2017-07-30 12:38:41 +08:00
|
|
|
# [glider](https://github.com/nadoo/glider)
|
2017-09-10 19:48:53 +08:00
|
|
|
|
|
|
|
[](https://travis-ci.org/nadoo/glider)
|
|
|
|
[](https://goreportcard.com/report/github.com/nadoo/glider)
|
2017-09-11 00:25:57 +08:00
|
|
|
[](https://github.com/nadoo/glider/releases)
|
|
|
|
[](https://github.com/nadoo/glider/releases)
|
2017-09-10 19:48:53 +08:00
|
|
|
|
2017-09-03 01:05:56 +08:00
|
|
|
glider is a forward proxy with multiple protocols support, and also a dns forwarding server with ipset management features(like dnsmasq).
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2017-09-03 01:05:56 +08:00
|
|
|
we can set up local listeners as proxy servers, and forward requests to internet via forwarders.
|
2017-07-23 01:57:05 +08:00
|
|
|
```
|
|
|
|
|Forwarder ----------------->|
|
|
|
|
Listener --> | | Internet
|
2017-07-26 18:56:24 +08:00
|
|
|
|Forwarder --> Forwarder->...|
|
2017-07-23 01:57:05 +08:00
|
|
|
```
|
|
|
|
|
2017-07-27 01:22:56 +08:00
|
|
|
## Features
|
2018-01-22 00:40:04 +08:00
|
|
|
Listen (local proxy server):
|
2018-01-20 23:27:22 +08:00
|
|
|
- Socks5 proxy(tcp&udp)
|
|
|
|
- Http proxy(tcp)
|
|
|
|
- SS proxy(tcp&udp)
|
2017-07-27 01:22:56 +08:00
|
|
|
- Linux transparent proxy(iptables redirect)
|
|
|
|
- TCP tunnel
|
2018-01-20 23:27:22 +08:00
|
|
|
- UDP tunnel
|
2018-01-20 22:13:04 +08:00
|
|
|
- UDP over TCP tunnel
|
2017-09-03 01:05:56 +08:00
|
|
|
|
2018-01-22 00:40:04 +08:00
|
|
|
Forward (local proxy client/upstream proxy server):
|
2018-01-22 23:24:33 +08:00
|
|
|
- Socks5 proxy(tcp&udp)
|
2018-01-20 23:27:22 +08:00
|
|
|
- Http proxy(tcp)
|
|
|
|
- SS proxy(tcp&udp&uot)
|
2018-05-17 10:16:00 +08:00
|
|
|
- SSR proxy(tcp)
|
2018-07-05 20:44:19 +08:00
|
|
|
- VMess proxy(tcp)
|
2018-07-05 20:56:05 +08:00
|
|
|
- TLS, use it together with above proxy protocols(tcp)
|
2018-07-22 20:02:50 +08:00
|
|
|
- Websocket, use it together with above proxy protocols(tcp)
|
2017-07-27 01:22:56 +08:00
|
|
|
|
2018-01-22 00:40:04 +08:00
|
|
|
DNS Forwarding Server (udp2tcp):
|
2017-09-03 01:05:56 +08:00
|
|
|
- Listen on UDP and forward dns requests to remote dns server in TCP via forwarders
|
|
|
|
- Specify different upstream dns server based on destinations(in rule file)
|
|
|
|
- Tunnel mode: forward to a fixed upstream dns server
|
|
|
|
- Add resolved IPs to proxy rules
|
|
|
|
- Add resolved IPs to ipset
|
|
|
|
|
2017-12-17 00:36:53 +08:00
|
|
|
IPSet Management:
|
2017-09-03 01:05:56 +08:00
|
|
|
- Add ip/cidrs from rule files on startup
|
|
|
|
- Add resolved ips for domains from rule files by dns forwarding server
|
|
|
|
|
2017-07-27 01:22:56 +08:00
|
|
|
General:
|
2017-07-30 10:35:11 +08:00
|
|
|
- Http and socks5 on the same port
|
2017-07-27 01:22:56 +08:00
|
|
|
- Forward chain
|
|
|
|
- HA or RR strategy for multiple forwarders
|
|
|
|
- Periodical proxy checking
|
2017-08-31 00:08:22 +08:00
|
|
|
- Rule proxy based on destinations: [Config Examples](config/examples)
