[ xray ] 优化xray部分,新增搬瓦工-洛杉矶节点

This commit is contained in:
zeaslity
2024-04-16 15:44:33 +08:00
parent 714ff01639
commit 907474ebf3
23 changed files with 106 additions and 665 deletions

View File

@@ -37,3 +37,5 @@
43.128.39.232 tc-hk 43.128.39.232 tc-hk
114.117.165.222 tc-cd 114.117.165.222 tc-cd
89.208.251.209 los-1

View File

@@ -44,106 +44,111 @@ dns:
- 192.168.34.0/24 - 192.168.34.0/24
- 192.168.35.0/24 - 192.168.35.0/24
proxies: proxies:
- {"type":"vmess","name":"us-cente-free","ws-opts":{"path":"/vmess"},"server":"northflank.107421.xyz","port":443,"uuid":"de04add9-5c68-8bab-950c-08cd5320df18","alterId":0,"cipher":"auto","network":"ws","tls":true} - {"type":"vmess","name":"us-central-free","ws-opts":{"path":"/vmess"},"server":"northflank.107421.xyz","port":443,"uuid":"de04add9-5c68-8bab-950c-08cd5320df18","alterId":0,"cipher":"auto","network":"ws","tls":true}
- {"type":"trojan","name":"LosAngels-BanH-Trojan","server":"89.208.251.209","port":443,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.l4.cc.nn.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.l4.cc.nn.107421.xyzh2,http/1.1"}}}
- {"type":"trojan","name":"Seoul-Trojan","server":"140.238.14.103","port":443,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}} - {"type":"trojan","name":"Seoul-Trojan","server":"140.238.14.103","port":443,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}}
- {"type":"trojan","name":"Osaka-Trojan","server":"140.238.14.103","port":19997,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}} - {"type":"trojan","name":"Osaka-Trojan","server":"140.238.14.103","port":19997,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}}
- {"type":"trojan","name":"Tokyo-Trojan","server":"140.238.14.103","port":19999,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}} - {"type":"trojan","name":"Tokyo-Trojan","server":"140.238.14.103","port":19999,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}}
- {"type":"trojan","name":"Pheonix-Trojan","server":"140.238.14.103","port":19998,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}} - {"type":"trojan","name":"Phoenix-Trojan","server":"140.238.14.103","port":19998,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s4.cc.hh.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s4.cc.hh.107421.xyzh2,http/1.1"}}}
- {"type":"trojan","name":"Seoul-arm64-01-Trojan","server":"132.145.87.10","port":30000,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s0.yy.ac.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s0.yy.ac.107421.xyzh2,http/1.1"}}} - {"type":"trojan","name":"Seoul-arm64-01-Trojan","server":"132.145.87.10","port":30000,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.s0.yy.ac.107421.xyz","network":"tcp","ws-opts":{"headers":{"host":"xx.s0.yy.ac.107421.xyzh2,http/1.1"}}}
- {"type":"trojan","name":"Tencent-Hkong-Trojan","server":"43.154.83.213","port":443,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.tc.hk.go.107421.xyz","network":"tcp"} - {"type":"trojan","name":"HongK-Tencent-Trojan","server":"43.154.83.213","port":443,"password":"V2ryStr0ngP0ss","udp":true,"skip-cert-verify":false,"sni":"xx.tc.hk.go.107421.xyz","network":"tcp"}
- {"type":"vless","name":"Tencent-HK-11.24","server":"43.154.83.213","port":29999,"uuid":"fc903f5d-a007-482b-928c-570da9a851f9","skip-cert-verify":false,"network":"tcp","flow":"xtls-rprx-vision","servername":"xx.tc.hk.go.107421.xyz","tls":true,"udp":true} - {"type":"vless","name":"Tencent-HK-11.24","server":"43.154.83.213","port":29999,"uuid":"fc903f5d-a007-482b-928c-570da9a851f9","skip-cert-verify":false,"network":"tcp","flow":"xtls-rprx-vision","servername":"xx.tc.hk.go.107421.xyz","tls":true,"udp":true}
