--- url: /faq.md description: >- 使用FlClash可以解决访问中国大陆难以访问的网站问题,对外贸业务有帮助。适合的机场包括符合Shadowsocks、VMess、Trojan、Snell、SOCKS5、HTTP(S)、Wireguard标准的机场。 --- # 常见问题 ## 使用 FlClash 后能够解决哪些问题? 使用[FlClash](/)代理有,选择其不通的节点,可以访问我们常见中国大陆不太容易访问的 Github、Google、YouTube、ChatGPT 等。 同时对做外贸业务的企业或网站非常有帮助,能够很顺畅的开展外部连接业务。 ## 有哪些机场(订阅代理)适合 FlClash? 简单来说,凡是符合 [Shadowsocks(R)](/wiki/Shadowsocks)、[VMess](/wiki/VMess)、[Trojan](/wiki/Trojan)、[Snell](/wiki/Snell)、[Socks5](/wiki/Socks5)、HTTP(S)、[Wireguard](/wiki/Wireguard) 等这些标准的[机场](/feed)都适合 FlClash。 --- --- url: /feed.md description: >- 机场推荐由网友收集和整理了值得推荐的机场,我们从中选择出一些靠谱机场,推荐给大家。推荐机场的标准中国大陆可以访问订阅套餐价格合理按量、月、年等周期流量节点相对满足需求能解锁绝大部分网站、视频、流媒体等网络 --- # 机场推荐 由网友收集和整理了值得推荐的机场,我们从中选择出一些靠谱机场,推荐给大家。 ![机场推荐](/assets/1714465249.webp) ## 推荐机场的标准 * 中国大陆可以访问 * 订阅套餐价格合理 * 按量、月、年等周期流量 * 节点相对满足需求 * 能解锁绝大部分网站、视频、流媒体等网络 ## 靠谱机场 --- --- url: /about.md description: >- FlClash 是一个基于 Clash 核心的多功能 GUI 工具,通过直观的界面和强大的功能,简化了网络代理的管理过程。无论是个人用户还是专业人士,FlClash 都为其提供了一个高效且可靠的解决方案。凭借其简洁的设计、广泛的协议支持和跨平台兼容性,FlClash 成为优化互联网体验的必备工具。 --- # 介绍 FlClash:适用于 Clash 的多功能图形用户界面。 [FlClash](/) 是一款基于 Clash 核心的多功能图形用户界面 (GUI) 工具,专为那些需要简单、直观地管理网络代理的用户设计。它通过丰富的功能和友好的界面,简化了代理配置和管理过程,为用户提供了一个高效且稳定的解决方案。 FlClash桌面端截图: ![FlClash On Desktop](/assets/desktop.gif) FlClash移动端截图: ![FlClash On Mobile](/assets/mobile.gif) ## 什么是 FlClash? FlClash 是一个专为 Clash 核心打造的 GUI 工具,旨在帮助用户在各种设备上轻松管理他们的代理设置。Clash 是一个强大的跨平台代理工具,支持多种协议,如 [Shadowsocks](/wiki/Shadowsocks)、[VMess](/wiki/VMess)、[Trojan](/wiki/Trojan) 等。然而,由于其命令行操作可能对一些用户不够友好,FlClash 通过图形化界面填补了这一空白,使得用户能够更直观地进行操作。 ## FlClash 的主要特点 1. **简洁的用户界面**:FlClash 提供了一个干净且易于导航的界面,用户可以轻松找到所需的功能。无论是配置代理、管理规则,还是实时监控流量,FlClash 都使这些任务变得简单明了。 2. **广泛的协议支持**:FlClash 支持多种流行的代理协议,包括 Shadowsocks、VMess 和 Trojan 等。用户可以根据自己的需求选择和配置适合的代理类型,并通过 FlClash 轻松管理这些配置。 3. **动态规则管理**:FlClash 允许用户基于 IP 地址、域名等创建并管理自定义的路由规则。通过这些规则,用户可以灵活地控制流量,绕过地理限制,优化网络性能。 4. **实时流量监控**:FlClash 提供了实时的流量监控功能,用户可以随时查看代理的使用情况,了解网络流量的走向,从而更好地管理和优化他们的网络体验。 5. **多平台兼容性**:FlClash 支持多种操作系统,包括 Windows、macOS 和 Linux。这种跨平台的兼容性确保了无论用户使用什么设备,都能享受到 FlClash 的便捷和高效。 ## 为什么选择 FlClash? FlClash 通过提供一个用户友好的界面,极大地降低了使用 Clash 的门槛,使得即使是没有技术背景的用户也能轻松上手。此外,它广泛的协议支持、强大的规则管理和实时监控功能,使得 FlClash 成为网络代理管理领域的强大工具。 对于那些希望通过 GUI 管理代理设置的用户来说,FlClash 是一个理想的选择。它不仅简化了配置过程,还提供了丰富的功能,帮助用户最大限度地利用 Clash 的强大功能。 ## 总结 FlClash 是一个基于 Clash 核心的多功能 GUI 工具,通过直观的界面和强大的功能,简化了网络代理的管理过程。无论是个人用户还是专业人士,FlClash 都为其提供了一个高效且可靠的解决方案。凭借其简洁的设计、广泛的协议支持和跨平台兼容性,FlClash 成为优化互联网体验的必备工具。 --- --- url: /ver.md description: FlClash 版本更新,实时更新和发布FlClash的版本更新情况,如:Changes、Features、Fixes等版本细节内容。 --- # 更新 --- --- url: /en/download.md description: >- FlClash provides multi-platform versions. Users can download installation packages for Windows, Mac and Android through GitHub or mirror addresses. --- # Download [FlClash](/) is currently hosted on Github and can be downloaded from `Releases`. The download from GitHub is unstable. If the download fails, you can try to download from the `mirror address`. **FlClash common version download corresponding version is as follows:** * Windows users download installation version: `FlClash-0.*.**-windows-amd64-setup.exe` * Intel chip Mac installation: `FlClash-0.*.**-macos-amd64.dmg` * M chip Mac installation: `FlClash-0.*.**-macos-arm64.dmg` * Android users download: `FlClash-0.*.**-android-arm64-v8a.apk` Detailed version correspondence is as follows: This table clearly shows the correspondence between the platform and the file suffix. **FlClash download address:** * [Github](https://github.com/chen08209/FlClash/releases) * [Mirror address](https://dl.p6p.net/FlClash/) --- --- url: /en/releases/v0.8.61.md description: '修复android系统dns问题。[chen08209],优化dns默认选项,修复部分问题,更新readme。[chen08209]' --- # FlClash v0.8.61 * 修复android系统dns问题。\[chen08209] * 优化dns默认选项 * 修复部分问题 * 更新readme。\[chen08209] * 更新README.md 2。\[chen08209] * 更新README.md 2。\[chen08209] * 更新README.md。\[chen08209] --- --- url: /releases/v0.8.61.md description: '修复android系统dns问题。[chen08209],优化dns默认选项,修复部分问题,更新readme。[chen08209]' --- # FlClash v0.8.61 * 修复android系统dns问题。\[chen08209] * 优化dns默认选项 * 修复部分问题 * 更新readme。\[chen08209] * 更新README.md 2。\[chen08209] * 更新README.md 2。\[chen08209] * 更新README.md。\[chen08209] --- --- url: /en/releases/v0.8.63.md description: '修复 windows 管理员自动启动问题。[chen08209],添加 android vpn 选项,支持代理图标配置,优化 android 沉浸式显示……' --- # FlClash v0.8.63 * 修复 windows 管理员自动启动问题。\[chen08209] * 添加 android vpn 选项 * 支持代理图标配置 * 优化 android 沉浸式显示 * 修复一些问题 --- --- url: /releases/v0.8.63.md description: '修复 windows 管理员自动启动问题。[chen08209],添加 android vpn 选项,支持代理图标配置,优化 android 沉浸式显示……' --- # FlClash v0.8.63 * 修复 windows 管理员自动启动问题。\[chen08209] * 添加 android vpn 选项 * 支持代理图标配置 * 优化 android 沉浸式显示 * 修复一些问题 --- --- url: /en/releases/v0.8.64.md description: 更新发布消息,初始化自动更改日志,修复窗口托盘问题,修复 urltest 问题,添加自动更改日志…… --- # FlClash v0.8.64 * 更新发布消息 * 初始化自动更改日志 * 修复窗口托盘问题 * 修复 urltest 问题 * 添加自动更改日志 --- --- url: /releases/v0.8.64.md description: 更新发布消息,初始化自动更改日志,修复窗口托盘问题,修复 urltest 问题,添加自动更改日志…… --- # FlClash v0.8.64 * 更新发布消息 * 初始化自动更改日志 * 修复窗口托盘问题 * 修复 urltest 问题 * 添加自动更改日志 --- --- url: /en/releases/v0.8.66.md description: 修复折叠问题,添加 fontFamily 选项…… --- # FlClash v0.8.66 * Fix the collapse issues * Add fontFamily options --- --- url: /releases/v0.8.66.md description: 修复折叠问题,添加 fontFamily 选项…… --- # FlClash v0.8.66 * Fix the collapse issues * Add fontFamily options --- --- url: /releases/v0.8.76.md description: FlClash v0.8.76,Fix scroll physics error …… --- # FlClash v0.8.76 * Fix scroll physics error --- --- url: /en/releases/v0.8.82.md description: >- Optimize android vpn performance, Add custom primary color and color scheme, Add linux nad windows arm release, Optimize requests and logs page, Fix map input page delete issues, Update changelog --- # FlClash v0.8.82 * Optimize android vpn performance * Add custom primary color and color scheme * Add linux nad windows arm release * Optimize requests and logs page * Fix map input page delete issues * Update changelog --- --- url: /releases/v0.8.82.md description: >- 优化 Android VPN 性能,添加自定义原色和配色方案,添加 Linux、Windows、ARM 版本,优化请求和日志页面,修复地图输入页面删除问题,更新更新日志 --- # FlClash v0.8.82 * 优化 Android VPN 性能 * 添加自定义原色和配色方案 * 添加 Linux、Windows、ARM 版本 * 优化请求和日志页面 * 修复地图输入页面删除问题 * 更新更新日志 --- --- url: /en/releases/v0.8.84.md description: >- Fix issues that TUN repeat failed to open. Update changelog, Fix windows service verify issues, Update changelog. --- # FlClash v0.8.84 * Fix issues that TUN repeat failed to open. * Update changelog * Fix windows service verify issues * Update changelog --- --- url: /releases/v0.8.84.md description: 修复 TUN repeat 无法打开的问题。 