For most situations in Cernet, access to Internet through IPv6 takes no charge, while IPv4 is charged normally. So we can escape the bills if our traffic are fully IPv6.

Deploy a IPv4/IPv6 dual-stack server in China (for Chinese users) or out if you are in need of anti-censor or anti-block. You can also deploy two respectively for traffic splitting.

Through WireGuard (China available) or any anti-block protocols (for overseas), you will connect to the proxy server through IPv6, which will access Internet normally and transport data to you through IPv6.

If you aren’t eager to self-host, you can also choose proxy providers that support IPv6.

You will need a local software to split traffic if you do so.

Proxy template

# wireguard_config.conf

[Interface]
Address = x.x.x.1/24
Address = x:x::1/64
ListenPort = 51820
PrivateKey = <key>

PostUp = iptables -t nat -A POSTROUTING -s x.x.x.0/24 -o eth0 -j MASQUERADE
PostUp = ip6tables -t nat -A POSTROUTING -s x:x::/64 -o eth0 -j MASQUERADE

PostDown = iptables -t nat -D POSTROUTING -s x.x.x.0/24 -o eth0 -j MASQUERADE
PostDown = ip6tables -t nat -D POSTROUTING -s x:x::/64 -o eth0 -j MASQUERADE

[Peer]
PublicKey = <key>
AllowedIPs = x.x.x.2/32, x:x::2/128

[Peer]
PublicKey = <key>
AllowedIPs = x.x.x.3/32, x:x::3/128
/* xray_config.json */

{
  "log": {
    "loglevel": "debug",
    "dnsLog": true,
    "maskAddress": "quarter",
    "access": "/var/log/xray/access.log",
    "error": "/var/log/xray/error.log"
  },

  "inbounds": [
    {
      "listen": "0.0.0.0",
      "port": 443,
      "protocol": "vless",
      
      "settings": {
        "clients": [
          {
            "id": "<uuid>",
            "email": "<string>"
          },
          {
            "id": "<uuid>",
            "email": "<string>"
          }
        ],
        "decryption": "none"
      },
      
      "streamSettings": {
        "network": "xhttp",
        "xhttpSettings": {
          "host": "<domain>",
          "path": "/<string>",
          "mode": "auto"
        },
        
        "security": "reality",
        "realitySettings": {
          "target": "<domain>:443",
          "serverNames": [
            "<domain>"
          ],
          "privateKey": "<key>",
          "publicKey": "<key>",
          "shortIds": [
            "<hex_num>"
          ]
        }
      }
    }
  ],
  
  "outbounds": [
    {
      "protocol": "freedom"
    }
  ]
}
# clash_config.yaml

allow-lan: false
bind-address: '*'
mode: rule
log-level: debug
ipv6: true
keep-alive-idle: 600
keep-alive-interval: 15
find-process-mode: always
external-controller: 127.0.0.1:9090
unified-delay: true
tcp-concurrent: true
geodata-mode: true
geo-auto-update: true
geo-update-interval: 24
geox-url:
  geoip: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/geoip.dat'
  geosite: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/v2ray-rules-dat@release/geosite.dat'
  mmdb: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/GeoLite2-Country.mmdb'
  asn: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/GeoLite2-ASN.mmdb'

dns:
  enable: true
  prefer-h3: false
  listen: 127.0.0.1:53
  ipv6: true
  default-nameserver:
    - 223.5.5.5
    - 119.29.29.29
    - 2400:3200::1
    - 2402:4e00::0
    
  # Redir-Host
  nameserver-policy:
    'geosite:private': system
    'geosite:category-ads-all': rcode://success
    'geosite:cn':
      - https://dns.alidns.com/dns-query#cloud-cn
      - https://doh.pub/dns-query#cloud-cn
  nameserver:
    - https://dns.cloudflare.com/dns-query#cloud-out
    - https://dns.google/dns-query#cloud-out
  proxy-server-nameserver:
    - https://dns.alidns.com/dns-query
    - https://doh.pub/dns-query

  # Fake-IP
  enhanced-mode: fake-ip
  fake-ip-range: 198.18.0.1/16
  fake-ip-range6: fdfe:dcba:9876::1/64
  fake-ip-filter:
    - 'geosite:private'
  nameserver-policy:
    'geosite:private': system
    'geosite:category-ads-all': rcode://success
  nameserver:
    - https://dns.alidns.com/dns-query
    - https://doh.pub/dns-query
    
sniffer:
  enable: true
  force-dns-mapping: true
  parse-pure-ip: true
  override-destination: false
  sniff:
    HTTP:
      ports:
        - 80
        - 8080-8880
      override-destination: true
    TLS:
      ports:
        - 443
        - 8443
    QUIC:
      ports:
        - 443
        - 8443
        
tun:
  enable: true
  stack: system
  auto-route: true
  auto-redirect: true
  auto-detect-interface: true
  dns-hijack:
    - any:53
    - tcp://any:53
  strict-route: true
  
# Redir-Host
rules:
  - GEOIP,private,DIRECT
  - GEOIP,cn,cloud-cn
  - MATCH,cloud-out
  
# Fake-IP
rules:
  - GEOSITE,private,DIRECT
  - GEOSITE,category-ads-all,REJECT
  - GEOSITE,cn,cloud-cn
  - GEOIP,private,DIRECT,no-resolve
  - GEOIP,cn,cloud-cn,no-resolve
  - MATCH,cloud-out
  
proxy-groups:
  - name: GLOBAL
    type: select
    proxies:
      - DIRECT
      - REJECT
      - cloud-cn
      - cloud-out
  - name: cloud-cn
    type: select
    proxies:
      - DIRECT
      - REJECT
      - proxy-cn
  - name: cloud-out
    type: select
    proxies:
      - DIRECT
      - REJECT
      - proxy-out
      
proxies:
  - name: proxy-cn
    type: wireguard
    private-key: <key>
    server: <ip>
    port: 51820
    ip: <ip>
    ipv6: <ip>
    public-key: <key>
    allowed-ips: ['0.0.0.0/0']
    udp: true
  - name: proxy-out
    type: vless
    server: <ip>
    port: 443
    uuid: <uuid>
    udp: true
    tls: true
    network: xhttp
    client-fingerprint: chrome
    alpn:
      - h2
    servername: <domain>
    xhttp-opts:
      path: <string>
      host: <domain>
    reality-opts:
      public-key: <key>
      short-id: <hex_num>

Reference