- {"type":"socks5","name":"onetools-35-71","server":"192.168.35.71","port":22888,"username":"zeaslity","password":"password","udp":true} - {"type":"socks5","name":"onetools-35-71","server":"192.168.35.71","port":22888,"username":"zeaslity","password":"password","udp":true}
- {"type":"socks5","name":"tc-shanghai-seoul","server":"42.192.52.227","port":22888,"username":"zeaslity","password":"lovemm.23","udp":true} - {"type":"socks5","name":"Seoul-F-Shanghai-TC","server":"42.192.52.227","port":22888,"username":"zeaslity","password":"lovemm.23","udp":true}
proxy-groups: proxy-groups:
- name: 🚀 节点选择 - name: 🚀 节点选择
type: select type: select
proxies: proxies:
- ♻️ 自动选择 - ♻️ 自动选择
- DIRECT - DIRECT
- us-cente-free - LosAngels-BanH-Trojan
- us-central-free
- Seoul-Trojan - Seoul-Trojan
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan - HongK-Tencent-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
- onetools-35-71 - onetools-35-71
- tc-shanghai-seoul - Seoul-F-Shanghai-TC
- name: ♻️ 自动选择 - name: ♻️ 自动选择
type: url-test type: url-test
url: http://www.gstatic.com/generate_204 url: http://www.gstatic.com/generate_204
interval: 300 interval: 300
tolerance: 50 tolerance: 50
proxies: proxies:
- us-cente-free - LosAngels-BanH-Trojan
- HongK-Tencent-Trojan
- us-central-free
- Seoul-Trojan - Seoul-Trojan
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
- tc-shanghai-seoul - Seoul-F-Shanghai-TC
- name: 🌍 国外媒体 - name: 🌍 国外媒体
type: select type: select
proxies: proxies:
- 🚀 节点选择 - 🚀 节点选择
- ♻️ 自动选择 - ♻️ 自动选择
- 🎯 全球直连 - 🎯 全球直连
- us-cente-free - LosAngels-BanH-Trojan
- us-central-free
- Seoul-Trojan - Seoul-Trojan
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan - HongK-Tencent-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
- name: 📲 电报信息 - name: 📲 电报信息
type: select type: select
proxies: proxies:
- 🚀 节点选择 - 🚀 节点选择
- 🎯 全球直连 - 🎯 全球直连
- us-cente-free - LosAngels-BanH-Trojan
- HongK-Tencent-Trojan
- us-central-free
- Seoul-Trojan - Seoul-Trojan
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
- name: Ⓜ️ 微软服务 - name: Ⓜ️ 微软服务
type: select type: select
proxies: proxies:
- 🎯 全球直连 - 🎯 全球直连
- 🚀 节点选择 - 🚀 节点选择
- us-cente-free - LosAngels-BanH-Trojan
- HongK-Tencent-Trojan
- Seoul-Trojan - Seoul-Trojan
- us-central-free
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
- name: 🍎 苹果服务 - name: 🍎 苹果服务
type: select type: select
proxies: proxies:
- 🚀 节点选择 - 🚀 节点选择
- 🎯 全球直连 - 🎯 全球直连
- us-cente-free - LosAngels-BanH-Trojan
- HongK-Tencent-Trojan
- us-central-free
- Seoul-Trojan - Seoul-Trojan
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
- name: 💩 工作环境 - name: 💩 工作环境
type: select type: select
proxies: proxies:
- DIRECT - DIRECT
- 🚀 节点选择
- ♻️ 自动选择
- name: 🎯 全球直连 - name: 🎯 全球直连
type: select type: select
proxies: proxies:
@@ -166,13 +171,14 @@ proxy-groups:
- 🚀 节点选择 - 🚀 节点选择
- 🎯 全球直连 - 🎯 全球直连
- ♻️ 自动选择 - ♻️ 自动选择
- us-cente-free - LosAngels-BanH-Trojan
- HongK-Tencent-Trojan
- us-central-free
- Seoul-Trojan - Seoul-Trojan
- Osaka-Trojan - Osaka-Trojan
- Tokyo-Trojan - Tokyo-Trojan
- Pheonix-Trojan - Phoenix-Trojan
- Seoul-arm64-01-Trojan - Seoul-arm64-01-Trojan
- Tencent-Hkong-Trojan
- Tencent-HK-11.24 - Tencent-HK-11.24
rules: rules:
- DOMAIN-SUFFIX,uavcmlc.com,💩 工作环境 - DOMAIN-SUFFIX,uavcmlc.com,💩 工作环境

