For most situations in Cernet, access to Internet through IPv6 takes no charge, while IPv4 is charged normally. So we can escape the bills if our traffic are fully IPv6.
Deploy a IPv4/IPv6 dual-stack server in China (for Chinese users) or out if you are in need of anti-censor or anti-block. You can also deploy two respectively for traffic splitting.
Through WireGuard (China available) or any anti-block protocols (for overseas), you will connect to the proxy server through IPv6, which will access Internet normally and transport data to you through IPv6.
If you aren’t eager to self-host, you can also choose proxy providers that support IPv6.
You will need a local software to split traffic if you do so.
Proxy template
# wireguard_config.conf
[Interface]
Address = x.x.x.1/24
Address = x:x::1/64
ListenPort = 51820
PrivateKey = <key>
PostUp = iptables -t nat -A POSTROUTING -s x.x.x.0/24 -o eth0 -j MASQUERADE
PostUp = ip6tables -t nat -A POSTROUTING -s x:x::/64 -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -s x.x.x.0/24 -o eth0 -j MASQUERADE
PostDown = ip6tables -t nat -D POSTROUTING -s x:x::/64 -o eth0 -j MASQUERADE
[Peer]
PublicKey = <key>
AllowedIPs = x.x.x.2/32, x:x::2/128
[Peer]
PublicKey = <key>
AllowedIPs = x.x.x.3/32, x:x::3/128
/* xray_config.json */
{
"log": {
"loglevel": "debug",
"dnsLog": true,
"maskAddress": "quarter",
"access": "/var/log/xray/access.log",
"error": "/var/log/xray/error.log"
},
"inbounds": [
{
"listen": "0.0.0.0",
"port": 443,
"protocol": "vless",
"settings": {
"clients": [
{
"id": "<uuid>",
"email": "<string>"
},
{
"id": "<uuid>",
"email": "<string>"
}
],
"decryption": "none"
},
"streamSettings": {
"network": "xhttp",
"xhttpSettings": {
"host": "<domain>",
"path": "/<string>",
"mode": "auto"
},
"security": "reality",
"realitySettings": {
"target": "<domain>:443",
"serverNames": [
"<domain>"
],
"privateKey": "<key>",
"publicKey": "<key>",
"shortIds": [
"<hex_num>"
]
}
}
}
],
"outbounds": [
{
"protocol": "freedom"
}
]
}
# clash_config.yaml
allow-lan: false
bind-address: '*'
mode: rule
log-level: debug
ipv6: true
keep-alive-idle: 600
keep-alive-interval: 15
find-process-mode: always
external-controller: 127.0.0.1:9090
unified-delay: true
tcp-concurrent: true
geodata-mode: true
geo-auto-update: true
geo-update-interval: 24
geox-url:
geoip: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/geoip.dat'
geosite: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/v2ray-rules-dat@release/geosite.dat'
mmdb: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/GeoLite2-Country.mmdb'
asn: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/GeoLite2-ASN.mmdb'
dns:
enable: true
prefer-h3: false
listen: 127.0.0.1:53
ipv6: true
default-nameserver:
- 223.5.5.5
- 119.29.29.29
- 2400:3200::1
- 2402:4e00::0
# Redir-Host
nameserver-policy:
'geosite:private': system
'geosite:category-ads-all': rcode://success
'geosite:cn':
- https://dns.alidns.com/dns-query#cloud-cn
- https://doh.pub/dns-query#cloud-cn
nameserver:
- https://dns.cloudflare.com/dns-query#cloud-out
- https://dns.google/dns-query#cloud-out
proxy-server-nameserver:
- https://dns.alidns.com/dns-query
- https://doh.pub/dns-query
# Fake-IP
enhanced-mode: fake-ip
fake-ip-range: 198.18.0.1/16
fake-ip-range6: fdfe:dcba:9876::1/64
fake-ip-filter:
- 'geosite:private'
nameserver-policy:
'geosite:private': system
'geosite:category-ads-all': rcode://success
nameserver:
- https://dns.alidns.com/dns-query
- https://doh.pub/dns-query
sniffer:
enable: true
force-dns-mapping: true
parse-pure-ip: true
override-destination: false
sniff:
HTTP:
ports:
- 80
- 8080-8880
override-destination: true
TLS:
ports:
- 443
- 8443
QUIC:
ports:
- 443
- 8443
tun:
enable: true
stack: system
auto-route: true
auto-redirect: true
auto-detect-interface: true
dns-hijack:
- any:53
- tcp://any:53
strict-route: true
# Redir-Host
rules:
- GEOIP,private,DIRECT
- GEOIP,cn,cloud-cn
- MATCH,cloud-out
# Fake-IP
rules:
- GEOSITE,private,DIRECT
- GEOSITE,category-ads-all,REJECT
- GEOSITE,cn,cloud-cn
- GEOIP,private,DIRECT,no-resolve
- GEOIP,cn,cloud-cn,no-resolve
- MATCH,cloud-out
proxy-groups:
- name: GLOBAL
type: select
proxies:
- DIRECT
- REJECT
- cloud-cn
- cloud-out
- name: cloud-cn
type: select
proxies:
- DIRECT
- REJECT
- proxy-cn
- name: cloud-out
type: select
proxies:
- DIRECT
- REJECT
- proxy-out
proxies:
- name: proxy-cn
type: wireguard
private-key: <key>
server: <ip>
port: 51820
ip: <ip>
ipv6: <ip>
public-key: <key>
allowed-ips: ['0.0.0.0/0']
udp: true
- name: proxy-out
type: vless
server: <ip>
port: 443
uuid: <uuid>
udp: true
tls: true
network: xhttp
client-fingerprint: chrome
alpn:
- h2
servername: <domain>
xhttp-opts:
path: <string>
host: <domain>
reality-opts:
public-key: <key>
short-id: <hex_num>