当前位置:首页 > 教程 > 正文内容

routeros配置vpn分流大陆ip

admin5年前 (2021-07-06)教程1.06

20201203更新:Routeros V7的分流方法参考Routeros V7配置策略路由
20201202更新:Routeros V7连接境外服务器的vpn方式可以参考Routeros 配置WireGuard
20200503更新:添加dnsmasq白名单分流解析
20200416更新:添加使用ipip.net的大陆ip列表生成命令并添加了私有ip地址

ros使用pppoe连网,ros上配置vpn连接香港服务器上的ros。目标:内网需要翻墙的ip通过大陆ip列表分流,大陆ip走默认路由,境外ip走vpn。其他内网ip全部走默认路由。
首先下载大陆ip列表,推荐方法2
方法1:

curl 'http://ftp.apnic.net/apnic/stats/apnic/delegated-apnic-latest' | grep ipv4 | grep CN | awk -F\| '{ printf("%s/%d\n", $4, 32-log($5)/log(2)) }' > chnroute.txt

生成的txt文件使用sublime的多行编辑功能或其他方式转换成ros的cn-ip.rsc脚本格式。

/ip firewall address-list
add list=cn-ip address=1.0.1.0/24
add list=cn-ip address=1.0.2.0/23

方法2:使用ipip.net发布在github的大陆ip列表生成

curl -s https://raw.githubusercontent.com/17mon/china_ip_list/master/china_ip_list.txt |sed -e 's/^/add address=/g' -e 's/$/ list=CNIP/g'|sed -e $'1i\\\n/ip firewall address-list' -e $'1i\\\nremove [/ip firewall address-list find list=CNIP]' -e $'1i\\\nadd address=10.0.0.0/8 list=CNIP comment=private-network' -e $'1i\\\nadd address=172.16.0.0/12 list=CNIP comment=private-network' -e $'1i\\\nadd address=192.168.0.0/16 list=CNIP comment=private-network'>cnip.rsc

以上脚本在CNIP列表里添加了私有ip地址192.168.0.0/16,172.16.0.0/12和10.0.0.0/8

方法3:下载别人制作好的脚本
http://www.iwik.org/ipcountry/mikrotik/CN

使用import cnip.rsc导入ros。添加内网需要翻墙的ip列表。
配置ip firewall的mangle
prerouting,source address list,destination address list取反,destination address type,address type local,invert,mark routing,cross-gfw。
配置ip routes的网关
0.0.0.0/0,gateway设置为vpn对端地址,routing mark 使用上面的cross-gfw。

现在解决dns问题,由于ros的dns功能比较弱,这里使用dnsmasq
内网一台linux系统,可以是虚拟机,可以是容器,安装dnsmasq。配置dnsmasq的源dns为google dns,然后使用github上的大陆网址白名单生成脚本添加需要使用大陆解析的域名。https://github.com/felixonmars/dnsmasq-china-list


相关文章

PVE-openwrt-模板安装

安装解包工具apt install squashfs-tools解压openwrt包gzip -d openwrt-x86-64-generic-squashf...

windows realtek网卡配置vlan

windows realtek网卡配置vlan

工具安装后网卡上添加了3种协议realtek diagnostic utility win10:https://www.techspot.com/drivers/downloadnow/18001/?...

linux开机自启动frpc

配置frpc.ini 参考frp配置说明#打开frpc配置文件vim /usr/frp/frpc.ini复制参考说明,进行配置#frps服务端地址 server_addr =...

PCI Express 版本对应宽带

PCI Express: Unidirectional Bandwidth in x1 and x16 ConfigurationsGenerationYear of ReleaseData Tran...

Proxmox VE 修改SPICE端口

/usr/share/perl5/PVE/AccessControl.pm     proxy => "http:...

linux 通过nmcli 接管网卡自动获取ip

如果你想要通过 DHCP 自动获取 IP 地址,你可以简单地使用 nmcli 来配置 tun 设备使用 DHCP。你只需要执行以下命令:bashCopy codenmcli con...

发表评论

访客

看不清,换一张

◎欢迎参与讨论,请在这里发表您的看法和观点。