View File

@@ -1,294 +0,0 @@
{
"log": {
"loglevel": "warning",
"access": "/var/log/xray/access.log",
"error": "/var/log/xray/error.log"
},
"inbounds": [
{
"protocol": "socks",
"tag": "proxy-tcp-seoul",
"port": 29999,
"listen": "0.0.0.0",
"settings": {
"auth": "noauth",
"udp": true,
"userLevel": 0
}
},
{
"tag": "in-vmess-tcp-seoul",
"port": 19999,
"listen": "0.0.0.0",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "7318178c-5583-40dd-996c-a0add1f8fc1e",
"level": 0,
"email": "不能用,腾讯云的ssl阻断机制 会封IP"
}
]
},
"streamSettings": {
"network": "tcp",
"security": "auto",
"tcpSettings": {
"acceptProxyProtocol": false,
"header": {
"type": "http",
"request": {
"path": [
"/v2ice-vmess-tcp-seoul"
]
}
}
}
}
},
{
"tag": "in-vmess-tcp-tokyo",
"port": 19998,
"listen": "0.0.0.0",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "89cb7e1d-9833-402c-9c1f-aafe8291510a",
"level": 0,
"email": "ice@gmail.com"
}
]
},
"streamSettings": {
"network": "tcp",
"security": "auto",
"tcpSettings": {
"acceptProxyProtocol": false,
"header": {
"type": "http",
"request": {
"path": [
"/v2ice-vmess-tcp-tokyo"
]
}
}
}
}
},
{
"tag": "in-vmess-vless-seoul4",
"port": 19997,
"listen": "0.0.0.0",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "eb574953-52fa-442e-a724-d3a21c72e658",
"level": 0,
"email": "ice@gmail.com"
}
]
},
"streamSettings": {
"network": "tcp",
"security": "auto",
"tcpSettings": {
"acceptProxyProtocol": false,
"header": {
"type": "http",
"request": {
"path": [
"/vmess-vless-seoul4"
]
}
}
}
}
}
],
"outbounds": [
{
"tag": "direct-out",
"protocol": "freedom"
},
{
"tag": "block",
"protocol": "blackhole"
},
{
"tag": "oracle-seoul4-vmess-websocket",
"protocol": "vmess",
"settings": {
"vnext": [
{
"address": "140.238.14.103",
"port": 19995,
"users": [
{
"id": "becaca40-b457-4572-9b46-ed66ecca7b4e",
"alterId": 0,
"email": "ice@cc.com",
"security": "auto"
}
]
}
]
},
"streamSettings": {
"network": "ws",
"wsSettings": {
"path": "/v2ice-default-ws"
}
},
"mux": {
"enabled": true,
"concurrency": 8
}
},
{
"tag": "oracle-seoul4-vless",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "140.238.14.103",
"port": 19990,
"users": [
{
"id": "adbd84eb-15fe-4c62-931c-b471791672ad",
"flow": "xtls-rprx-direct",
"security": "auto",
"encryption": "none",
"level": 0
}
]
}
]
},
"streamSettings": {
"network": "tcp",
"security": "xtls",
"xtlsSettings": {
"serverName": "xx.s4.cc.hh.107421.xyz",
"allowInsecure": true,
"rejectUnknownSni": false,
"alpn": [
"h2",
"http/1.1"
],
"minVersion": "1.2",
"maxVersion": "1.3"
}
}
},
{
"tag": "oracle-seoul4-trojan",
"protocol": "trojan",
"settings": {
"servers": [
{
"address": "140.238.14.103",
"port": 19990,
"password": "loveff.22",
"level": 0,
"flow": "xtls-rprx-direct"
}
]
},
"streamSettings": {
"network": "tcp",
"security": "tls",
"tlsSettings": {
"serverName": "xx.s4.cc.hh.107421.xyz"
}
},
"mux": {
"enabled": true,
"concurrency": 8
}
},
{
"tag": "oracle-seoul4-vmess-ws",
"protocol": "vmess",
"settings": {
"vnext": [
{
"address": "140.238.14.103",
"port": 19990,
"users": [
{
"id": "c08e68f1-283c-4f91-9603-0b80484bb283",
"security": "none",
"level": 0
}
]
}
]
},
"streamSettings": {
"network": "ws",
"security": "tls",
"tlsSettings": {
"serverName": "xx.s4.cc.hh.107421.xyz"
},
"wsSettings": {
"path": "/v2ice-vmess-ws"
}
},
"mux": {
"enabled": true,
"concurrency": 8
}
}
],
"routing": {
"domainStrategy": "AsIs",
"domainMatcher": "hybrid",
"balancers": [
{
"tag": "seoul-4-balancer",
"selector": [
"oracle-seoul"
]
}
],
"rules": [
{
"type": "field",
"domain": [
"geosite:category-ads-all"
],
"outboundTag": "block"
},
{
"type": "field",
"domain": [
"geosite:cn",
"geosite:private"
],
"outboundTag": "direct-out"
},
{
"type": "field",
"inboundTag": "in-vmess-tcp-seoul",
"outboundTag": "oracle-seoul4-vmess-websocket"
},
{
"type": "field",
"inboundTag": "proxy-tcp-seoul",
"outboundTag": "oracle-seoul4-vmess-websocket"
},
{
"type": "field",
"inboundTag": "in-vmess-tcp-tokyo",
"outboundTag": "oracle-tokyo1-vmess-websocket"
},
{
"type": "field",
"inboundTag": "in-vmess-vless-seoul4",
"outboundTag": "oracle-seoul4-vless"
}
]
}
}

