shadowsocks网关版,全局透明翻墙,智能分流,支持ss/vess协议,支持多服务器负载均衡
1.8K
其实我已经做过一个docker-Meow了,工作的不错,直到有一天在用某Web开发工具下载插件时一直wating wating wating,后来一查果然是被墙的关系,气得要死。meow的缺点是只支持浏览器和部分命令行程序,考虑到以后还会碰到很多这种事情,我可真不想被各种莫名其妙的问题耽误时间、浪费精力,于是萌生了做一款全局翻墙工具的想法,顺带着智能分流(一则国内访问快,二则给代理省点流量)
ts-dns + glider
ts-dns负责解析dns,自带一张国内ip段和gfw域名来实现智能分流,匹配到gfw的域名会经由远程解析dns实现去污染,同时将解析后的ip写入路由表转给redir来实现代理访问。同时它还支持自定义黑白域名和本地域名泛解析功能,下文将有详述
v1.0 初版
v1.1 原版对非gwf名单的国外ip默认直连,我修改了部分代码,只要是国外ip都走代理,实测速度有质的提升(但可能会牺牲点流量)。不想走代理的请手动将相关域名加到direct文件中。另外屏蔽了一些udp请求超时日志输出
v1.2 ss改成glider,支持多协议(ss/vmess)多服务器负载均衡、高可用
服务器配置
1.保存glider.conf到本地,修改连接参数
2.保存docker-compose.yml到本地,运行docker-compose up -d启动
客户端
3-1(可选)路由器配置网关和dns,指向ss-gateway所在ip
3-1(可选)路由器不动,想翻墙的机器(含手机)手动把网关和dns指向ss-gateway所在ip
注意事项
1.部署ss-gateway的宿主机网关必须指向路由器,否则无法连网
2.如果使用的代理服务器是域名而非ip,必须添加到direct直连文件中,否则无法连网
version: '3.3'
services:
ss-gateway:
image: 36bian/ss-gateway:1.2
container_name: ss-gateway
privileged: true
restart: unless-stopped
network_mode: "host"
volumes:
- "./glider.conf:/root/glider.conf"
- "./direct:/root/ts-dns/direct" # 可选,直连域名
#- "./proxy:/root/ts-dns/proxy" # 可选,代理域名
#- "./hosts:/root/ts-dns/hosts" # 可选,自定义hosts映射
# https://github.com/nadoo/glider/blob/master/config/glider.conf.example
verbose=True
listen=redir://:1080
strategy=ha
checkwebsite=www.google.com
checkinterval=600
# priority数字越大,优先级越高
forward=ss://aes-256-gcm:[email protected]:1080
forward=simple-obfs://www.server.com:1080?type=tls&host=bing.com,ss://aes-256-gcm:password@#priority=1
forward=vmess://aes-128-gcm:[email protected]:1080#priority=2
添加直连名单,创建direct文件,格式为
代理服务器域名.com # 一定要加进来,否则无法联网
baidu.* # 支持后缀泛解析
qq.com #支持前缀泛解析
添加代理名单,创建proxy文件,内容格式为
docker.com
docker.io
自定义host,创建hosts文件,支持泛解析,格式为
192.168.1.33 *.home.com
---------------------------以下为构建文档-------------------------------
FROM alpine:3.11
RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.ustc.edu.cn/g' /etc/apk/repositories \
&& apk add --no-cache iptables ipset
# copy source files
COPY ts-dns /root/ts-dns
COPY glider glider.conf entrypoint.sh /root/
# 容器自启动入口(注意赋予可执行权限)
ENTRYPOINT ["/root/entrypoint.sh"]
#!/bin/sh
# 启动dns解析
cd /root/ts-dns && ./ts-dns & # 启动时会创建被墙ipset-blocked
# 重定向ipset名单到ss-redir
sleep 1
iptables -P FORWARD ACCEPT
iptables -t nat -I PREROUTING -p tcp -m set --match-set blocked dst -j REDIRECT --to-ports 1080
iptables -t nat -I OUTPUT -p tcp -m set --match-set blocked dst -j REDIRECT --to-ports 1080
# 启动glider
/root/glider -config /root/glider.conf
# Telescope DNS Configure File
# https://github.com/wolf-joe/ts-dns
listen = ":53"
gfwlist = "gfwlist.txt"
cnip = "cnip.txt"
hosts_files = ["hosts"] # 自定义的host映射,支持通配符
[cache] # dns缓存配置
min_ttl = 86400 # 所有dns最少保持一天,防止频繁解析
[groups]
[groups.clean]
dns = ["223.5.5.5","223.6.6.6"]
rules_file = "direct" # 强制直连名单
[groups.dirty]
dns = ["208.67.222.222:5353","208.67.220.220:5353"]
rules_file = "proxy" # 强制代理名单
# 警告:进程启动时会覆盖已有同名IPSet
ipset = "blocked" # 目标IPSet名称,该组所有域名的ipv4解析结果将加入到该IPSet中
ipset_ttl = 86400 # ipset记录超时时间,单位为秒,推荐设置以避免ipset记录过多
#line 51 log.Errorf("query dns error: %v", err)
#line193 } else if blocked, ok := handler.GFWMatcher.Match(question.Name); !ok || !blocked {
#line194 // 出现非cn ip但域名不匹配gfwlist,流程结束
#line195 handler.LogQuery(resp, question, "not match gfwlist", "clean")
#line196 }
Content type
Image
Digest
Size
8.1 MB
Last updated
over 6 years ago
docker pull 36bian/ss-gateway