vernesong / OpenClash

A Clash Client For OpenWrt
MIT License
16.92k stars 3.11k forks source link

无法使用Youtube App #1168

Closed qingyiwebt closed 3 years ago

qingyiwebt commented 3 years ago

Screenshot_2021-01-16-01-06-15-483_mark via Screenshot_2021-01-16-01-05-49-318_com google and 当我使用OpenClash时,无法使用Youtube App,但是却可以正常访问网页版的Youtube。
以下为OpenClash调试日志:

OpenClash 调试日志

生成时间: 2021-01-16 00:11:33
插件版本: v0.40.7-beta

#===================== 系统信息 =====================#
主机型号: 
固件版本: OpenWrt SNAPSHOT r0-a8ddd98
LuCI版本: git-20.343.54716-6fc079f-1
内核版本: 5.4.79-v7+
处理器架构: arm_cortex-a7_neon-vfpv4

#此项在使用Tun模式时应为ACCEPT
防火墙转发: ACCEPT

#此项有值时建议到网络-接口-lan的设置中禁用IPV6的DHCP
IPV6-DHCP: 

#此项结果应仅有配置文件的DNS监听地址
Dnsmasq转发设置: 127.0.0.1#7874

#===================== 依赖检查 =====================#
dnsmasq-full: 已安装
coreutils: 已安装
coreutils-nohup: 已安装
bash: 已安装
curl: 已安装
jsonfilter: 已安装
ca-certificates: 已安装
ipset: 已安装
ip-full: 已安装
iptables-mod-tproxy: 已安装
kmod-tun(TUN模式): 已安装
luci-compat(Luci-19.07): 已安装

#===================== 内核检查 =====================#
运行状态: 运行中
已选择的架构: linux-armv7

#下方无法显示内核版本号时请确认您的内核版本是否正确或者有无权限
Tun内核版本: 2021.01.01.g0ab75c5
Tun内核文件: 存在
Tun内核运行权限: 正常

Game内核版本: v0.17.0-232-ge389e33
Game内核文件: 存在
Game内核运行权限: 正常

Dev内核版本: v1.3.5-4-g6fedd7e
Dev内核文件: 存在
Dev内核运行权限: 正常

#===================== 插件设置 =====================#
当前配置文件: /etc/openclash/config/hub_with_adblock.yaml
运行模式: fake-ip
默认代理模式: rule
UDP流量转发: 启用
DNS劫持: 启用
自定义DNS: 停用
IPV6-DNS解析: 停用
禁用Dnsmasq缓存: 停用
自定义规则: 停用
仅允许内网: 停用
仅代理命中规则流量: 停用
绕过中国大陆IP: 停用

#启动异常时建议关闭此项后重试
保留配置: 停用
第三方规则: 停用

#===================== 防火墙设置 =====================#

#NAT chain

Chain PREROUTING (policy ACCEPT)
num  target     prot opt source               destination         
1    REDIRECT   tcp  --  0.0.0.0/0            8.8.4.4              redir ports 7892
2    REDIRECT   tcp  --  0.0.0.0/0            8.8.8.8              redir ports 7892
3    REDIRECT   udp  --  0.0.0.0/0            0.0.0.0/0            udp dpt:53 redir ports 53
4    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:53 redir ports 53
5    zone_lan_prerouting  all  --  0.0.0.0/0            0.0.0.0/0            /* !fw3 */
6    zone_vpn_prerouting  all  --  0.0.0.0/0            0.0.0.0/0            /* !fw3 */
7    openclash  tcp  --  0.0.0.0/0            0.0.0.0/0           
Chain OUTPUT (policy ACCEPT)
num  target     prot opt source               destination         
1    openclash_output  tcp  --  0.0.0.0/0            0.0.0.0/0           

#Mangle chain

Chain PREROUTING (policy ACCEPT)
num  target     prot opt source               destination         
1    openclash  udp  --  0.0.0.0/0            0.0.0.0/0           
Chain OUTPUT (policy ACCEPT)
num  target     prot opt source               destination         
1    RRDIPT_OUTPUT  all  --  0.0.0.0/0            0.0.0.0/0           

#===================== 路由表状态 =====================#
#route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         192.168.2.1     0.0.0.0         UG    0      0        0 eth0
192.168.2.0     0.0.0.0         255.255.255.0   U     0      0        0 eth0
#ip route list
default via 192.168.2.1 dev eth0 proto static 
192.168.2.0/24 dev eth0 proto kernel scope link src 192.168.2.2 
#ip rule show
0:  from all lookup local
32765:  from all fwmark 0x162 lookup 354
32766:  from all lookup main
32767:  from all lookup default

#===================== 端口占用状态 =====================#
tcp        0      0 :::7890                 :::*                    LISTEN      9905/clash
tcp        0      0 :::7891                 :::*                    LISTEN      9905/clash
tcp        0      0 :::7892                 :::*                    LISTEN      9905/clash
tcp        0      0 :::9090                 :::*                    LISTEN      9905/clash
udp        0      0 127.0.0.1:7874          0.0.0.0:*                           9905/clash
udp        0      0 :::7891                 :::*                                9905/clash
udp        0      0 :::7892                 :::*                                9905/clash