View File

@@ -1,3 +0,0 @@
## Xray官方文档写的非常好
https://xtls.github.io/document/level-1/fallbacks-lv1.html

View File

@@ -1,220 +0,0 @@
{
"log": {
"access": "/var/log/xray/access.log",
"error": "/var/log/xray/error.log",
"loglevel": "warning"
},
"inbounds": [
{
"port": 19990,
"protocol": "vless",
"settings": {
"clients": [
{
"id": "adbd84eb-15fe-4c62-931c-b471791672ad",
"flow": "xtls-rprx-direct",
"level": 0,
"email": "ice@gmail.com"
}
],
"decryption": "none",
"fallbacks": [
{
"dest": 19999,
"xver": 1
},
{
"path": "/v2ice-vless-ws",
"dest": 19998,
"xver": 1
},
{
"path": "/v2ice-vmess-tcp",
"dest": 19997,
"xver": 1
},
{
"path": "/v2ice-vmess-ws",
"dest": 19996,
"xver": 1
}
]
},
"streamSettings": {
"network": "tcp",
"security": "xtls",
"xtlsSettings": {
"alpn": [
"h2",
"http/1.1"
],
"certificates": [
{
"certificateFile": "/root/.acme.sh/xx.s4.cc.hh.107421.xyz_ecc/fullchain.cer",
"keyFile": "/root/.acme.sh/xx.s4.cc.hh.107421.xyz_ecc/xx.s4.cc.hh.107421.xyz.key"
}
]
},
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls"
]
}
}
},
{
"port": 19999,
"listen": "127.0.0.1",
"protocol": "trojan",
"settings": {
"clients": [
{
"password": "loveff.22",
"level": 0,
"email": "ice@gmail.com.cn",
"flow": "xtls-rprx-direct"
}
],
"fallbacks": [
{
"dest": 8080,
"alpn": "",
"xver": 1
},
{
"dest": 8081,
"alpn": "h2",
"xver": 1
}
]
},
"streamSettings": {
"network": "tcp",
"security": "xtls",
"xtlsSettings": {
"alpn": [
"h2",
"http/1.1"
],
"certificates": [
{
"certificateFile": "/root/.acme.sh/xx.s4.cc.hh.107421.xyz_ecc/fullchain.cer",
"keyFile": "/root/.acme.sh/xx.s4.cc.hh.107421.xyz_ecc/xx.s4.cc.hh.107421.xyz.key"
}
]
},
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls"
]
}
}
},
{
"port": 19998,
"listen": "127.0.0.1",
"protocol": "vless",
"settings": {
"clients": [
{
"id": "adbd84eb-15fe-4c62-931c-b471791672ad",
"level": 0,
"email": "ice@gmail.com"
}
],
"decryption": "none"
},
"streamSettings": {
"network": "ws",
"security": "auto",
"wsSettings": {
"acceptProxyProtocol": true,
"path": "/v2ice-vless-ws"
}
}
},
{
"port": 19997,
"listen": "127.0.0.1",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "3da8aa3f-ddd7-49bf-94ba-950593f24471",
"level": 0,
"email": "ice@gmail.com"
}
]
},
"streamSettings": {
"network": "tcp",
"security": "auto",
"tcpSettings": {
"acceptProxyProtocol": true,
"header": {
"type": "http",
"request": {
"path": [
"/v2ice-vmess-tcp"
]
}
}
}
}
},
{
"port": 19996,
"listen": "127.0.0.1",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "c08e68f1-283c-4f91-9603-0b80484bb283",
"level": 0,
"email": "ice@gmail.com"
}
]
},
"streamSettings": {
"network": "ws",
"security": "auto",
"wsSettings": {
"acceptProxyProtocol": true,
"path": "/v2ice-vmess-ws"
}
}
},
{
"port": 19995,
"listen": "0.0.0.0",
"protocol": "vmess",
"settings": {
"clients": [
{
"id": "becaca40-b457-4572-9b46-ed66ecca7b4e",
"level": 0,
"alterId": 0,
"email": "ice@cc.com"
}
]
},
"streamSettings": {
"network": "ws",
"security": "auto",
"wsSettings": {
"acceptProxyProtocol": false,
"path": "/v2ice-default-ws"
}
}
}
],
"outbounds": [
{
"protocol": "freedom"
}
]
}