|
2017-07-30 10:57:24 +08:00
|
|
|
|
|
|
|
TODO:
|
2018-01-11 23:14:09 +08:00
|
|
|
- [ ] Transparent UDP proxy (iptables tproxy)
|
|
|
|
- [ ] DNS Cache
|
2018-07-03 00:31:43 +08:00
|
|
|
- [ ] Performance tuning
|
2017-08-24 11:58:32 +08:00
|
|
|
- [ ] TUN/TAP device support
|
2017-08-29 18:36:42 +08:00
|
|
|
- [ ] IPv6 support
|
2017-08-24 11:58:32 +08:00
|
|
|
- [ ] SSH tunnel support
|
2017-07-27 01:22:56 +08:00
|
|
|
|
2017-07-13 21:55:41 +08:00
|
|
|
## Install
|
2017-07-21 18:58:51 +08:00
|
|
|
Binary:
|
|
|
|
- [https://github.com/nadoo/glider/releases](https://github.com/nadoo/glider/releases)
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2018-07-16 15:08:43 +08:00
|
|
|
Go Get (requires **Go 1.10+** ):
|
2017-07-21 18:58:51 +08:00
|
|
|
```bash
|
|
|
|
go get -u github.com/nadoo/glider
|
|
|
|
```
|
|
|
|
|
|
|
|
ArchLinux:
|
|
|
|
```bash
|
|
|
|
sudo pacman -S glider
|
|
|
|
```
|
|
|
|
|
|
|
|
## Run
|
2017-07-29 18:15:22 +08:00
|
|
|
command line:
|
2017-07-21 18:58:51 +08:00
|
|
|
```bash
|
|
|
|
glider -listen :8443 -verbose
|
|
|
|
```
|
|
|
|
|
2017-07-29 18:15:22 +08:00
|
|
|
config file:
|
2017-07-21 18:58:51 +08:00
|
|
|
```bash
|
|
|
|
glider -config CONFIGPATH
|
|
|
|
```
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2017-07-29 18:15:22 +08:00
|
|
|
command line with config file:
|
|
|
|
```bash
|
|
|
|
glider -config CONFIGPATH -listen :8080 -verbose
|
|
|
|
```
|
|
|
|
|
2017-07-13 21:55:41 +08:00
|
|
|
## Usage
|
|
|
|
```bash
|
2018-08-01 00:36:11 +08:00
|
|
|
glider v0.6.5 usage:
|
2017-07-18 19:25:54 +08:00
|
|
|
-checkduration int
|
2017-07-18 19:01:42 +08:00
|
|
|
proxy check duration(seconds) (default 30)
|
2017-07-30 10:35:11 +08:00
|
|
|
-checkwebsite string
|
2017-07-31 13:42:11 +08:00
|
|
|
proxy check HTTP(NOT HTTPS) website address, format: HOST[:PORT], default port: 80 (default "www.apple.com")
|
2017-07-18 19:25:54 +08:00
|
|
|
-config string
|
|
|
|
config file path
|
2018-01-20 23:27:22 +08:00
|
|
|
-dns string
|
|
|
|
dns forwarder server listen address
|
2018-08-01 00:36:11 +08:00
|
|
|
-dnsrecord value
|
|
|
|
custom dns record, format: domain/ip
|
2018-01-20 23:27:22 +08:00
|
|
|
-dnsserver value
|
|
|
|
remote dns server
|
2017-07-18 19:25:54 +08:00
|
|
|
-forward value
|
2018-06-03 13:54:16 +08:00
|
|
|
forward url, format: SCHEME://[USER|METHOD:PASSWORD@][HOST]:PORT?PARAMS[,SCHEME://[USER|METHOD:PASSWORD@][HOST]:PORT?PARAMS]
|
2018-01-20 23:27:22 +08:00
|
|
|
-ipset string
|
|
|
|
ipset name
|
2017-07-18 19:25:54 +08:00
|
|
|
-listen value
|
2018-06-03 13:54:16 +08:00
|
|
|
listen url, format: SCHEME://[USER|METHOD:PASSWORD@][HOST]:PORT?PARAMS
|
2017-07-30 10:35:11 +08:00
|
|
|
-rulefile value
|
|
|
|
rule file path
|
2018-01-20 23:27:22 +08:00
|
|
|
-rules-dir string
|
|
|
|
rule file folder
|
2017-07-18 19:25:54 +08:00
|
|
|
-strategy string
|
2017-07-13 21:55:41 +08:00
|
|
|
forward strategy, default: rr (default "rr")
|
2017-07-18 19:25:54 +08:00
|
|
|
-verbose
|
|
|