#===================== 测试本机DNS查询 =====================#
Server:     127.0.0.11
Address:    127.0.0.11#53

Name:      www.baidu.com
www.baidu.com   canonical name = www.a.shifen.com
Name:      www.a.shifen.com
Address 1: 163.177.151.109
Address 2: 163.177.151.110
www.baidu.com   canonical name = www.a.shifen.com

#===================== resolv.conf.d =====================#
# Interface lan
nameserver 192.168.2.1

#===================== 测试本机网络连接 =====================#
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: private, no-cache, no-store, proxy-revalidate, no-transform
Connection: keep-alive
Content-Length: 277
Content-Type: text/html
Date: Fri, 15 Jan 2021 16:11:37 GMT
Etag: "575e1f72-115"
Last-Modified: Mon, 13 Jun 2016 02:50:26 GMT
Pragma: no-cache
Server: bfe/1.0.8.18

#===================== 测试本机网络下载 =====================#
HTTP/1.1 200 Connection established

HTTP/1.1 200 OK
Connection: keep-alive
Content-Length: 80
Cache-Control: max-age=300
Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline'; sandbox
Content-Type: text/plain; charset=utf-8
ETag: "00cdb0532e41777645c9ad3e0a65a1b1ac87d6afaf72cf6e33d925dbbd05be97"
Strict-Transport-Security: max-age=31536000
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-XSS-Protection: 1; mode=block
via: 1.1 varnish (Varnish/6.0), 1.1 varnish
X-GitHub-Request-Id: 1192:2F4D:2330B3:269DFD:6001BD6B
Accept-Ranges: bytes
Date: Fri, 15 Jan 2021 16:11:38 GMT
X-Served-By: cache-hkg17923-HKG
X-Cache: HFM, HIT
X-Cache-Hits: 0, 1
X-Timer: S1610727099.856711,VS0,VE1
Vary: Authorization,Accept-Encoding
Access-Control-Allow-Origin: *
X-Fastly-Request-ID: 338e4966c5a047dd03b4ade11888c963965e62a3
Expires: Fri, 15 Jan 2021 16:16:38 GMT
Source-Age: 19

#===================== 最近运行日志 =====================#
OpenClash Now Disabled, Need Start From Luci Page, Exit...
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 📢 谷歌FCM"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 📲 电报信息"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🎯 全球直连"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🚀 节点选择"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🛑 全球拦截"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider Ⓜ️ 微软服务"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🆎 AdBlock"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🌍 国外媒体"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🐟 漏网之鱼"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🍃 应用净化"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider ♻️ 自动选择"
time="2021-01-15T22:54:02+08:00" level=info msg="Start initial compatible provider 🍎 苹果服务"
time="2021-01-15T22:54:02+08:00" level=info msg="DNS server listening at: 127.0.0.1:7874"
2021-01-15 22:52:36 OpenClash Start Successful
2021-01-15 22:55:46 OpenClash Start Successful

以及我的方案:

我在树莓派上使用docker运行了openwrt,在Raspberry OS上新建了一个brlan,并且使用hostapd和dnsmasq配置了一个带dhcp的无线热点。
还在OpenWrt内进行了部分配置。
Raspberry OS上新建的brlan: 192.168.2.1/24
OpenWrt运行在:192.168.2.2
Raspberry OS运行在:192.168.2.1

我的Dnsmasq配置(注意是运行在Docker外):

domain-needed
bogus-priv
clear-on-reload

interface=brlan
dhcp-range=192.168.2.50,192.168.2.150,255.255.255.0,12h
dhcp-option=3,192.168.2.2
dhcp-option=6,192.168.2.2,8.8.8.8,114.114.114.114

我的Hostapd配置(注意是运行在Docker外):

interface=wlan0
bridge=brlan
driver=nl80211
ssid=Raspberry Brlan
hw_mode=g
channel=6
wmm_enabled=1
macaddr_acl=0
auth_algs=1
ignore_broadcast_ssid=0
wpa=2
wpa_passphrase=************
wpa_key_mgmt=WPA-PSK
rsn_pairwise=CCMP
vernesong commented 3 years ago

dhcp-option=6,192.168.2.2,8.8.8.8,114.114.114.114

dnsmasq保留192.168.2.2,其他去掉

tonyzhou777 commented 3 years ago

我这里也是,Youtube和Google Photo过办个小时以上就无法访问。需要到Google Play商店刷新一下,然后Youtube和Google Photo就能加载内容了。 估计是OpenClash内部DNS解析的锅。

iam7cn commented 3 years ago

我的也是,不知道怎么解决??? rule模式,全局模式可以用APP打开

FreedomC commented 3 years ago

问题解决了吗? 我也一样的情况

tonyzhou777 commented 3 years ago

问题解决了吗? 我也一样的情况

算是解决了,GMS服务后台被杀了,根据不同品牌手机,保留GMS后台权限,应该能缓解。

00SunnyDay00 commented 3 years ago

您好这个问题最后怎么解决的? 能否详细说一下 我也遇到了