View File

@@ -1,64 +0,0 @@
{
"log": {
"access": "/var/log/xray/access.log",
"error": "/var/log/xray/error.log",
"loglevel": "warning"
},
"inbounds": [
{
"port": 19990,
"protocol": "vless",
"settings": {
"clients": [
{
"id": "adbd84eb-15fe-4c62-931c-b471791672ad",
"flow": "xtls-rprx-direct",
"level": 0,
"email": "ice@gmail.com"
}
],
"decryption": "none",
"fallbacks": [
{
"dest": 60000,
"alpn": "",
"xver": 1
},
{
"dest": 60001,
"alpn": "h2",
"xver": 1
}
]
},
"streamSettings": {
"network": "tcp",
"security": "xtls",
"xtlsSettings": {
"alpn": [
"h2",
"http/1.1"
],
"certificates": [
{
"certificateFile": "/root/.acme.sh/xx.s4.cc.hh.107421.xyz_ecc/fullchain.cer",
"keyFile": "/root/.acme.sh/xx.s4.cc.hh.107421.xyz_ecc/xx.s4.cc.hh.107421.xyz.key"
}
]
},
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls"
]
}
}
}
],
"outbounds": [
{
"protocol": "freedom"
}
]
}

View File

@@ -1,30 +0,0 @@
server {
listen 443 ssl;
listen [::]:443 ssl;
ssl_certificate /etc/nginx/ssl/ws.s1.ccc.107421.xyz/ws.s1.ccc.107421.xyz.cert.pem;
ssl_certificate_key /etc/nginx/ssl/ws.s1.ccc.107421.xyz/ws.s1.ccc.107421.xyz.key.pem;
ssl_session_timeout 1d;
ssl_session_cache shared:MozSSL:10m;
ssl_session_tickets off;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers off;
server_name xx.s4.cc.hh.107421.xyz;
location /v2ice { # 与 V2Ray 配置中的 path 保持一致
if ($http_upgrade != "websocket") { # WebSocket协商失败时返回404
return 404;
}
proxy_redirect off;
proxy_pass http://127.0.0.1:12000; # 假设WebSocket监听在环回地址的10000端口上
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
# Show real IP in v2ray access.log
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
}

View File

@@ -1,19 +0,0 @@
## Xray官方文档写的非常好
https://xtls.github.io/document/level-1/fallbacks-lv1.html
这一段配置用人话要怎么解释呢?
Xray 的入站端口 (inbound port) 是 443
即由 Xray 负责监听 443 端口的 HTTPS 流量,并使用 certificates 项下设定的 TLS 证书来进行验证
Xray 的入站协议 (inbound protocol) 是 vless
1. vless 协议流量直接流入 Xray 中做后续处理
2. 非 VLESS 协议流量有 4 个不同的回落目标:
1. path 为 websocket 的流量,回落给端口 1234 后续处理
2. path 为 vmesstcp 的流量,回落给端口 2345 后续处理
3. path 为 vmessws 的流量,回落给端口 3456 后续处理
4. 其它所有流量,回落给端口 1310 后续处理
3. xver 为 1 表示开启 proxy protocol 功能,向后传递来源真实 IP

Binary file not shown.