|
verbose mode
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2018-06-03 13:54:16 +08:00
|
|
|
Available Schemes:
|
2017-07-13 21:55:41 +08:00
|
|
|
mixed: serve as a http/socks5 proxy on the same port. (default)
|
|
|
|
ss: ss proxy
|
|
|
|
socks5: socks5 proxy
|
|
|
|
http: http proxy
|
2018-05-20 16:59:48 +08:00
|
|
|
ssr: ssr proxy
|
2018-07-05 20:44:19 +08:00
|
|
|
vmess: vmess proxy
|
2018-07-24 00:54:38 +08:00
|
|
|
tls: tls transport
|
|
|
|
ws: websocket transport
|
2017-07-13 21:55:41 +08:00
|
|
|
redir: redirect proxy. (used on linux as a transparent proxy with iptables redirect rules)
|
2018-01-20 23:31:36 +08:00
|
|
|
tcptun: tcp tunnel
|
|
|
|
udptun: udp tunnel
|
|
|
|
uottun: udp over tcp tunnel
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2018-06-03 13:54:16 +08:00
|
|
|
Available schemes for different modes:
|
2018-07-30 01:13:44 +08:00
|
|
|
listen: mixed ss socks5 http redir tcptun udptun uottun
|
2018-07-22 20:02:50 +08:00
|
|
|
forward: ss socks5 http ssr vmess tls ws
|
2018-05-17 10:16:00 +08:00
|
|
|
|
2018-06-03 13:54:16 +08:00
|
|
|
SS scheme:
|
2018-05-17 10:16:00 +08:00
|
|
|
ss://method:pass@host:port
|
2017-07-13 21:55:41 +08:00
|
|
|
|
|
|
|
Available methods for ss:
|
|
|
|
AEAD_AES_128_GCM AEAD_AES_192_GCM AEAD_AES_256_GCM AEAD_CHACHA20_POLY1305 AES-128-CFB AES-128-CTR AES-192-CFB AES-192-CTR AES-256-CFB AES-256-CTR CHACHA20-IETF XCHACHA20
|
2017-07-26 18:56:24 +08:00
|
|
|
NOTE: chacha20-ietf-poly1305 = AEAD_CHACHA20_POLY1305
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2018-06-03 13:54:16 +08:00
|
|
|
SSR scheme:
|
2018-05-17 10:16:00 +08:00
|
|
|
ssr://method:pass@host:port?protocol=xxx&protocol_param=yyy&obfs=zzz&obfs_param=xyz
|
|
|
|
|
2018-07-05 20:44:19 +08:00
|
|
|
VMess scheme:
|
2018-07-06 11:13:25 +08:00
|
|
|
vmess://[security:]uuid@host:port?alterID=num
|
2018-07-05 20:44:19 +08:00
|
|
|
|
2018-07-12 11:22:21 +08:00
|
|
|
Available securities for vmess:
|
2018-07-11 08:34:15 +08:00
|
|
|
none, aes-128-gcm, chacha20-poly1305
|
|
|
|
|
|
|
|
TLS scheme:
|
|
|
|
tls://host:port[?skipVerify=true]
|
|
|
|
|
2018-08-01 00:36:11 +08:00
|
|
|
TLS with a specified proxy protocol:
|
2018-07-24 00:45:41 +08:00
|
|
|
tls://host:port[?skipVerify=true],scheme://
|
2018-07-11 08:34:15 +08:00
|
|
|
tls://host:port[?skipVerify=true],http://[user:pass@]
|
|
|
|
tls://host:port[?skipVerify=true],socks5://[user:pass@]
|
|
|
|
tls://host:port[?skipVerify=true],vmess://[security:]uuid@?alterID=num
|
2018-07-05 20:44:19 +08:00
|
|
|
|
2018-07-22 20:02:50 +08:00
|
|
|
Websocket scheme:
|
|
|
|
ws://host:port[/path]
|
|
|
|
|
2018-08-01 00:36:11 +08:00
|
|
|
Websocket with a specified proxy protocol:
|
2018-07-24 00:54:38 +08:00
|
|
|
ws://host:port[/path],scheme://
|
2018-07-22 20:02:50 +08:00
|
|
|
ws://host:port[/path],http://[user:pass@]
|
|
|
|
ws://host:port[/path],socks5://[user:pass@]
|
|
|
|
ws://host:port[/path],vmess://[security:]uuid@?alterID=num
|
|
|
|
|
2018-08-01 00:36:11 +08:00
