84 lines
4.7 KiB
Markdown
84 lines
4.7 KiB
Markdown
---
|
|
title: 搭载 sing-boxr 内核进行 DNS 分流教程-ruleset方案
|
|
description: 此教程搭载 sing-boxr 内核并使用其特性进行 DNS 分流,即指定国内域名 <code>rule_set:cn</code> 走国内 DNS 解析,国外域名走 <code>fake-ip</code>
|
|
date: 2024-08-22 18:24:06 +0800
|
|
categories: [DNS 配置, DNS 分流]
|
|
tags: [sing-box, sing-boxr, ShellCrash, ruleset, rule_set, 进阶, DNS, DNS 分流]
|
|
---
|
|
|
|
> 说明
|
|
{: .prompt-tip }
|
|
1. [ShellCrash](https://github.com/juewuy/ShellCrash) 搭配 [AdGuard Home](https://github.com/AdguardTeam/AdGuardHome) 并将 AdGuard Home 作为上游时不要使用该方法
|
|
2. 本教程以 ShellCrash 为例,其它客户端亦可参考
|
|
3. 本教程搭载 [sing-box 内核 reF1nd-Testing 版](https://github.com/reF1nd/sing-box/tree/reF1nd-testing)(导入内核方法可参考《[ShellCrash 和 AdGuard Home 快速安装教程/导入 mihomo 内核 或 sing-box 内核](https://proxy-tutorials.dustinwin.cc.cd/posts/pin-toolsinstall/#%E4%BA%8C-%E5%AF%BC%E5%85%A5-mihomo-%E5%86%85%E6%A0%B8-%E6%88%96-sing-box-%E5%86%85%E6%A0%B8)》)
|
|
4. DNS 分流简单来说就是**指定国内域名走国内 DNS 解析,国外域名走 `fakeip`**。未知域名走 `real-ip`(在匹配 `rule_set:cnip` 规则时会先由国内 DNS 解析,解析出 IP 在国内则直接返回解析结果且走 `国内 IP` 规则,否则走 `漏网之鱼` 规则)
|
|
5. 部分用户觉得未知域名处理方式会导致 DNS 泄露,可参考《[搭载 sing-boxr 内核配置 DNS 不泄露教程-ruleset 方案](https://proxy-tutorials.dustinwin.cc.cd/posts/dnsnoleaks-singboxr-ruleset)》
|
|
|
|
## 一、 导入规则集合文件
|
|
`route.rule_set` 须添加 `fakeip-filter`、`proxy`、`cn` 和 `cnip`,如下:
|
|
|
|
```json
|
|
{
|
|
"route": {
|
|
"rule_set": [
|
|
{
|
|
"tag": [ "fakeip-filter", "proxy", "cn", "cnip" ],
|
|
"type": "remote",
|
|
"format": "binary",
|
|
"path": "./ruleset/{tag}.srs",
|
|
"url": "https://github.com/DustinWin/ruleset_geodata/releases/download/sing-box-ruleset/{tag}.srs"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
```
|
|
|
|
## 二、 DNS 分流配置
|
|
1. 进入 ShellCrash 配置脚本 → 2) 功能设置 → 2) DNS 设置 → 9) 修改 DNS 服务器,将“DIRECT-DNS”、“PROXY-DNS”和“DEFAULT-DNS”都设置为 `null`
|
|
<img src="/assets/img/dns/dns-null.png" alt="ShellCrash 设置" width="60%" />
|
|
|
|
2. 连接 SSH 后执行命令 `vi $CRASHDIR/jsons/dns.json`,按一下 Ins 键(Insert 键),粘贴如下内容:
|
|
- 注:推荐将 `client_subnet` 设置为当前宽带运营商分配的默认 DNS(可进入光猫或路由器拨号页面查看,或者前往[公共 DNS 大全](https://toolb.cn/publicdns)查询)的 IP 段,如默认 DNS 为 `211.137.58.20`,可设置为 `211.137.58.0/24`
|
|
|
|
```json
|
|
{
|
|
"dns": {
|
|
"servers": [
|
|
{
|
|
"tag": "hosts",
|
|
"type": "hosts",
|
|
"predefined": {
|
|
"dns.alidns.com": [ "223.5.5.5", "223.6.6.6", "2400:3200::1", "2400:3200:baba::1" ],
|
|
"doh.pub": [ "1.12.12.12", "120.53.53.53" ],
|
|
"dns.google": [ "8.8.8.8", "8.8.4.4", "2001:4860:4860::8888", "2001:4860:4860::8844" ],
|
|
"cloudflare-dns.com": [ "1.1.1.1", "1.0.0.1", "2606:4700:4700::1111", "2606:4700:4700::1001" ]
|
|
}
|
|
},
|
|
{ "tag": "dns_resolver", "type": "local" },
|
|
{ "tag": "dns_alidns", "type": "quic", "server": "dns.alidns.com", "domain_resolver": "hosts" },
|
|
{ "tag": "dns_dnspod", "type": "https", "server": "doh.pub", "domain_resolver": "hosts" },
|
|
{ "tag": "dns_google", "type": "https", "server": "dns.google", "domain_resolver": "hosts", "detour": "GLOBAL" },
|
|
{ "tag": "dns_cloudflare", "type": "https", "server": "cloudflare-dns.com", "domain_resolver": "hosts", "detour": "GLOBAL" },
|
|
{ "tag": "dns_direct", "type": "group", "servers": [ "dns_alidns", "dns_dnspod" ] },
|
|
{ "tag": "dns_proxy", "type": "group", "servers": [ "dns_google", "dns_cloudflare" ] },
|
|
{ "tag": "dns_fakeip", "type": "fakeip", "inet4_range": "198.18.0.0/15", "inet6_range": "fc00::/16" }
|
|
],
|
|
"rules": [
|
|
{ "clash_mode": [ "Direct" ], "server": "dns_direct" },
|
|
{ "clash_mode": [ "Global" ], "server": "dns_proxy" },
|
|
{ "rule_set": [ "fakeip-filter" ], "server": "dns_direct" },
|
|
{ "rule_set": [ "proxy" ], "query_type": [ "A", "AAAA" ], "server": "dns_fakeip" },
|
|
{ "rule_set": [ "cn" ], "server": "dns_direct" },
|
|
{ "action": "evaluate", "server": "dns_direct" },
|
|
{ "match_response": true, "rule_set": [ "cnip" ], "action": "respond" }
|
|
],
|
|
"final": "dns_proxy",
|
|
"strategy": "prefer_ipv4",
|
|
"cache_client_subnet": true,
|
|
"optimistic": true,
|
|
"reverse_mapping": true
|
|
}
|
|
}
|
|
```
|
|
按一下 Esc 键(退出键),输入英文冒号 `:`,继续输入 `wq` 并回车
|