a680d0ad45f41c71c1dd2f"> </div></main></div>]]></content:encoded>
        </item>
    </channel>
</rss>