|
|
|
TLS and Websocket with a specified proxy protocol:
|
2018-07-24 00:45:41 +08:00
|
|
|
tls://host:port[?skipVerify=true],ws://[@/path],scheme://
|
2018-07-22 20:02:50 +08:00
|
|
|
tls://host:port[?skipVerify=true],ws://[@/path],http://[user:pass@]
|
|
|
|
tls://host:port[?skipVerify=true],ws://[@/path],socks5://[user:pass@]
|
|
|
|
tls://host:port[?skipVerify=true],ws://[@/path],vmess://[security:]uuid@?alterID=num
|
|
|
|
|
2018-08-01 00:36:11 +08:00
|
|
|
DNS forwarding server:
|
|
|
|
dns=:53
|
|
|
|
dnsserver=8.8.8.8:53
|
|
|
|
dnsserver=1.1.1.1:53
|
|
|
|
dnsrecord=www.example.com/1.2.3.4
|
|
|
|
dnsrecord=www.example.com/2606:2800:220:1:248:1893:25c8:1946
|
|
|
|
|
2017-07-13 21:55:41 +08:00
|
|
|
Available forward strategies:
|
|
|
|
rr: Round Robin mode
|
|
|
|
ha: High Availability mode
|
|
|
|
|
2017-07-23 01:46:06 +08:00
|
|
|
Config file format(see `glider.conf.example` as an example):
|
|
|
|
# COMMENT LINE
|
|
|
|
KEY=VALUE
|
|
|
|
KEY=VALUE
|
|
|
|
# KEY equals to command line flag name: listen forward strategy...
|
|
|
|
|
2017-07-13 21:55:41 +08:00
|
|
|
Examples:
|
2017-07-18 19:25:54 +08:00
|
|
|
glider -config glider.conf
|
|
|
|
-run glider with specified config file.
|
|
|
|
|
2017-07-30 10:35:11 +08:00
|
|
|
glider -config glider.conf -rulefile office.rule -rulefile home.rule
|
|
|
|
-run glider with specified global config file and rule config files.
|
|
|
|
|
2017-07-18 19:25:54 +08:00
|
|
|
glider -listen :8443
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :8443, serve as http/socks5 proxy on the same port.
|
|
|
|
|
2017-07-18 19:25:54 +08:00
|
|
|
glider -listen ss://AEAD_CHACHA20_POLY1305:pass@:8443
|
2017-07-29 18:15:22 +08:00
|
|
|
-listen on 0.0.0.0:8443 as a ss server.
|
2017-07-13 21:55:41 +08:00
|
|
|
|
2017-07-18 19:25:54 +08:00
|
|
|
glider -listen socks5://:1080 -verbose
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :1080 as a socks5 proxy server, in verbose mode.
|
|
|
|
|
2017-07-18 19:25:54 +08:00
|
|
|
glider -listen http://:8080 -forward socks5://127.0.0.1:1080
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :8080 as a http proxy server, forward all requests via socks5 server.
|
|
|
|
|
2017-07-31 13:42:11 +08:00
|
|
|
glider -listen redir://:1081 -forward ss://method:pass@1.1.1.1:8443
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :1081 as a transparent redirect server, forward all requests via remote ss server.
|
|
|
|
|
2018-05-22 12:19:57 +08:00
|
|
|
glider -listen redir://:1081 -forward "ssr://method:pass@1.1.1.1:8444?protocol=a&protocol_param=b&obfs=c&obfs_param=d"
|
2018-05-17 10:16:00 +08:00
|
|
|
-listen on :1081 as a transparent redirect server, forward all requests via remote ssr server.
|
|
|
|
|
2018-07-12 11:22:21 +08:00
|
|
|
glider -listen redir://:1081 -forward "tls://1.1.1.1:443,vmess://security:uuid@?alterID=10"
|
2018-07-24 00:45:41 +08:00
|
|
|
-listen on :1081 as a transparent redirect server, forward all requests via remote tls+vmess server.
