Open themikan opened 2 months ago
参考 wiki 中说明,当前我的设备的防火墙规则与 wiki 示例有差别,不清楚是否与这个有关,如果有关,应该怎么调整配置?(差异主要在 第 1、6 条内容)
iptables -t nat -nL --line-number
Chain PREROUTING (policy ACCEPT)
num target prot opt source destination
1 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 / OpenClash TCP DNS Hijack / tcp dpt:53
2 REDIRECT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 / OpenClash DNS Hijack / redir ports 53
3 REDIRECT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53 / OpenClash DNS Hijack / redir ports 53
4 prerouting_rule all -- 0.0.0.0/0 0.0.0.0/0 / !fw3: Custom prerouting rule chain /
5 zone_lan_prerouting all -- 0.0.0.0/0 0.0.0.0/0 / !fw3 /
6 zone_docker_prerouting all -- 0.0.0.0/0 0.0.0.0/0 / !fw3 /
7 openclash tcp -- 0.0.0.0/0 0.0.0.0/0
ping google的情况: PING google.com (142.250.71.174): 56 data bytes
--- google.com ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss
nslookup google 的情况: Server: 127.0.0.1 Address: 127.0.0.1:53
Name: google.com Address: 142.250.71.174
参考 wiki 中说明,当前我的设备的防火墙规则与 wiki 示例有差别,不清楚是否与这个有关,如果有关,应该怎么调整配置?(差异主要在 第 1、6 条内容)
iptables -t nat -nL --line-number Chain PREROUTING (policy ACCEPT) num target prot opt source destination 1 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 / OpenClash TCP DNS Hijack / tcp dpt:53 2 REDIRECT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 / OpenClash DNS Hijack / redir ports 53 3 REDIRECT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53 / OpenClash DNS Hijack _/ redir ports 53 4 preroutingrule all -- 0.0.0.0/0 0.0.0.0/0 / !fw3: Custom prerouting rule chain _/ 5 zone_lanprerouting all -- 0.0.0.0/0 0.0.0.0/0 / !fw3 _/ 6 zone_dockerprerouting all -- 0.0.0.0/0 0.0.0.0/0 / !fw3 / 7 openclash tcp -- 0.0.0.0/0 0.0.0.0/0
删除第一条规则后,仍然无法访问
多发点下面客户端访问时在控制面板的debug等级日志
你的路由器是可以出去的
多发点下面客户端访问时在控制面板的debug等级日志
请看附件 log826.txt
又捉了一份,ping github, youtube, google 情况对应的日志,麻烦看看 github+youtube+google.txt @vernesong
是否是这段的原因?
24-08-26 22:13:46[ debug ][DNS] youtube.com --> [142.250.197.14] A from tls://8.8.4.4:853
24-08-26 22:13:46[ debug ][https://public.dns.iij.jp:443/dns-query?dns=AAABAAABAAAAAAAAB3lvdXR1YmUDY29tAAABAAE] using HTTP/2 for this upstream:
@vernesong 你好,我的选项中没有你截图的 Auto-UrlTest 选项,只有上面截图的选项,我尝试切换了其中的google 选项,还是不行。
切换选项后,重新 ping google.com 对应的 debug 日志: [2024-08-27 09:27:15][INFO] Load MMDB file: /etc/openclash/Country.mmdb [2024-08-27 09:27:15][INFO] [TCP] 192.168.31.152:36992(curl) --> api.stentvessel.top:443 match Match using Final[🇭🇰 日用 专线 香港 [0.2]] [2024-08-27 09:23:09][DEBUG] ip: unknown version: 15 [2024-08-27 09:23:11][DEBUG] [DNS] cache hit for google.com., expire at 2024-08-27 01:24:15 [2024-08-27 09:24:11][DEBUG] ip: unknown version: 15 [2024-08-27 09:24:36][DEBUG] [DNS] resolve youtube.com from https://dns.oszx.co:443/dns-query [2024-08-27 09:24:36][DEBUG] [DNS] resolve youtube.com from https://dns.cloudflare.com:443/dns-query [2024-08-27 09:24:36][DEBUG] [DNS] resolve youtube.com from https://public.dns.iij.jp:443/dns-query [2024-08-27 09:24:36][DEBUG] [DNS] cache hit for aexgzbgp01.00117163.xyz., expire at 2024-08-27 01:24:30 [2024-08-27 09:24:36][DEBUG] [DNS] cache hit for aexgzbgp01.00117163.xyz., expire at 2024-08-27 01:24:30 [2024-08-27 09:24:36][DEBUG] [DNS] cache hit for aexgzbgp01.00117163.xyz., expire at 2024-08-27 01:24:30 [2024-08-27 09:24:36][DEBUG] [DNS] resolve aexgzbgp01.00117163.xyz from https://dns.alidns.com:443/dns-query [2024-08-27 09:24:36][DEBUG] [DNS] resolve