Before

Width:  |  Height:  |  Size: 72 KiB

View File

@@ -2,8 +2,9 @@
# 香港 xx.tc.hk.go.107421.xyz # 香港 xx.tc.hk.go.107421.xyz
# Seoul-arm64-01 xx.s0.yy.ac.107421.xyz # Seoul-arm64-01 xx.s0.yy.ac.107421.xyz
# Seoul-amd64-04 xx.s4.cc.hh.107421.xyz # Seoul-amd64-04 xx.s4.cc.hh.107421.xyz
# LosAngeles-amd64-01 xx.l4.cc.nn.107421.xyz
export DOMAIN_NAME=xx.s4.cc.hh.107421.xyz export DOMAIN_NAME=xx.l4.cc.nn.107421.xyz
export CF_Token="oXJRP5XI8Zhipa_PtYtB_jy6qWL0I9BosrJEYE8p" export CF_Token="oXJRP5XI8Zhipa_PtYtB_jy6qWL0I9BosrJEYE8p"
export CF_Account_ID="dfaadeb83406ef5ad35da02617af9191" export CF_Account_ID="dfaadeb83406ef5ad35da02617af9191"
@@ -11,9 +12,10 @@ export CF_Zone_ID="511894a4f1357feb905e974e16241ebb"
acme.sh --issue --dns dns_cf -d ${DOMAIN_NAME} --keylength ec-256 acme.sh --issue --dns dns_cf -d ${DOMAIN_NAME} --keylength ec-256
export DOMAIN_NAME=xx.s4.cc.hh.107421.xyz
chmod -R 644 /root/.acme.sh/${DOMAIN_NAME}_ecc/fullchain.cer chmod -R 644 /root/.acme.sh/${DOMAIN_NAME}_ecc/fullchain.cer
chmod -R 644 /root/.acme.sh/${DOMAIN_NAME}_ecc/${DOMAIN_NAME}.key chmod -R 644 /root/.acme.sh/${DOMAIN_NAME}_ecc/${DOMAIN_NAME}.key
systemctl restart xray && sleep 1 && systemctl status xray systemctl restart xray && sleep 1 && systemctl status xray
curl https://get.acme.sh | sh -s email=ice@qq.com

View File

@@ -0,0 +1,39 @@
{
"inbounds": [
{
"protocol": "trojan",
"listen": "0.0.0.0",
"port": 443,
"settings": {
"clients": [
{
"password": "V2ryStr0ngP0ss",
"email": "lovemm@107421.xyz"
}
]
},
"streamSettings": {
"network": "tcp",
"security": "tls",
"tlsSettings": {
"alpn": [
"h2",
"http/1.1"
],
"certificates": [
{
"certificateFile": "/root/.acme.sh/xx.l4.cc.nn.107421.xyz_ecc/fullchain.cer",
"keyFile": "/root/.acme.sh/xx.l4.cc.nn.107421.xyz_ecc/xx.l4.cc.nn.107421.xyz.key"
}
]
}
},
"tag": "LosAngels-amd64-01"
}
],
"outbounds": [
{
"protocol": "freedom"
}
]
}

View File

@@ -0,0 +1,19 @@
# 默认禁止所有其他端口
firewall-cmd --set-default-zone=drop
# 允许从任何源访问 22333、443、80 端口的 TCP 和 UDP 流量
firewall-cmd --permanent --add-port=22333/tcp
firewall-cmd --permanent --add-port=22333/udp
firewall-cmd --permanent --add-port=443/tcp
firewall-cmd --permanent --add-port=443/udp
firewall-cmd --permanent --add-port=80/tcp
firewall-cmd --permanent --add-port=80/udp
# 允许来自20000-30000的tcp udp端口
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source-port port-range="20000-30000" protocol="tcp" accept'
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source-port port-range="20000-30000" protocol="udp" accept'
# 重新载入防火墙规则
firewall-cmd --reload

View File

@@ -1,7 +1,8 @@
#!/bin/bash #!/bin/bash
kernel_config_file=/etc/sysctl.d/import_kernel.conf
cat >>/etc/sysctl.d/import_kernel.conf <<EOF cat >> ${kernel_config_file} <<EOF
# 开启bbr # 开启bbr
net.ipv4.tcp_fastopen = 3 net.ipv4.tcp_fastopen = 3
net.core.default_qdisc = fq net.core.default_qdisc = fq
@@ -30,3 +31,5 @@ net.ipv4.neigh.default.gc_stale_time = 120
# 增加哈希表大小可以提高路由查找性能。 # 增加哈希表大小可以提高路由查找性能。
net.ipv4.neigh.default.hash_buckets = 1024 net.ipv4.neigh.default.hash_buckets = 1024
EOF EOF
sysctl -p ${kernel_config_file}