|
|
|
|
|
|
|
|
glider -listen redir://:1081 -forward "ws://1.1.1.1:80,vmess://security:uuid@?alterID=10"
|
|
|
|
-listen on :1081 as a transparent redirect server, forward all requests via remote ws+vmess server.
|
2018-07-05 20:44:19 +08:00
|
|
|
|
2017-07-31 13:42:11 +08:00
|
|
|
glider -listen tcptun://:80=2.2.2.2:80 -forward ss://method:pass@1.1.1.1:8443
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :80 and forward all requests to 2.2.2.2:80 via remote ss server.
|
|
|
|
|
2018-01-20 23:27:22 +08:00
|
|
|
glider -listen udptun://:53=8.8.8.8:53 -forward ss://method:pass@1.1.1.1:8443
|
|
|
|
-listen on :53 and forward all udp requests to 8.8.8.8:53 via remote ss server.
|
|
|
|
|
|
|
|
glider -listen uottun://:53=8.8.8.8:53 -forward ss://method:pass@1.1.1.1:8443
|
|
|
|
-listen on :53 and forward all udp requests via udp over tcp tunnel.
|
|
|
|
|
2017-07-31 13:42:11 +08:00
|
|
|
glider -listen socks5://:1080 -listen http://:8080 -forward ss://method:pass@1.1.1.1:8443
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :1080 as socks5 server, :8080 as http proxy server, forward all requests via remote ss server.
|
|
|
|
|
2018-08-01 00:36:11 +08:00
|
|
|
glider -listen redir://:1081 -dns=:53 -dnsserver=8.8.8.8:53 -forward ss://method:pass@server1:port1,ss://method:pass@server2:port2
|
2017-07-13 21:55:41 +08:00
|
|
|
-listen on :1081 as transparent redirect server, :53 as dns server, use forward chain: server1 -> server2.
|
|
|
|
|
2017-07-18 19:25:54 +08:00
|
|
|
glider -listen socks5://:1080 -forward ss://method:pass@server1:port1 -forward ss://method:pass@server2:port2 -strategy rr
|
2018-02-25 12:31:48 +08:00
|
|
|
-listen on :1080 as socks5 server, forward requests via server1 and server2 in round robin mode.
|
2018-08-01 00:36:11 +08:00
|
|
|
|
|
|
|
glider -verbose -dns=:53 -dnsserver=8.8.8.8:53 -dnsrecord=www.example.com/1.2.3.4
|
|
|
|
-listen on :53 as dns server, forward dns requests to 8.8.8.8:53, return 1.2.3.4 when resolving www.example.com.
|
2017-07-13 21:55:41 +08:00
|
|
|
```
|
|
|
|
|
2017-09-16 23:10:10 +08:00
|
|
|
## Advanced Usage
|
2017-09-03 01:05:56 +08:00
|
|
|
- [ConfigFile](config)
|
|
|
|
- [glider.conf.example](config/glider.conf.example)
|
|
|
|
- [office.rule.example](config/rules.d/office.rule.example)
|
|
|
|
- [Examples](config/examples)
|
2017-09-04 00:21:12 +08:00
|
|
|
- [transparent proxy with dnsmasq](config/examples/8.transparent_proxy_with_dnsmasq)
|
|
|
|
- [transparent proxy without dnsmasq](config/examples/9.transparent_proxy_without_dnsmasq)
|
2017-07-30 10:35:11 +08:00
|
|
|
|
2017-07-13 21:55:41 +08:00
|
|
|
## Service
|
2017-07-26 18:56:24 +08:00
|
|
|
- systemd: [https://github.com/nadoo/glider/blob/master/systemd/](https://github.com/nadoo/glider/blob/master/systemd/)
|
2017-07-14 11:20:02 +08:00
|
|
|
|
2017-07-18 19:45:35 +08:00
|
|
|
## Links
|
2017-09-04 00:21:12 +08:00
|
|
|
- [go-ss2](https://github.com/shadowsocks/go-shadowsocks2): ss protocol support
|
2017-07-21 18:58:51 +08:00
|
|
|
- [conflag](https://github.com/nadoo/conflag): command line and config file parse support
|
2017-07-23 01:46:06 +08:00
|
|
|
- [ArchLinux](https://www.archlinux.org/packages/community/x86_64/glider): a great linux distribution with glider pre-built package
|