aexgzbgp01.00117163.xyz from udp://119.29.29.29:53 [2024-08-27 09:24:36][DEBUG] [DNS] resolve aexgzbgp01.00117163.xyz from udp://114.114.114.114:53 [2024-08-27 09:24:36][DEBUG] [DNS] resolve aexgzbgp01.00117163.xyz from https://doh.pub:443/dns-query [2024-08-27 09:24:36][DEBUG] [DNS] cache hit for dns.alidns.com., expire at 2024-08-27 02:10:51 [2024-08-27 09:24:36][DEBUG] [DNS] cache hit for doh.pub., expire at 2024-08-27 01:27:34 [2024-08-27 09:24:36][DEBUG] [DNS] aexgzbgp01.00117163.xyz --> [163.177.58.120] A from udp://119.29.29.29:53 [2024-08-27 09:24:37][DEBUG] [DNS] youtube.com --> [142.251.130.14] A from https://dns.cloudflare.com:443/dns-query [2024-08-27 09:25:12][DEBUG] ip: unknown version: 15 [2024-08-27 09:26:14][DEBUG] ip: unknown version: 15 [2024-08-27 09:27:15][DEBUG] ip: unknown version: 15
切换了其他机场,使用其中的“自动选择”选项,也是不行
对应的 debug日志如下: [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.stentvessel.top from https://dns.alidns.com:443/dns-query [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for dns.alidns.com., expire at 2024-08-27 02:10:51 [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.stentvessel.top from udp://114.114.114.114:53 [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.stentvessel.top from udp://119.29.29.29:53 [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.stentvessel.top from https://doh.pub:443/dns-query [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for doh.pub., expire at 2024-08-27 01:57:35 [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.acaisbest.shop from https://dns.alidns.com:443/dns-query [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.acaisbest.shop from udp://119.29.29.29:53 [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.acaisbest.shop from udp://114.114.114.114:53 [2024-08-27 09:52:56][DEBUG] [DNS] resolve api.acaisbest.shop from https://doh.pub:443/dns-query [2024-08-27 09:52:56][DEBUG] [DNS] api.stentvessel.top --> [104.21.80.4 172.67.172.85] A from udp://114.114.114.114:53 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for doh.pub., expire at 2024-08-27 01:57:35 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for dns.alidns.com., expire at 2024-08-27 02:10:51 [2024-08-27 09:52:56][DEBUG] [Rule] use default rules [2024-08-27 09:52:56][DEBUG] [DNS] api.acaisbest.shop --> [194.104.146.58] A from udp://114.114.114.114:53 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [Rule] use default rules [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for api.acaisbest.shop., expire at 2024-08-27 01:53:02 [2024-08-27 09:52:56][INFO] [TCP] 192.168.31.152:32770(curl) --> api.stentvessel.top:443 match Match using 🐟 漏网之鱼[🇭🇰 Hong Kong 03] [2024-08-27 09:52:56][INFO] [TCP] 192.168.31.152:33400 --> api.acaisbest.shop:443 match Domain(api.acaisbest.shop) using DIRECT [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for api.acaisbest.shop., expire at 2024-08-27 01:53:02 [2024-08-27 09:52:56][DEBUG] [Rule] use default rules [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for api.acaisbest.shop., expire at 2024-08-27 01:53:02 [2024-08-27 09:52:56][INFO] [TCP] 192.168.31.152:33414 --> api.acaisbest.shop:443 match Domain(api.acaisbest.shop) using DIRECT [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for dtjaswffgyjh.