OpenWrt透明代理方案

详细的原理请点击293号档案DNS部分已失效,请考虑使用ChinaDNS项目。11月3日最新更新:

ipset create vpn nethashipset create rst ipporthash timeout 90iptables -t nat -A PREROUTING -p tcp -m set --match-set vpn dst -j REDIRECT --to-port 1080iptables -t nat -A PREROUTING -p tcp -m set --match-set rst dst,dst -j REDIRECT --to-port 1080iptables -t mangle -A PREROUTING -p udp --sport 53 -m u32 --u32 "22&0xFFFF@16=0x3B1803AD,0x253D369E" -j DROP #genericiptables -t mangle -A PREROUTING -p udp --sport 53 -m u32 --u32 "22&0xFFFF@16=0x5D2E0859,0x4E10310F,0xF3B9BB27,0x2E52AE44,0x0807C62D,0xCB620741,0x9F6A794B,0x2E52AE44" -j DROP #webcache.googleusercontent.comiptables -t mangle -A PREROUTING -p udp --sport 53 -m u32 --u32 "22&0xFFFF@16=0x4A7D2766,0x4A7D2771,0x4A7D7F66,0x4A7D9B66,0xD155E58A" -j DROP #plus.google.comiptables -t mangle -A PREROUTING -s 192.168/16 -j RETURNiptables -t mangle -A PREROUTING -p tcp --tcp-flags RST RST -m recent --name rst --rcheck --seconds 1 --hitcount 2 -j SET --add-set rst src,srciptables -t mangle -A PREROUTING -p tcp --tcp-flags RST RST -m recent --name rst --setipset add vpn 74.125.0.0/16 #Googleipset add vpn 173.194.0.0/16 #Googleipset add vpn 199.59.148.0/22 #Twitter

3 thoughts on “OpenWrt透明代理方案

  1. Pingback: 基于DNS污染、关键词阻断、IP封锁的透明防火墙方案 | LXF's X Factory

Leave a Reply

Your email address will not be published. Required fields are marked *

Using REAL email address will help you receive reply notifications.