Sign inSign up

36bian/ss-gateway

By 36bian

•Updated over 6 years ago

shadowsocks网关版,全局透明翻墙,智能分流,支持ss/vess协议,支持多服务器负载均衡

Image
0

1.8K

36bian/ss-gateway repository overview

⁠初衷

其实我已经做过一个docker-Meow⁠了,工作的不错,直到有一天在用某Web开发工具下载插件时一直wating wating wating,后来一查果然是被墙的关系,气得要死。meow的缺点是只支持浏览器和部分命令行程序,考虑到以后还会碰到很多这种事情,我可真不想被各种莫名其妙的问题耽误时间、浪费精力,于是萌生了做一款全局翻墙工具的想法,顺带着智能分流(一则国内访问快,二则给代理省点流量)

⁠工作原理

ts-dns + glider

ts-dns负责解析dns,自带一张国内ip段和gfw域名来实现智能分流,匹配到gfw的域名会经由远程解析dns实现去污染,同时将解析后的ip写入路由表转给redir来实现代理访问。同时它还支持自定义黑白域名和本地域名泛解析功能,下文将有详述

⁠版本

v1.0 初版
v1.1 原版对非gwf名单的国外ip默认直连,我修改了部分代码,只要是国外ip都走代理,实测速度有质的提升(但可能会牺牲点流量)。不想走代理的请手动将相关域名加到direct文件中。另外屏蔽了一些udp请求超时日志输出
v1.2 ss改成glider⁠,支持多协议(ss/vmess)多服务器负载均衡、高可用

⁠使用

服务器配置
1.保存glider.conf到本地,修改连接参数
2.保存docker-compose.yml到本地,运行docker-compose up -d启动

客户端
3-1(可选)路由器配置网关和dns,指向ss-gateway所在ip
3-1(可选)路由器不动,想翻墙的机器(含手机)手动把网关和dns指向ss-gateway所在ip
注意事项
1.部署ss-gateway的宿主机网关必须指向路由器,否则无法连网
2.如果使用的代理服务器是域名而非ip,必须添加到direct直连文件中,否则无法连网

⁠配置文件

⁠docker-compose.yml
version: '3.3'

services:
  ss-gateway:
    image: 36bian/ss-gateway:1.2
    container_name: ss-gateway
    privileged: true
    restart: unless-stopped
    network_mode: "host"
    volumes:
      - "./glider.conf:/root/glider.conf"
      - "./direct:/root/ts-dns/direct" # 可选,直连域名
      #- "./proxy:/root/ts-dns/proxy" # 可选,代理域名
      #- "./hosts:/root/ts-dns/hosts" # 可选,自定义hosts映射
⁠glider.conf示例
# https://github.com/nadoo/glider/blob/master/config/glider.conf.example

verbose=True
listen=redir://:1080

strategy=ha
checkwebsite=www.google.com
checkinterval=600

# priority数字越大,优先级越高
forward=ss://aes-256-gcm:[email protected]:1080
forward=simple-obfs://www.server.com:1080?type=tls&host=bing.com,ss://aes-256-gcm:password@#priority=1
forward=vmess://aes-128-gcm:[email protected]:1080#priority=2

⁠进阶配置

添加直连名单,创建direct文件,格式为

代理服务器域名.com # 一定要加进来,否则无法联网
baidu.* # 支持后缀泛解析
qq.com #支持前缀泛解析

添加代理名单,创建proxy文件,内容格式为

docker.com
docker.io

自定义host,创建hosts文件,支持泛解析,格式为

192.168.1.33 *.home.com

---------------------------以下为构建文档-------------------------------

⁠dockerfile文件
FROM alpine:3.11

RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.ustc.edu.cn/g' /etc/apk/repositories \
    && apk add --no-cache iptables ipset

# copy source files
COPY ts-dns /root/ts-dns
COPY glider glider.conf entrypoint.sh /root/

# 容器自启动入口(注意赋予可执行权限)
ENTRYPOINT ["/root/entrypoint.sh"]
⁠entrypoint.sh
#!/bin/sh

# 启动dns解析
cd /root/ts-dns && ./ts-dns & # 启动时会创建被墙ipset-blocked
# 重定向ipset名单到ss-redir
sleep 1
iptables -P FORWARD ACCEPT
iptables -t nat -I PREROUTING -p tcp -m set --match-set blocked dst -j REDIRECT --to-ports 1080
iptables -t nat -I OUTPUT -p tcp -m set --match-set blocked dst -j REDIRECT --to-ports 1080
# 启动glider
/root/glider -config /root/glider.conf
⁠ts-dns.toml
# Telescope DNS Configure File
# https://github.com/wolf-joe/ts-dns

listen = ":53"
gfwlist = "gfwlist.txt"
cnip = "cnip.txt"
hosts_files = ["hosts"] # 自定义的host映射,支持通配符

[cache]  # dns缓存配置
min_ttl = 86400  # 所有dns最少保持一天,防止频繁解析

[groups]
  [groups.clean]
  dns = ["223.5.5.5","223.6.6.6"]
  rules_file = "direct" # 强制直连名单

  [groups.dirty]
  dns = ["208.67.222.222:5353","208.67.220.220:5353"]
  rules_file = "proxy" # 强制代理名单

  # 警告:进程启动时会覆盖已有同名IPSet
  ipset = "blocked"  # 目标IPSet名称,该组所有域名的ipv4解析结果将加入到该IPSet中
  ipset_ttl = 86400 # ipset记录超时时间,单位为秒,推荐设置以避免ipset记录过多
⁠inbound/server.go
#line 51  log.Errorf("query dns error: %v", err)

#line193	} else if blocked, ok := handler.GFWMatcher.Match(question.Name); !ok || !blocked {
#line194		// 出现非cn ip但域名不匹配gfwlist,流程结束
#line195		handler.LogQuery(resp, question, "not match gfwlist", "clean")
#line196	} 

Tag summary

Content type

Image

Digest

Size

8.1 MB

Last updated

over 6 years ago

docker pull 36bian/ss-gateway