diff --git a/config/flclash/flclash.yaml b/config/flclash/flclash.yaml index 42d31e2..9eaa655 100644 --- a/config/flclash/flclash.yaml +++ b/config/flclash/flclash.yaml @@ -9,33 +9,86 @@ mode: rule log-level: info external-controller: 127.0.0.1:9090 +tun: + enable: true # 1. 必须改为 true 才能真正启用 + stack: mixed # 2. 改为 mixed 性能最好,或者用 system + auto-route: true + strict-route: true # 3. 建议改为 true,开启严格路由模式,能够更彻底地封死特定软件绕过代理的行为 + auto-detect-interface: true + dns-hijack: + - any:53 # 4. 修正了这里的空格缩进,强行劫持全部本地 DNS 请求 + dns: enable: true - # listen: 0.0.0.0:53 - ipv6: false - - default-nameserver: - - 223.5.5.5 - - 119.29.29.29 + listen: 0.0.0.0:7874 enhanced-mode: fake-ip fake-ip-range: 198.18.0.1/16 use-hosts: true + use-system-hosts: true + + default-nameserver: + - 223.5.5.5 + - 119.29.29.29 nameserver: - - https://doh.pub/dns-query - - https://dns.alidns.com/dns-query - fallback: - - https://doh-pure.onedns.net/dns-query - - https://ada.openbld.net/dns-query - - https://223.5.5.5/dns-query - - https://223.6.6.6/dns-query - fallback-filter: - geoip: true - ipcidr: - - 240.0.0.0/4 - - 0.0.0.0/32 + - https://1.1.1.1/dns-query + - https://8.8.8.8/dns-query + nameserver-policy: + 'geosite:cn,apple,private': + - https://223.5.5.5/dns-query + - https://doh.pub/dns-query + - system + 'rule-set:salem@cn': [https://223.5.5.5/dns-query, https://doh.pub/dns-query] + 'geosite:geolocation-!cn,google,category-ai-!cn': + - https://1.1.1.1/dns-query#Google + - https://8.8.8.8/dns-query#Google + proxy-server-nameserver: + - 223.5.5.5 + - 119.29.29.29 + fake-ip-filter: + - '*.lan' + - "rule-set:salem@cn,GitHub,fake-ip-filter" + - 'geosite:cn' + #STUN + - '+.stun.*.*' + - '+.stun.*.*.*' + - '+.stun.*.*.*.*' + - '+.stun.*.*.*.*.*' + - 'stun.*' + - 'ntp.*.com' + - 'time.*.com' + - 'ntp?.*.com' + - 'time?.*.com' + - 'time.*.gov' + - 'time.*.edu.cn' + #微信登录 + - 'localhost.*.weixin.qq.com' + - 'localhost.*.qq.com' + #放行NTP服务 + - 'time.*.apple.com' + - 'time-ios.apple.com' + - 'time1.*.com' + - 'time2.*.com' + - 'time3.*.com' + - 'time4.*.com' + - 'time5.*.com' + - 'time6.*.com' + - 'time7.*.com' + - 'ntp1.*.com' + - 'ntp2.*.com' + - 'ntp3.*.com' + - 'ntp4.*.com' + - 'ntp5.*.com' + - 'ntp6.*.com' + - 'ntp7.*.com' + #Microsoft Xbox + - 'xbox.*.*.microsoft.com' + - '*.*.xboxlive.com' + - 'xbox.*.microsoft.com' + - '*.xboxlive.com' # 本地服务器 proxies: +- {name: "🟢 直连", type: direct, udp: true, ip-version: ipv4} # 订阅引用相关 u: &u {type: select, use: [Salem]} @@ -53,9 +106,9 @@ proxy-providers: # 代理组相关 o1: &o1 {type: select, use: [Salem], proxies: []} o2: &o2 {type: select, use: [Salem], proxies: ['节点选择']} -o3: &o3 {type: select, use: [Salem], proxies: ['DIRECT', '节点选择']} -o4: &o4 {type: select, use: [Salem], proxies: ['节点选择', 'DIRECT']} -o5: &o5 {type: select, use: [Salem], proxies: ['REJECT', 'DIRECT']} +o3: &o3 {type: select, use: [Salem], proxies: ['🟢 直连', '节点选择']} +o4: &o4 {type: select, use: [Salem], proxies: ['节点选择', '🟢 直连']} +o5: &o5 {type: select, use: [Salem], proxies: ['REJECT', '🟢 直连']} g5: &g5 {type: select, include-all: true} # 代理组