校园网络访问互联网,一般 IPv4 收费而 IPv6 免费,故若本地流量为纯 IPv6 则可免流。
在国内部署一台 IPv4/IPv6 双栈服务器。若您有抗审查或抗封锁的需求,在海外部署。或国内、海外各一台,作分流用。
通过 WireGuard(国内)或任意抗封锁协议(海外)等,即可 IPv6 连接到服务器。此时服务器作为代理,可正常访问 IPv4/IPv6 互联网,并将数据通过 IPv6 传输给您。
若不想自建海外服务器,也可选择支持 IPv6 的代理提供商(机场)。
若分流,本地须有支持分流的代理软件。
代理模板
# wireguard_config.conf
[Interface]
Address = x.x.x.1/24
Address = x:x::1/64
ListenPort = 51820
PrivateKey = <key>
PostUp = iptables -t nat -A POSTROUTING -s x.x.x.0/24 -o eth0 -j MASQUERADE
PostUp = ip6tables -t nat -A POSTROUTING -s x:x::/64 -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -s x.x.x.0/24 -o eth0 -j MASQUERADE
PostDown = ip6tables -t nat -D POSTROUTING -s x:x::/64 -o eth0 -j MASQUERADE
[Peer]
PublicKey = <key>
AllowedIPs = x.x.x.2/32, x:x::2/128
[Peer]
PublicKey = <key>
AllowedIPs = x.x.x.3/32, x:x::3/128
/* xray_config.json */
{
"log": {
"loglevel": "debug",
"dnsLog": true,
"maskAddress": "quarter",
"access": "/var/log/xray/access.log",
"error": "/var/log/xray/error.log"
},
"inbounds": [
{
"listen": "0.0.0.0",
"port": 443,
"protocol": "vless",
"settings": {
"clients": [
{
"id": "<uuid>",
"email": "<string>"
},
{
"id": "<uuid>",
"email": "<string>"
}
],
"decryption": "none"
},
"streamSettings": {
"network": "xhttp",
"xhttpSettings": {
"host": "<domain>",
"path": "/<string>",
"mode": "auto"
},
"security": "reality",
"realitySettings": {
"target": "<domain>:443",
"serverNames": [
"<domain>"
],
"privateKey": "<key>",
"publicKey": "<key>",
"shortIds": [
"<hex_num>"
]
}
}
}
],
"outbounds": [
{
"protocol": "freedom"
}
]
}
# clash_config.yaml
allow-lan: false
bind-address: '*'
mode: rule
log-level: debug
ipv6: true
keep-alive-idle: 600
keep-alive-interval: 15
find-process-mode: always
external-controller: 127.0.0.1:9090
unified-delay: true
tcp-concurrent: true
geodata-mode: true
geo-auto-update: true
geo-update-interval: 24
geox-url:
geoip: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/geoip.dat'
geosite: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/v2ray-rules-dat@release/geosite.dat'
mmdb: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/GeoLite2-Country.mmdb'
asn: 'https://cdn.jsdelivr.net/gh/Loyalsoldier/geoip@release/GeoLite2-ASN.mmdb'
dns:
enable: true
prefer-h3: false
listen: 127.0.0.1:53
ipv6: true
default-nameserver:
- 223.5.5.5
- 119.29.29.29
- 2400:3200::1
- 2402:4e00::0
# Redir-Host
nameserver-policy:
'geosite:private': system
'geosite:category-ads-all': rcode://success
'geosite:cn':
- https://dns.alidns.com/dns-query#cloud-cn
- https://doh.pub/dns-query#cloud-cn
nameserver:
- https://dns.cloudflare.com/dns-query#cloud-out
- https://dns.google/dns-query#cloud-out
proxy-server-nameserver:
- https://dns.alidns.com/dns-query
- https://doh.pub/dns-query
# Fake-IP
enhanced-mode: fake-ip
fake-ip-range: 198.18.0.1/16
fake-ip-range6: fdfe:dcba:9876::1/64
fake-ip-filter:
- 'geosite:private'
nameserver-policy:
'geosite:private': system
'geosite:category-ads-all': rcode://success
nameserver:
- https://dns.alidns.com/dns-query
- https://doh.pub/dns-query
sniffer:
enable: true
force-dns-mapping: true
parse-pure-ip: true
override-destination: false
sniff:
HTTP:
ports:
- 80
- 8080-8880
override-destination: true
TLS:
ports:
- 443
- 8443
QUIC:
ports:
- 443
- 8443
tun:
enable: true
stack: system
auto-route: true
auto-redirect: true
auto-detect-interface: true
dns-hijack:
- any:53
- tcp://any:53
strict-route: true
# Redir-Host
rules:
- GEOIP,private,DIRECT
- GEOIP,cn,cloud-cn
- MATCH,cloud-out
# Fake-IP
rules:
- GEOSITE,private,DIRECT
- GEOSITE,category-ads-all,REJECT
- GEOSITE,cn,cloud-cn
- GEOIP,private,DIRECT,no-resolve
- GEOIP,cn,cloud-cn,no-resolve
- MATCH,cloud-out
proxy-groups:
- name: GLOBAL
type: select
proxies:
- DIRECT
- REJECT
- cloud-cn
- cloud-out
- name: cloud-cn
type: select
proxies:
- DIRECT
- REJECT
- proxy-cn
- name: cloud-out
type: select
proxies:
- DIRECT
- REJECT
- proxy-out
proxies:
- name: proxy-cn
type: wireguard
private-key: <key>
server: <ip>
port: 51820
ip: <ip>
ipv6: <ip>
public-key: <key>
allowed-ips: ['0.0.0.0/0']
udp: true
- name: proxy-out
type: vless
server: <ip>
port: 443
uuid: <uuid>
udp: true
tls: true
network: xhttp
client-fingerprint: chrome
alpn:
- h2
servername: <domain>
xhttp-opts:
path: <string>
host: <domain>
reality-opts:
public-key: <key>
short-id: <hex_num>