更新更新日志,修复 Windows 服务验证问题,更新更新日志。 --- # FlClash v0.8.84 * 修复 TUN repeat 无法打开的问题。 * 更新更新日志 * 修复 Windows 服务验证问题 * 更新更新日志 --- --- url: /en/releases/v0.8.85.md description: >- Support override script Support proxies search Support svg display Optimize config persistence Add some scenes auto close connections --- # FlClash v0.8.85 * Support override script * Support proxies search * Support svg display * Optimize config persistence * Add some scenes auto close connections * Update core * Optimize more details --- --- url: /releases/v0.8.85.md description: 支持覆盖脚本 支持代理搜索 支持 SVG 显示 优化配置持久化 增加部分场景自动关闭连接 --- # FlClash v0.8.85 * 支持覆盖脚本 * 支持代理搜索 * 支持 SVG 显示 * 优化配置持久化 * 增加部分场景自动关闭连接 * 更新核心 * 优化更多细节 --- --- url: /en/releases/v0.8.86.md description: >- Fix windows tun issues Optimize android get system dns Optimize more details Update changelog --- # FlClash v0.8.86 * Fix windows tun issues * Optimize android get system dns * Optimize more details * Update changelog --- --- url: /releases/v0.8.86.md description: 修复 Windows Tun 问题 优化 Android 获取系统 DNS 优化更多细节 更新变更日志 --- # FlClash v0.8.86 * 修复 Windows tun 问题 * 优化 Android 获取系统 DNS * 优化更多细节 * 更新更新日志 --- --- url: /en/releases/v0.8.87.md description: >- Optimize desktop view Optimize logs, requests, connection pages Optimize windows tray auto hide Optimize some details Update core Update changelog --- # FlClash v0.8.87 * Optimize desktop view * Optimize logs, requests, connection pages * Optimize windows tray auto hide * Optimize some details * Udate core * Update changelog --- --- url: /releases/v0.8.87.md description: 优化桌面视图 优化日志、请求、连接页面 优化托盘自动隐藏 优化部分细节 更新核心 更新更新日志 --- # FlClash v0.8.87 * 优化桌面视图 * 优化日志、请求、连接页面 * 优化托盘自动隐藏 * 优化部分细节 * 更新核心 * 更新更新日志 --- --- url: /en/releases/v0.8.89.md description: '- Bug fixes - Optimizes Windows service mode - Core updates - Update changelog' --- # FlClash v0.8.89 * Bug fixes * Optimizes Windows service mode * Core updates * Update changelog --- --- url: /releases/v0.8.89.md description: '- 修复一些问题 - 优化 Windows 服务模式 - 更新核心 - 更新变更日志' --- # FlClash v0.8.89 * 修复一些问题 * 优化 Windows 服务模式 * 更新核心 * 更新变更日志 --- --- url: /en/releases/v0.8.90.md description: >- Fix android tile service Support append system DNS Fix some issues Update changelog --- # FlClash v0.8.89 * Fix android tile service * Support append system DNS * Fix some issues * Update changelog --- --- url: /releases/v0.8.90.md description: 修复 Android Tile 服务 支持附加系统 DNS 修复一些问题 更新更新日志 --- # FlClash v0.8.90 * 修复 Android Tile 服务 * 支持附加系统 DNS * 修复一些问题 * 更新更新日志 --- --- url: /en/releases/v0.8.91.md description: >- Fix some Windows issues, optimize overwrite handling, access control page, and other details --- # FlClash v0.8.91 * Fix some issues on Windows * Optimize overwrite handling * Optimize the access control page * Optimize some details --- --- url: /releases/v0.8.91.md description: 修复 Windows 部分问题,优化覆盖处理与访问控制页面,优化部分细节 --- # FlClash v0.8.91 * 修复 Windows 平台部分问题 * 优化覆盖(overwrite)处理逻辑 * 优化访问控制页面 * 优化部分细节体验 --- --- url: /en/releases/v0.8.93.md description: >- Support custom overwrite, support run on demand, optimize Windows IPC, optimize Windows ARM64, optimize build, optimize some details, update core --- # FlClash v0.8.93 * Support custom overwrite * Support run on demand * Optimize Windows IPC * Optimize Windows ARM64 * Optimize build * Optimize some details * Update core --- --- url: /releases/v0.8.93.md description: 支持自定义覆盖(overwrite),支持按需运行,优化 Windows IPC,优化 Windows ARM64,优化构建,优化部分细节体验,更新核心 --- # FlClash v0.8.93 * 支持自定义覆盖(overwrite) * 支持按需运行 * 优化 Windows IPC * 优化 Windows ARM64 * 优化构建 * 优化部分细节体验 * 更新核心 --- --- url: /en/releases/v0.8.94.md description: >- Fix macOS performance issue, support custom global-ua, update core, optimize some details, fix Linux silent launching not working --- # FlClash v0.8.94 * Fix macOS performance issue * Support custom global-ua * Update core * Optimize some details * Fix Linux silent launching not working --- --- url: /releases/v0.8.94.md description: 修复 macOS 性能问题,支持自定义 global-ua,更新核心,优化部分细节体验,修复 Linux 静默启动不生效 --- # FlClash v0.8.94 * 修复 macOS 性能问题 * 支持自定义 global-ua * 更新核心 * 优化部分细节体验 * 修复 Linux 静默启动不生效 --- --- url: /en/ver.md description: >- FlClash version update, real-time update and release of FlClash version update status, such as: Changes, Features, Fixes and other version details. --- # Update --- --- url: /download.md description: FlClash 提供多平台版本,用户可通过 GitHub 或镜像地址下载适用于 Windows、Mac 和 Android 的安装包。 --- # 下载 [FlClash](/)目前托管在Github上面,可以从`Releases`下载。github的下载不稳定,如果下载失败,可以尝试从`镜像地址`下载。 **FlClash常见版本下载对应版本如下:** * Windows 用户下载安装版:`FlClash-0.*.**-windows-amd64-setup.exe` * Intel 芯片 Mac 安装:`FlClash-0.*.**-macos-amd64.dmg` * M 芯片 Mac 安装:`FlClash-0.*.**-macos-arm64.dmg` * Android 用户下载:`FlClash-0.*.**-android-arm64-v8a.apk` 详细版本对应如下: 这个表格清晰地展示了平台与文件后缀的对应关系。 **FlClash下地址:** * [Github](https://github.com/chen08209/FlClash/releases) * [镜像地址](https://dl.p6p.net/FlClash/) --- --- url: /tutorial.md description: 下载安装FlClash后,通过订阅导入订阅地址,选择代理节点并激活,然后在系统设置中激活代理即可。 --- # 教程 FlClash [下载](/download)和安装之后,可用通过 **FlClash 使用教程**配置好[FlClash](/)。 ## 一、导入订阅链接 ### 1.一键导入 [机场](/feed)面板基本都有导入到Clash的按钮,直接一键导入即可。以v2board面板为例子:点击首页的一键订阅导入的clash。 ![一键导入](/assets/0.webp) ### 2.手动复制订阅导入 选择【配置】页面–点击加号–选择 第三个URL–粘贴复制的订阅进去–提交 ![配置](/assets/1.webp) ![URL](/assets/2.webp) ## 二、打开开关,开始使用 打开首页仪表盘右下角开关即可使用。就这么简单,太方便了。打开开关就是开启系统代理(接管你电脑的所有请求,clash进行分流需不需要走代理),很多用户根本不明白系统代理是什么意思,也不需要知道其实。 ![打开开关,开始使用](/assets/3.webp) ## 三、选择节点 代理页面可以选择一个节点,默认是自动选择的。 ![选择节点](/assets/4.webp) ## 四、其他设置 ### 1.开机自启–工具–应用程序 ![开机自启](/assets/5.webp) ![开机自启](/assets/6.webp) --- --- url: /en/faq.md description: >- Using FlClash can solve the problem of accessing websites that are difficult to access in mainland China, which is helpful for foreign trade business. Suitable airports include airports that meet the standards of Shadowsocks, VMess, Trojan, Snell, SOCKS5, HTTP(S), and Wireguard. --- # Frequently Asked Questions ## What problems can be solved after using FlClash? Using [FlClash](/) proxy, select its unreachable node, and you can access Github, Google, YouTube, ChatGPT, etc., which are not easy to access in mainland China. At the same time, it is very helpful for enterprises or websites doing foreign trade business, and can smoothly carry out external connection business. ## Which airports (subscription agents) are suitable for FlClash? In short, any [airport](/feed) that meets the standards such as [Shadowsocks(R)](/en/wiki/Shadowsocks), [VMess](/en/wiki/VMess), [Trojan](/en/wiki/Trojan), [Snell](/en/wiki/Snell), [Socks5](/en/wiki/Socks5), HTTP(S), [Wireguard](/en/wiki/Wireguard), etc. is suitable for FlClash. --- --- url: /en/tutorial.md description: >- After downloading and installing FlClash, import the subscription address through subscription, select the proxy node and activate it, and then activate the proxy in the system settings. --- # Tutorial After downloading and installing FlClash, you can configure [FlClash](/) through **FlClash tutorial**. ## 1. Import subscription links ### 1. One-click import [Airport](/en/feed) panels basically have buttons to import to Clash, which can be imported directly with one click. Take the v2board panel as an example: click the one-click subscription on the homepage to import Clash. ![One-click import](/assets/0.webp) ### 2. Manually copy subscription import Select the \[Configuration] page – click the plus sign – select the third URL – paste the copied subscription in – submit ![Configuration](/assets/1.webp) ![URL](/assets/2.webp) ## 2. Turn on the switch and start using Turn on the switch in the lower right corner of the home dashboard to use it. It's that simple, so convenient. Turning on the switch means turning on the system proxy (taking over all requests from your computer, whether clash needs to go through a proxy for diversion). Many users don't understand what the system proxy means, and don't need to know it. ![Turn on the switch and start using](/assets/3.webp) ## 3. Select a node You can select a node on the proxy page, and it is automatically selected by default. ![Select Node](/assets/4.webp) ## 4. Other Settings ### 1. Startup – Tools – Applications ![Startup](/assets/5.webp) ![Startup](/assets/6.webp) --- --- url: /en/about.md description: >- FlClash is a multi-functional GUI tool based on Clash core, which simplifies the management process of network proxies through an intuitive interface and powerful functions. Whether it is individual users or professionals, FlClash provides an efficient and reliable solution. With its simple design, wide protocol support and cross-platform compatibility, FlClash has become a must-have tool for optimizing Internet experience. --- # Introduction FlClash: Multi-functional Graphical User Interface for Clash. [FlClash](/) is a multi-functional graphical user interface (GUI) tool based on Clash core, designed for users who need simple and intuitive management of network proxies. It simplifies the proxy configuration and management process through rich functions and friendly interface, providing users with an efficient and stable solution. FlClash Desktop Screenshot: ![FlClash On Desktop](/assets/desktop.gif) FlClash Mobile Screenshot: ![FlClash On Mobile](/assets/mobile.gif) ## What is FlClash? FlClash is a GUI tool built for Clash core, designed to help users easily manage their proxy settings on various devices. Clash is a powerful cross-platform proxy tool that supports multiple protocols such as [Shadowsocks](/en/wiki/Shadowsocks), [VMess](/en/wiki/VMess), [Trojan](/en/wiki/Trojan), etc. However, since its command line operation may not be friendly enough for some users, FlClash fills this gap through a graphical interface, allowing users to operate more intuitively. ## Main features of FlClash 1. **Simple user interface**: FlClash provides a clean and easy-to-navigate interface where users can easily find the features they need. Whether it is configuring proxies, managing rules, or monitoring traffic in real time, FlClash makes these tasks simple and clear. 2. **Extensive protocol support**: FlClash supports a variety of popular proxy protocols, including Shadowsocks, VMess, and Trojan. Users can choose and configure the appropriate proxy type according to their needs, and easily manage these configurations through FlClash. 3. **Dynamic rule management**: FlClash allows users to create and manage customized routing rules based on IP addresses, domain names, etc. With these rules, users can flexibly control traffic, bypass geographic restrictions, and optimize network performance. 4. **Real-time traffic monitoring**: FlClash provides real-time traffic monitoring capabilities, users can view proxy usage at any time, understand the direction of network traffic, and better manage and optimize their network experience. 5. **Multi-platform compatibility**: FlClash supports multiple operating systems, including Windows, macOS, and Linux. This cross-platform compatibility ensures that users can enjoy the convenience and efficiency of FlClash no matter what device they use. ## Why choose FlClash? FlClash greatly reduces the threshold for using Clash by providing a user-friendly interface, making it easy for even users without a technical background to get started. In addition, its wide range of protocol support, powerful rule management, and real-time monitoring capabilities make FlClash a powerful tool in the field of network proxy management. For those who want to manage proxy settings through a GUI, FlClash is an ideal choice. It not only simplifies the configuration process, but also provides rich features to help users maximize the power of Clash. ## Summary FlClash is a multi-functional GUI tool based on the Clash core, which simplifies the management process of network proxies through an intuitive interface and powerful functions. Whether it is an individual user or a professional, FlClash provides an efficient and reliable solution. With its simple design, wide protocol support and cross-platform compatibility, FlClash becomes an essential tool for optimizing your Internet experience. --- --- url: /en.md --- --- --- url: /en/feed.md description: >- Recommended Proxy are collected and sorted by netizens. We have selected some reliable Proxy and recommend them to you. Recommended airport standards Mainland China can access the subscription package at a reasonable price. The nodes meet the demand for periodic traffic such as volume, month, and year. It can unlock most websites, videos, streaming media and other networks. --- # Recommended Proxy Netizens have collected and sorted out Proxy that are worth recommending. We have selected some reliable Proxy and recommend them to you. ![Airport recommendation](/assets/1714465249.webp) ## Recommended Proxy standards * Mainland China can access * Subscription package at a reasonable price * Periodic traffic such as volume, month, and year * Nodes meet the demand relatively * It can unlock most websites, videos, streaming media and other