{ "log": { "level": "info", "timestamp": true }, // ========= DNS:无泄露方案 ========= "dns": { "servers": [ { // 境外加密 DNS(走 TLS) "tag": "google", "type": "tls", "server": "8.8.8.8" }, { // 境内加密 DNS(走 DoH,223.5.5.5 是阿里) "tag": "local", "type": "https", "server": "223.5.5.5" // 也可以改成 https://dns.alidns.com/dns-query 这种域名形式, // 但那样需要再配 domain_resolver,这里用 IP 省事 } ], "rules": [ { // 中国域名:用境内 DoH,解析快一点 "rule_set": "geosite-geolocation-cn", "server": "local" }, { // 其它(非 CN)且 IP 在中国的情况:走 8.8.8.8,但伪装成中国 IP(ECS) "type": "logical", "mode": "and", "rules": [ { "rule_set": "geosite-geolocation-!cn", "invert": true }, { "rule_set": "geoip-cn" } ], "server": "google", "client_subnet": "114.114.114.114/24" } ], "independent_cache": true, "strategy": "ipv4_only" }, // ========= 入站:TUN,全局透明代理 ========= "inbounds": [ { "type": "tun", "tag": "tun-in", "address": [ "172.19.0.1/30", "fdfe:dcba:9876::1/126" ], "auto_route": true, // Linux 可同时打开 auto_redirect // "auto_redirect": true, "strict_route": true } ], // ========= 出站:代理 + 直连 + 拦截 ========= "outbounds": [ { "type": "hysteria2", "tag": "proxy", "server": "166.88.55.241", // VPS ip "server_port": 1443, "up_mbps": 20, //上传速率,实际填写,过大会导致流量浪费 "down_mbps": 150, //下载速率,实际填写,过大会导致流量浪费 "password": "LER1SPLqYBFp3UUv7JQBe+6b", //hysteria2 服务密码 "tls": { "enabled": true, "server_name": "bing.com", //若域名搭建,请填写域名,若IP搭建,请填写 bing.com "insecure": true //若域名搭建,请填写 false,若IP搭建,请填写 true } }, { "type": "direct", "tag": "direct" }, { "type": "block", "tag": "block" } ], // ========= 路由:无 DNS 泄露 + 绕行中国 ========= "route": { // 默认所有没被规则命中的流量,走 proxy "final": "proxy", "default_domain_resolver": "google", "auto_detect_interface": true, "rule_set": [ { "type": "remote", "tag": "geosite-geolocation-cn", "format": "binary", "url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-geolocation-cn.srs" }, { "type": "remote", "tag": "geosite-geolocation-!cn", "format": "binary", "url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-geolocation-!cn.srs" }, { "type": "remote", "tag": "geoip-cn", "format": "binary", "url": "https://raw.githubusercontent.com/SagerNet/sing-geoip/rule-set/geoip-cn.srs" } ], "rules": [ { // 协议探测(域名嗅探) "action": "sniff" }, { // 劫持所有 DNS(包括纯 IP:53 流量) "type": "logical", "mode": "or", "rules": [ { "protocol": "dns" }, { "port": 53 } ], "action": "hijack-dns" }, { // 内网地址一律直连 "ip_is_private": true, "outbound": "direct" }, { // 阻止常见绕过方式:DoT / QUIC / STUN "type": "logical", "mode": "or", "rules": [ { "port": 853 // DoT }, { "network": "udp", "port": 443 // QUIC }, { "protocol": "stun" } ], "action": "reject" }, { // 中国域名直连 "rule_set": "geosite-geolocation-cn", "outbound": "direct" }, { // 中国 IP 且不是明显非 CN 域名的,也直连 "type": "logical", "mode": "and", "rules": [ { "rule_set": "geoip-cn" }, { "rule_set": "geosite-geolocation-!cn", "invert": true } ], "outbound": "direct" } // 其它全部走 final = proxy ] }, // ========= 实验性:缓存 + Clash API(可选) ========= "experimental": { "cache_file": { "enabled": true, "store_rdrc": true }, "clash_api": { "default_mode": "Enhanced" } } }