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:33][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:33][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:33][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:33][DEBUG] [DNS] cache hit for aca-cm-js-4g.cfprefer1.xyz., expire at 2024-08-27 01:53:01 [2024-08-27 09:52:34][DEBUG] [DNS] cache hit for rhsdrhwa.cfprefer1.xyz., expire at 2024-08-27 01:53:06 [2024-08-27 09:52:34][DEBUG] [DNS] cache hit for oss-gz.cfprefer1.xyz., expire at 2024-08-27 01:52:44 [2024-08-27 09:52:40][DEBUG] [DNS] resolve github.com from udp://114.114.114.114:53 [2024-08-27 09:52:40][DEBUG] [DNS] resolve github.com from https://dns.alidns.com:443/dns-query [2024-08-27 09:52:40][DEBUG] [DNS] resolve github.com from udp://119.29.29.29:53 [2024-08-27 09:52:40][DEBUG] [DNS] resolve github.com from https://doh.pub:443/dns-query [2024-08-27 09:52:40][DEBUG] [DNS] cache hit for dns.alidns.com., expire at 2024-08-27 02:10:51 [2024-08-27 09:52:40][DEBUG] [DNS] cache hit for doh.pub., expire at 2024-08-27 01:57:35 [2024-08-27 09:52:40][DEBUG] [DNS] github.com --> [20.205.243.166] A from udp://119.29.29.29:53 [2024-08-27 09:52:51][DEBUG] ip: unknown version: 15 [2024-08-27 09:52:56][DEBUG] [DNS] resolve google.com from https://dns.alidns.com:443/dns-query [2024-08-27 09:52:56][DEBUG] [DNS] resolve google.com from udp://114.114.114.114:53 [2024-08-27 09:52:56][DEBUG] [DNS] resolve google.com from udp://119.29.29.29:53 [2024-08-27 09:52:56][DEBUG] [DNS] resolve google.com from https://doh.pub:443/dns-query [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for doh.pub., expire at 2024-08-27 01:57:35 [2024-08-27 09:52:56][DEBUG] [DNS] cache hit for dns.alidns.com., expire at 2024-08-27 02:10:51 [2024-08-27 09:52:56][DEBUG] [DNS] google.com --> [142.251.43.14] A from udp://119.29.29.29:53
节点不通吗
节点不通吗
节点应该是通的,这2 个机场我在电脑端的 clash verge 中一直有使用
@vernesong 把所有打勾的那么 Server, FallBack,都配置了节点域名解析,还是无法 ping 通 google。。😭
首先你的配置就有问题,我也不知道你咋写的,要出去的域名怎么还用国内的dns
首先你的配置就有问题,我也不知道你咋写的,要出去的域名怎么还用国内的dns
请问你指的配置是?我基本没有调整过 UI 界面的配置,机场相关的配置也没有动过。。。这个出去的域名是否与 覆写设置 的配置有关?
你先用订阅转换试试,DNS写上fallback然后指定代理组
你先用订阅转换试试,DNS写上fallback然后指定代理组
使用了,还是不行,如果切换发到 fakeip,手机直接无法上网
[2024-08-27 23:54:49][DEBUG] [DNS] resolve www.youtube.com from tls://8.8.4.4:853 [2024-08-27 23:54:49][DEBUG] [DNS] resolve www.youtube.com from https://1.0.0.1:443/dns-query [2024-08-27 23:54:49][DEBUG] [DNS] resolve www.youtube.com from https://public.dns.iij.jp:443/dns-query [2024-08-27 23:54:49][DEBUG] [DNS] cache hit for aexshbgp01.00117163.xyz., expire at 2024-08-27 15:57:11 [2024-08-27 23:54:50][DEBUG] [DNS] www.youtube.com --> [142.250.68.14 142.250.68.46 142.250.72.238 142.250.72.174 142.250.68.78 142.250.176.14 142.250.72.142 172.217.14.78 142.250.189.14 142.251.40.46 172.217.12.142 142.250.217.142 172.217.14.110 142.250.188.238] A from https://1.0.0.1:443/dns-query
从日志看,似乎只有https://1.0.0.1:443/dns-query返回了 地址,其他DNS 服务器没返回,会不会是这个原因呢?
对应的 fallback 配置情况, 另外 NameServer 和 Default-NmaeServer 没有启用任何一个服务
@vernesong 我调整了部分设置后能正常访问了。 具体调整:不使用 Meta 内核,并切换到 Fake-IP 模式后,一切正常了,谢谢
内核问题,等更新
今天整了一下午 晚上看了一眼issues 得一下午白折腾 meta有问题
Verify Steps
OpenClash Version
0.45.157-beta
Bug on Environment
Istoreos
OpenWrt Version
iStoreOS 22.03.6 2024043010
Bug on Platform
Linux-arm64
Describe the Bug
无法访问外网,只能访问国内网络
To Reproduce
斐讯 N1 作为旁路由接入主路由的 LAN 口,刷如 istoreOS,安装 openClash 后,配置机场,使用 meta 内核,使用混合模式,发现只能上国内完整,国外网站访问失败。 例如谷歌 ping 不通,但nslookup, 能得到正确的 IP
OpenClash Log
OpenClash Config
No response
Expected Behavior
希望能正常访问外网
Additional Context
OpenClash 调试日志.txt