networks ## Proxy --- --- url: /en/wiki/RESTful-API.md description: >- RESTful API (Representational State Transfer API) is an application interface design method based on the REST architectural style, widely used for data exchange between Web services and systems. REST was first proposed by Roy Fielding in his doctoral dissertation in 2000, emphasizing principles such as statelessness, client-server separation, unified interface, and cacheability. The core of RESTful API is to create, read, update, and delete resources (CRUD) through the HTTP protocol. --- # RESTful API RESTful API (Representational State Transfer API) is an application interface design method based on the REST architectural style, widely used for data exchange between Web services and systems. REST was first proposed by Roy Fielding in his doctoral dissertation in 2000, emphasizing principles such as statelessness, client-server separation, unified interface, and cacheability. The core of RESTful API is to create, read, update, and delete resources (CRUD) through the HTTP protocol. ## Features of RESTful API * **Stateless**: Each request contains all necessary information (such as authentication information), and the server does not retain the client's state between requests. * **Client-Server Architecture**: The client is responsible for the user interface and user experience, and the server is responsible for data storage and business logic, which are independent of each other. * **Uniform Interface**: RESTful API uses standard HTTP verbs (GET, POST, PUT, DELETE, etc.) for operation, and the interface design specifications are consistent, easy to understand and use. * **Cacheability**: Response data can be marked as cacheable to improve performance and reduce server load. * **Layered System**: Improve the scalability and security of the system through the middle layer (such as load balancer, proxy server). * **Encoding on Demand**: The server can send code or scripts to the client for execution to enhance client functionality. ## HTTP Verbs * **GET**: Used to read resources without any impact on resources on the server. * **POST**: Used to create new resources or submit data. The server creates new resources after processing the request. * **PUT**: used to update existing resources, overwriting the resources on the server with the data provided by the client. * **DELETE**: used to delete resources on the server. * **PATCH**: used to partially update resources and change part of the content of resources. ## URL design RESTful API uses Uniform Resource Identifiers (URIs) to represent resources, and each resource has a unique URL. The relationship between resources is represented by the URL hierarchy. Example URL design: * `GET /books`: Get a list of all books. * `GET /books/{id}`: Get a book with a specific ID. * `POST /books`: Create a new book. * `PUT /books/{id}`: Update a book with a specific ID. * `DELETE /books/{id}`: Delete a book with a specific ID. ## Response status code RESTful API uses HTTP status codes to indicate the processing results of the request: * **200 OK**: The request is successful and data is returned. * **201 Created**: The resource is created successfully. * **204 No Content**: Request successful, no content returned. * **400 Bad Request**: Request invalid or malformed. * **401 Unauthorized**: Request unauthorized. * **404 Not Found**: Requested resource does not exist. * **500 Internal Server Error**: Server internal error. ## Example The following is a simple RESTful API example that uses Node.js and Express framework to create a book management system. ### Server code (Node.js + Express) ```javascript const express = require('express'); const app = express(); app.use(express.json()); let books = [ { id: 1, title: '1984', author: 'George Orwell' }, { id: 2, title: 'To Kill a Mockingbird', author: 'Harper Lee' } ]; // Get all books app.get('/books', (req, res) => { res.json(books); }); // Get a specific book app.get('/books/:id', (req, res) => { const book = books.find(b => b.id === parseInt(req.params.id)); if (!book) return res.status(404).send('Book not found'); res.json(book); }); // Create a new book app.post('/books', (req, res) => { const book = { id: books.length + 1, title: req.body.title, author: req.body.author }; books.push(book); res.status(201).json(book); }); // Update a book app.put('/books/:id', (req, res ) => { const book = books.find(b => b.id === parseInt(req.params.id)); if (!book) return res.status(404).send('Book not found'); book.title = req.body.title; book.author = req.body.author; res.json(book); }); // Delete books app.delete('/books/:id', (req, res) => { const book = books.find(b => b.id === parseInt(req.params.id)); if (!book) return res.status(404).send('Book not found'); const index = books.indexOf(book); books.splice(index, 1); res.status(204).send(); }); const port = process.env.PORT || 3000; app.listen(port, () => console.log(`Listening on port ${port}...`)); ``` ## Summary RESTful API is a simple, flexible, and easy-to-extend Web service design approach that operates through standard HTTP protocols and verbs, making communication between clients and servers more intuitive and efficient. It is suitable for Web applications of all sizes, from small projects to large distributed systems. --- --- url: /wiki/RESTful-API.md description: >- RESTful API(Representational State Transfer API)是一种基于REST架构风格的应用程序接口设计方法,广泛用于Web服务和系统之间的数据交换。REST由Roy Fielding在2000年的博士论文中首次提出,强调无状态性、客户端-服务器分离、统一接口、可缓存性等原则。RESTful API的核心是通过HTTP协议进行资源的创建、读取、更新和删除操作(CRUD)。 --- # RESTful API RESTful API(Representational State Transfer API)是一种基于REST架构风格的应用程序接口设计方法,广泛用于Web服务和系统之间的数据交换。REST由Roy Fielding在2000年的博士论文中首次提出,强调无状态性、客户端-服务器分离、统一接口、可缓存性等原则。RESTful API的核心是通过HTTP协议进行资源的创建、读取、更新和删除操作(CRUD)。 ## RESTful API 的特点 * **无状态性**:每个请求都包含了所有必要的信息(如身份验证信息),服务器不会在请求之间保留客户端的状态。 * **客户端-服务器架构**:客户端负责用户界面和用户体验,服务器负责数据存储和业务逻辑,二者相互独立。 * **统一接口**:RESTful API使用标准的HTTP动词(GET、POST、PUT、DELETE等)进行操作,接口设计规范一致,易于理解和使用。 * **可缓存性**:响应数据可以被标记为可缓存,以提高性能和减少服务器负载。 * **分层系统**:通过中间层(如负载均衡器、代理服务器)提升系统的可伸缩性和安全性。 * **按需编码**:服务器可以将代码或脚本发送到客户端执行,以增强客户端功能。 ## HTTP动词 * **GET**:用于读取资源,不会对服务器上的资源造成任何影响。 * **POST**:用于创建新资源或提交数据,服务器处理请求后创建新资源。 * **PUT**:用于更新现有资源,将客户端提供的数据覆盖服务器上的资源。 * **DELETE**:用于删除服务器上的资源。 * **PATCH**:用于部分更新资源,改变资源的部分内容。 ## URL设计 RESTful API使用统一资源标识符(URI)来表示资源,每个资源有一个唯一的URL。资源之间的关系通过URL层级表示。 示例URL设计: * `GET /books`:获取所有图书列表。 * `GET /books/{id}`:获取特定ID的图书。 * `POST /books`:创建新图书。 * `PUT /books/{id}`:更新特定ID的图书。 * `DELETE /books/{id}`:删除特定ID的图书。 ## 响应状态码 RESTful API使用HTTP状态码来表示请求的处理结果: * **200 OK**:请求成功,返回数据。 * **201 Created**:资源创建成功。 * **204 No Content**:请求成功,无返回内容。 * **400 Bad Request**:请求无效或格式错误。 * **401 Unauthorized**:请求未经授权。 * **404 Not Found**:请求的资源不存在。 * **500 Internal Server Error**:服务器内部错误。 ## 示例 以下是一个简单的RESTful API示例,使用Node.js和Express框架创建一个书籍管理系统。 ### 服务器代码(Node.js + Express) ```javascript const express = require('express'); const app = express(); app.use(express.json()); let books = [ { id: 1, title: '1984', author: 'George Orwell' }, { id: 2, title: 'To Kill a Mockingbird', author: 'Harper Lee' } ]; // 获取所有书籍 app.get('/books', (req, res) => { res.json(books); }); // 获取特定书籍 app.get('/books/:id', (req, res) => { const book = books.find(b => b.id === parseInt(req.params.id)); if (!book) return res.status(404).send('Book not found'); res.json(book); }); // 创建新书籍 app.post('/books', (req, res) => { const book = { id: books.length + 1, title: req.body.title, author: req.body.author }; books.push(book); res.status(201).json(book); }); // 更新书籍 app.put('/books/:id', (req, res) => { const book = books.find(b => b.id === parseInt(req.params.id)); if (!book) return res.status(404).send('Book not found'); book.title = req.body.title; book.author = req.body.author; res.json(book); }); // 删除书籍 app.delete('/books/:id', (req, res) => { const book = books.find(b => b.id === parseInt(req.params.id)); if (!book) return res.status(404).send('Book not found'); const index = books.indexOf(book); books.splice(index, 1); res.status(204).send(); }); const port = process.env.PORT || 3000; app.listen(port, () => console.log(`Listening on port ${port}...`)); ``` ## 总结 RESTful API是一种简单、灵活、易于扩展的Web服务设计方法,通过标准的HTTP协议和动词进行操作,使得客户端和服务器之间的通信更加直观和高效。它适用于各种规模的Web应用程序,从小型项目到大型分布式系统。 --- --- url: /en/wiki/Shadowsocks.md description: >- Shadowsocks is an open-source proxy software originally created by a Chinese programmer named "clowwindy". It is designed to break through China's Internet censorship. --- # Shadowsocks Shadowsocks is an open-source proxy software originally created by a Chinese programmer named "clowwindy". It is designed to break through China's Internet censorship. Here's how Shadowsocks works: * **Proxy mechanism**: Shadowsocks uses the [Socks5](/en/wiki/Socks5) proxy protocol to encrypt the user's Internet traffic and send it through a relay server. The relay server can be located anywhere, thus bypassing geographical restrictions and Internet censorship. * **Encryption**: Shadowsocks uses a variety of encryption algorithms (such as AES, Chacha20) to protect the user's traffic from being monitored or tampered with. * **Distributed network**: Users can build their own Shadowsocks servers, or use public Shadowsocks servers. --- --- url: /wiki/Shadowsocks.md description: Shadowsocks是一种开源的代理软件,最初由中国程序员"clowwindy"创建。它的设计目的是为了突破中国的网络审查。 --- # Shadowsocks Shadowsocks是一种开源的代理软件,最初由中国程序员"clowwindy"创建。它的设计目的是为了突破中国的网络审查。Shadowsocks的工作原理如下: * **代理机制**:Shadowsocks使用[Socks5](/wiki/Socks5)代理协议,将用户的互联网流量加密并通过一个中转服务器发送。中转服务器可以位于任何地方,从而绕过地域限制和网络审查。 * **加密**:Shadowsocks使用多种加密算法(如AES、Chacha20)来保护用户的流量不被监视或篡改。 * **分布式网络**:用户可以自行搭建Shadowsocks服务器,或者使用公共的Shadowsocks服务器。 --- --- url: /en/wiki/Snell.md description: >- Trojan is a proxy tool based on the HTTPS protocol, designed to bypass network censorship covertly and efficiently. Trojan uses TLS encryption to make its traffic look the same as normal HTTPS traffic, making it difficult to detect and intercept by network censorship mechanisms such as the Great Firewall (GFW) --- # Snell Snell is a proxy protocol designed for high speed, low latency and stealth, created by Chinese developers. Snell aims to provide faster and more stable network connections than existing proxy protocols (such as [Shadowsocks](/en/wiki/Shadowsocks) and [VMess](/en/wiki/VMess)), while having high stealth and being difficult to detect and block. The following is a detailed introduction to Snell: ## Features of Snell * **High performance**: Snell is designed with a focus on speed and low latency, suitable for applications with high bandwidth requirements, such as HD video streaming, online games, etc. * **Stealth**: Snell obfuscates and encrypts traffic, making its traffic look like ordinary network traffic, making it difficult to detect and block. * **Simple configuration**: Snell is relatively simple to configure and deploy, and users can get started quickly. * **Cross-platform support**: Snell supports multiple operating systems, including Windows, macOS, Linux, etc., making it convenient for users to use on different devices. ## Working principle The working principle of Snell is similar to other proxy protocols, mainly including the following steps: * **Client configuration**: The user configures the Snell client locally and specifies the address, port, key and other information of the Snell server to be connected. * **Server configuration**: Deploy the Snell server on the remote server, set the listening port and verification key, etc. * **Connection establishment**: The client and the server establish a connection through an encrypted channel to ensure the security and concealment of data transmission. * **Data transmission**: Once the connection is established, all traffic from the client will be forwarded through the Snell server, thereby achieving scientific Internet access and privacy protection. ## Application scenarios * **Scientific Internet access**: Through Snell, users can bypass network censorship and regional restrictions and access blocked content and services. * **Privacy protection**: Snell's encryption and obfuscation technology ensures that users' network traffic is not monitored and analyzed, improving privacy and security. * **High-bandwidth applications**: Due to its high performance, Snell is very suitable for application scenarios that require high bandwidth and low latency, such as video streaming, online games, etc. ## Relationship with other proxy protocols Snell is similar to proxy protocols such as [Shadowsocks](/en/wiki/Shadowsocks), [VMess](/en/wiki/VMess), and [Trojan](/en/wiki/Trojan), all of which are tools designed to bypass network censorship and protect privacy. In contrast, Snell focuses more on high performance and concealment, and is suitable for users who have high requirements for speed and stability. Although Snell's current scope of use and popularity may not be as wide as other protocols, its superior performance and concealment make it the choice of many users. ## Summary Snell is a high-performance, high-concealment proxy protocol suitable for users who need fast and stable network connections. Its simple configuration and deployment process allows users to quickly get started and use it on a variety of operating systems. With Snell, users can surf the Internet scientifically, protect privacy, and meet the needs of high-bandwidth applications. --- --- url: /wiki/Snell.md description: >- Trojan是一种基于HTTPS协议的代理工具,设计目的是为了隐蔽和高效地绕过网络审查。Trojan利用TLS加密,使其流量看起来与正常的HTTPS流量无异,从而难以被防火长城(GFW)等网络审查机制检测和拦截 --- # Snell Snell 是一种专为高速、低延迟和隐蔽性设计的代理协议,由中文开发者创建。Snell旨在提供比现有代理协议(如[Shadowsocks](/wiki/Shadowsocks)和[VMess](/wiki/VMess))更快、更稳定的网络连接,同时具备较高的隐蔽性,难以被检测和封锁。以下是Snell的详细介绍: ## Snell 的特点 * **高性能**:Snell的设计注重速度和低延迟,适合高带宽需求的应用,如高清视频流、在线游戏等。 * **隐蔽性**:Snell通过混淆和加密流量,使得其流量看起来像普通的网络流量,从而难以被检测和封锁。 * **简单配置**:Snell的配置和部署相对简单,用户可以快速上手。 * **跨平台支持**:Snell支持多种操作系统,包括Windows、macOS、Linux等,方便用户在不同设备上使用。 ## 工作原理 Snell的工作原理与其他代理协议类似,主要包括以下几个步骤: * **客户端配置**:用户在本地配置Snell客户端,指定要连接的Snell服务器的地址、端口、密钥等信息。 * **服务器配置**:在远程服务器上部署Snell服务端,设置监听端口和验证密钥等。 * **连接建立**:客户端与服务器通过加密通道建立连接,确保数据传输的安全性和隐蔽性。 * **数据传输**:一旦连接建立,客户端的所有流量都会通过Snell服务器进行转发,从而实现科学上网和隐私保护。 ## 应用场景 * **科学上网**:通过Snell,用户可以绕过网络审查和地域限制,访问被屏蔽的内容和服务。 * **隐私保护**:Snell的加密和混淆技术确保用户的网络流量不被监视和分析,提高隐私和安全性。 * **高带宽应用**:由于其高性能特点,Snell非常适合需要高带宽和低延迟的应用场景,如视频流、在线游戏等。 ## 与其他代理协议的关系 Snell与[Shadowsocks](/wiki/Shadowsocks)、[VMess](/wiki/VMess)、[Trojan](/wiki/Trojan)等代理协议类似,都是为了绕过网络审查和保护隐私而设计的工具。相比之下,Snell更注重高性能和隐蔽性,适合那些对速度和稳定性有较高要求的用户。虽然Snell目前的使用范围和知名度可能不如其他协议广泛,但其优越的性能和隐蔽性使得它成为了许多用户的选择。 ## 总结 Snell是一种高性能、高隐蔽性的代理协议,适用于需要快速、稳定网络连接的用户。其简单的配置和部署过程使得用户可以快速上手,并在多种操作系统上使用。通过Snell,用户可以实现科学上网、保护隐私以及满足高带宽应用的需求。 --- --- url: /en/wiki/Socks5.md description: >- SOCKS5 is a network proxy protocol, mainly used to transmit network data between client and server. It is the fifth version of the SOCKS protocol, providing more functions and higher security. --- # SOCKS5 SOCKS5 is a network proxy protocol, mainly used to transmit network data between client and server. It is the fifth version of the SOCKS protocol, providing more functions and higher security. The following is a detailed introduction to SOCKS5: ## Functions and features * **Proxy mechanism**: SOCKS5 establishes a connection between the client and the proxy server, and all data packets are forwarded through the proxy server, thereby hiding the client's real IP address. * **Protocol support**: SOCKS5 supports TCP (Transmission Control Protocol) and UDP (User Datagram Protocol), which allows it to handle more types of network traffic, such as real-time communication, online games, and video streaming. * **Authentication**: SOCKS5 supports multiple authentication methods, including no authentication, username/password authentication, etc., to enhance security. * **Data packet transmission**: SOCKS5 can transmit any type of data packet, not just HTTP protocol, so it is suitable for a variety of application scenarios, such as email, FTP, P2P, etc. ## Working principle * **Client request**: The client sends a connection request to the SOCKS5 proxy server, including the IP address and port number of the target server. * **Authentication**: Depending on the configuration, the proxy server may require the client to authenticate. * **Proxy connection**: The proxy server establishes a connection with the target server, after which all the client's data will be forwarded to the target server through the proxy server, and the returned data will also be forwarded to the client through the proxy server. ## Usage scenario * **Breaking firewalls**: SOCKS5 can be used to bypass firewalls and regional restrictions to access blocked websites and services. * **Privacy protection**: By hiding the client's real IP address, SOCKS5 can enhance the user's privacy and anonymity. * **Multi-protocol support**: Due to its support for TCP and UDP, SOCKS5 is suitable for a variety of network applications, including web browsing, online games, video streaming, instant messaging, etc. ## Configure SOCKS5 proxy in the browser * Open the browser's settings page. * Find the Network Settings or Proxy Settings section. * Enter the IP address and port number of the SOCKS5 proxy. * If authentication is required, enter the username and password. ## Summary SOCKS5 is a powerful and flexible proxy protocol that is suitable for a variety of network applications and scenarios. It provides features such as hiding IP addresses, supporting multiple protocols, and enhancing security, allowing users to perform network proxy operations more efficiently. In tools such as [FlClash](/), SOCKS5 proxy can be combined with other proxy protocols and rules to provide a more flexible and efficient network proxy solution. --- --- url: /wiki/Socks5.md description: SOCKS5是一种网络代理协议,主要用于在客户端和服务器之间传输网络数据。它是SOCKS协议的第五个版本,提供了更多的功能和更高的安全性 --- # SOCKS5 SOCKS5是一种网络代理协议,主要用于在客户端和服务器之间传输网络数据。它是SOCKS协议的第五个版本,提供了更多的功能和更高的安全性。以下是关于SOCKS5的详细介绍: ## 功能和特点 * **代理机制**:SOCKS5在客户端和代理服务器之间建立连接,所有的数据包通过代理服务器转发,从而隐藏了客户端的真实IP地址。 * **协议支持**:SOCKS5支持TCP(传输控制协议)和UDP(用户数据报协议),这使得它可以处理更多类型的网络流量,比如实时通信、在线游戏和视频流。 * **身份验证**:SOCKS5支持多种身份验证方法,包括无认证、用户名/密码认证等,增强了安全性。 * **数据包传输**:SOCKS5能够传输任何类型的数据包,不仅限于HTTP协议,因此适用于多种应用场景,比如电子邮件、FTP、P2P等。 ## 工作原理 * **客户端请求**:客户端向SOCKS5代理服务器发送连接请求,包括目标服务器的IP地址和端口号。 * **身份验证**:根据配置,代理服务器可能要求客户端进行身份验证。 * **代理连接**:代理服务器与目标服务器建立连接,之后客户端的所有数据都会通过代理服务器转发给目标服务器,返回的数据也会通过代理服务器转发给客户端。 ## 使用场景 * **突破防火墙**:SOCKS5可以用来绕过防火墙和地域限制,访问被屏蔽的网站和服务。 * **隐私保护**:通过隐藏客户端的真实IP地址,SOCKS5可以增强用户的隐私和匿名性。 * **多协议支持**:由于支持TCP和UDP,SOCKS5适用于多种网络应用,包括浏览网页、在线游戏、视频流、即时通讯等。 ## 在浏览器中配置SOCKS5代理 * 打开浏览器的设置页面。 * 找到网络设置或代理设置部分。 * 输入SOCKS5代理的IP地址和端口号。 * 如果需要身份验证,输入用户名和密码。 ## 总结 SOCKS5是一种功能强大、灵活性高的代理协议,适用于多种网络应用和场景。它提供了隐藏IP地址、支持多种协议和增强安全性的功能,使得用户可以更高效地进行网络代理操作。在工具如[FlClash](/)中,SOCKS5代理可以与其他代理协议和规则结合使用,提供更加灵活和高效的网络代理解决方案。 --- --- url: /en/wiki/TCP.md description: >- TCP (Transmission Control Protocol) is one of the core protocols of the Internet. It defines how to reliably transmit data in the network. TCP is a transport layer protocol located between the application layer and the network layer, and is mainly used to provide reliable, connection-oriented communication services. --- # TCP TCP (Transmission Control Protocol) is one of the core protocols of the Internet. It defines how to reliably transmit data in the network. TCP is a transport layer protocol located between the application layer and the network layer, and is mainly used to provide reliable, connection-oriented communication services. The following is a detailed introduction to TCP: ## Features of TCP * **Reliability**: TCP provides reliable data transmission services, ensuring that data packets arrive at the receiver in order and without errors. It uses acknowledgment (ACK), retransmission mechanism and checksum to achieve this. * **Connection-oriented**: TCP needs to establish a connection before communication begins. This process is called "Three-Way Handshake". After the communication is completed, "Four-Way Handshake" is required to disconnect the connection. * **Flow Control**: TCP uses flow control mechanisms to prevent the sender from sending data too fast and exceeding the processing capacity of the receiver. It achieves this through the sliding window protocol. * **Congestion Control**: TCP has a congestion control mechanism that can detect network congestion and take measures to reduce the data sending rate to avoid further congestion. Common congestion control algorithms include Slow Start, Congestion Avoidance, Fast Retransmit, and Fast Recovery. * **Ordered Delivery**: TCP ensures that data packets arrive at the receiver in the order they are sent, even if the data packets are fragmented or reordered during transmission. * **Error Detection**: TCP uses checksums to detect errors in data packets and perform error recovery to ensure data integrity. ## TCP Packet Structure A TCP packet (or TCP segment) contains the following main fields: * **Source Port**: The port number of the sender. * **Destination Port**: The port number of the receiver. * **Sequence Number**: The position of the data segment in the entire data stream. * **Acknowledgment Number**: The next expected byte sequence number, used to confirm the received data. * **Data Offset**: The length of the TCP segment header. * **Flags**: Control flags used to control the status of the data packet, including SYN, ACK, FIN, RST, PSH and URG. * **Window Size**: The receiving window size of the receiver, used for flow control. * **Checksum**: Used to detect errors in data packets. * **Urgent Pointer**: Indicates the location of urgent data. * **Options**: Optional extension field used to support new features. ## TCP connection management ### Three-way handshake (connection establishment) * **SYN**: The client sends a SYN (synchronous sequence number) packet to the server to request to establish a connection. * **SYN-ACK**: After receiving the SYN packet, the server replies with a packet with SYN and ACK (confirmation sequence number) flags, indicating that it agrees to establish a connection and confirm the client's SYN. * **ACK**: After receiving the SYN-ACK packet, the client sends an ACK packet to confirm the server's SYN-ACK, and the connection establishment is complete. ### Four waves (disconnection) * **FIN**: The client sends a FIN (end) packet to indicate that it wants to disconnect. * **ACK**: After receiving the FIN packet, the server replies with an ACK packet to confirm the client's FIN. * **FIN**: The server sends a FIN packet, indicating that the server also wants to disconnect. * **ACK**: After receiving the server's FIN packet, the client sends an ACK packet to confirm the server's FIN, and the connection disconnection is complete. ## Application scenarios TCP is widely used in network services and applications that require reliable data transmission, such as: * **Web browsing**: HTTP/HTTPS protocols are based on TCP to ensure reliable transmission of web page data. * **Email**: SMTP, IMAP and POP3 protocols are based on TCP to ensure complete transmission of email data. * **File transfer**: FTP protocol is based on TCP to provide reliable file transfer services. * **Remote login**: SSH and Telnet protocols are based on TCP to provide reliable remote control and login services. ## Advantages and disadvantages of TCP **Advantages**: * Provides reliable data transmission and ensures data integrity and order. * Supports flow control and congestion control to adapt to different network environments. * Connection-oriented, suitable for long-term and stable communication. **Disadvantages**: * Compared with the connectionless [UDP](/en/wiki/UDP), TCP has a large overhead and low efficiency. * The process of connection establishment and disconnection increases the delay, which is not suitable for applications with high real-time requirements. ## Summary TCP is one of the most important protocols in Internet communication, providing reliable, connection-oriented communication services and widely used in various network applications and services. Through flow control, congestion control and error detection mechanisms, TCP ensures reliable data transmission in complex network environments. Despite certain overhead and delay, TCP's stability and reliability make it the preferred protocol for most network applications. --- --- url: /wiki/TCP.md description: >- TCP(Transmission Control Protocol,传输控制协议)是互联网的核心协议之一,它定义了如何在网络中可靠地传输数据。TCP是传输层的协议,位于应用层和网络层之间,主要用于提供可靠的、面向连接的通信服务。 --- # TCP TCP(Transmission Control Protocol,传输控制协议)是互联网的核心协议之一,它定义了如何在网络中可靠地传输数据。TCP是传输层的协议,位于应用层和网络层之间,主要用于提供可靠的、面向连接的通信服务。以下是对TCP的详细介绍: ## TCP 的特点 * **可靠性**:TCP提供可靠的数据传输服务,确保数据包按顺序、无错误地到达接收方。它使用确认(ACK)、重传机制和校验和来实现这一点。 * **面向连接**:TCP在通信开始前需要建立一个连接,这个过程称为“三次握手”(Three-Way Handshake)。在通信结束后,需要进行“四次挥手”(Four-Way Handshake)来断开连接。 * **流量控制**:TCP使用流量控制机制来防止发送方发送数据过快,超过接收方的处理能力。它通过滑动窗口协议实现这一点。 * **拥塞控制**:TCP具有拥塞控制机制,可以检测网络拥塞并采取措施减少数据发送速率,以避免进一步的拥塞。常见的拥塞控制算法包括慢启动(Slow Start)、拥塞避免(Congestion Avoidance)、快速重传(Fast Retransmit)和快速恢复(Fast Recovery)。 * **有序传输**:TCP保证数据包按照发送顺序到达接收方,即使数据包在传输过程中被分割或重新排序。 * **错误检测**:TCP使用校验和来检测数据包中的错误,并进行错误恢复,确保数据的完整性。 ## TCP 数据包结构 TCP数据包(或TCP段)包含以下主要字段: * **源端口(Source Port)**:发送方的端口号。 * **目的端口(Destination Port)**:接收方的端口号。 * **序列号(Sequence Number)**:数据段在整个数据流中的位置。 * **确认号(Acknowledgment Number)**:下一个预期的字节序列号,用于确认接收到的数据。 * **数据偏移(Data Offset)**:TCP段头部的长度。 * **标志位(Flags)**:控制标志,用于控制数据包的状态,包括SYN、ACK、FIN、RST、PSH和URG等。 * **窗口大小(Window Size)**:接收方的接收窗口大小,用于流量控制。 * **校验和(Checksum)**:用于检测数据包中的错误。 * **紧急指针(Urgent Pointer)**:指示紧急数据的位置。 * **选项(Options)**:可选的扩展字段,用于支持新的特性。 ## TCP 连接管理 ### 三次握手(连接建立) * **SYN**:客户端向服务器发送一个SYN(同步序列编号)包,请求建立连接。 * **SYN-ACK**:服务器收到SYN包后,回复一个带有SYN和ACK(确认序列编号)标志的包,表示同意建立连接并确认客户端的SYN。 * **ACK**:客户端收到SYN-ACK包后,发送一个ACK包,确认服务器的SYN-ACK,连接建立完成。 ### 四次挥手(连接断开) * **FIN**:客户端发送一个FIN(结束)包,表示希望断开连接。 * **ACK**:服务器收到FIN包后,回复一个ACK包,确认客户端的FIN。 * **FIN**:服务器发送一个FIN包,表示服务器也希望断开连接。 * **ACK**:客户端收到服务器的FIN包后,发送一个ACK包,确认服务器的FIN,连接断开完成。 ## 应用场景 TCP广泛应用于需要可靠数据传输的网络服务和应用程序,如: * **Web浏览**:HTTP/HTTPS协议基于TCP,确保网页数据可靠传输。 * **电子邮件**:SMTP、IMAP和POP3协议基于TCP,确保邮件数据完整传输。 * **文件传输**:FTP协议基于TCP,提供可靠的文件传输服务。 * **远程登录**:SSH和Telnet协议基于TCP,提供可靠的远程控制和登录服务。 ## TCP 的优缺点 **优点**: * 提供可靠的数据传输,保证数据的完整性和顺序。 * 支持流量控制和拥塞控制,适应不同网络环境。 * 面向连接,适用于长时间、稳定的通信。 **缺点**: * 相比无连接的[UDP](/wiki/UDP),TCP的开销较大,效率较低。 * 连接建立和断开的过程增加了延迟,不适用于对实时性要求高的应用。 ## 总结 TCP是互联网通信中最重要的协议之一,提供可靠的、面向连接的通信服务,广泛应用于各种网络应用和服务。通过流量控制、拥塞控制和错误检测机制,TCP确保数据在复杂网络环境中的可靠传输。尽管有一定的开销和延迟,TCP的稳定性和可靠性使其成为大多数网络应用的首选协议。 --- --- url: /en/wiki/TProxy-TCP-UDP.md description: >- TProxy (Transparent Proxy) is a module in the Linux kernel that transparently proxies TCP and UDP traffic. The main feature of a transparent proxy is that the client is unaware that its traffic is passing through a proxy server, which makes it very useful in certain application scenarios, such as load balancing, security monitoring, and network optimization. --- # TProxy TProxy (Transparent Proxy) is a module in the Linux kernel that transparently proxies [TCP](/wiki/TCP) and [UDP](/wiki/UDP) traffic. The main feature of a transparent proxy is that the client is unaware that its traffic is passing through a proxy server, which makes it very useful in certain application scenarios, such as load balancing, security monitoring, and network optimization. Here is a detailed introduction to TProxy: ## Features of TProxy * **Transparency**: The client does not need to perform any configuration or be aware of the existence of the proxy, and the proxy server can intercept and process the traffic. * **TCP/UDP support**: TProxy supports both [TCP](/wiki/TCP) and [UDP](/wiki/UDP) traffic, and can proxy various types of network communications. * **Flexibility**: Combined with iptables, traffic redirection and processing rules can be flexibly defined. * **Non-interruption**: Since TProxy works at the network layer, the proxy process of traffic is seamless to the client and does not interrupt communication. ## Working Principle TProxy works at the network layer of the Linux kernel and transparently redirects traffic to the proxy server for processing by modifying the destination address of the IP packet. The specific steps are as follows: * **Capture traffic**: Use iptables to capture and redirect traffic to the TProxy module. * **Proxy processing**: TProxy receives the redirected traffic, processes it, and forwards it to the target server. * **Return response**: The response traffic of the target server is returned to the client through TProxy, and the client thinks it is communicating directly with the target server. ## Configuration steps The following are example steps to configure TProxy to transparently proxy TCP and UDP traffic: ### Prerequisites * Install and configure the Linux operating system. * Make sure the kernel version supports TProxy (Linux kernel 2.6.28 and above). * Install iptables and iproute2 tools. ### Kernel module loading ```bash modprobe xt_TPROXY modprobe nf_tproxy_core ``` ### Configure iptables * **Create mangle table rules**: Capture and redirect traffic to the local proxy port. ```bash iptables -t mangle -N DIVERT iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT iptables -t mangle -A PREROUTING -p udp -m socket -j DIVERT iptables -t mangle -A DIVERT -j MARK --set-mark 1 iptables -t mangle -A DIVERT -j ACCEPT ``` * **Add PREROUTING rules**: Redirect traffic to TProxy. ```bash iptables -t mangle -A PREROUTING -p tcp -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 iptables -t mangle -A PREROUTING -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 ``` ### Configure ip rule and ip route * **Set ip rule**: Set routing rules for marked traffic. ```bash ip rule add fwmark 1 lookup 100 ``` * **Set routing table**: Configure routing table 100 to redirect traffic to local. ```bash ip route add local 0.0.0.0/0 dev lo table 100 ``` ## Example: Use TProxy to proxy HTTP traffic Suppose you have an HTTP proxy server running on port 12345 locally, you can use the following configuration to transparently proxy HTTP traffic: ### Configure iptables ```bash iptables -t mangle -A PREROUTING -p tcp --dport 80 -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 iptables -t mangle -A PREROUTING -p tcp --dport 443 -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 ``` ## Application scenarios * **Load balancing**: TProxy can transparently distribute traffic to multiple servers to achieve load balancing. * **Security Monitoring**: Transparent proxy can monitor and filter network traffic, detect and block malicious behavior. * **Network Optimization**: Cache and optimize traffic through proxy servers to improve network performance. * **Access Control**: Perform access control and permission management based on traffic characteristics. ## Advantages and Disadvantages **Advantages**: * Transparent to the client, no need to modify the client configuration. * Supports TCP and UDP traffic, with a wide range of applications. * Combined with iptables, flexible rule configuration. **Disadvantages**: * Requires high network configuration and maintenance skills. * Increases the load on the proxy server and has high hardware requirements. ## Summary TProxy is a powerful transparent proxy tool suitable for various scenarios that require transparent proxy and processing of network traffic. By combining with iptables and iproute2, TProxy can flexibly capture and redirect TCP and UDP traffic to achieve functions such as load balancing, security monitoring and network optimization. Despite the complex configuration, its powerful functions and flexibility make it an important tool for network administrators and developers. --- --- url: /wiki/TProxy-TCP-UDP.md description: >- TProxy(Transparent Proxy,透明代理)是Linux内核中的一个模块,用于透明地代理TCP和UDP流量。透明代理的主要特点是,客户端并不知道其流量正在通过代理服务器,这使得它在某些应用场景中非常有用,如负载均衡、安全监控和网络优化。 --- # TProxy TProxy(Transparent Proxy,透明代理)是Linux内核中的一个模块,用于透明地代理[TCP](/wiki/TCP)和[UDP](/wiki/UDP)流量。透明代理的主要特点是,客户端并不知道其流量正在通过代理服务器,这使得它在某些应用场景中非常有用,如负载均衡、安全监控和网络优化。以下是对TProxy的详细介绍: ## TProxy 的特点 * **透明性**:客户端无需进行任何配置或意识到代理的存在,代理服务器可以截获并处理流量。 * **TCP/UDP支持**:TProxy同时支持[TCP](/wiki/TCP)和[UDP](/wiki/UDP)流量,可以代理各种类型的网络通信。 * **灵活性**:与iptables结合使用,可以灵活地定义流量重定向和处理规则。 * **无中断**:由于TProxy在网络层工作,流量的代理过程对客户端是无缝的,不会中断通信。 ## 工作原理 TProxy工作在Linux内核的网络层,通过修改IP包的目的地址,将流量透明地重定向到代理服务器进行处理。具体步骤如下: * **捕获流量**:使用iptables将流量捕获并重定向到TProxy模块。 * **代理处理**:TProxy接收到重定向的流量,对其进行处理后转发到目标服务器。 * **返回响应**:目标服务器的响应流量通过TProxy返回给客户端,客户端认为其直接与目标服务器通信。 ## 配置步骤 以下是配置TProxy以透明代理TCP和UDP流量的示例步骤: ### 前提条件 * 安装并配置好Linux操作系统。 * 确保内核版本支持TProxy(Linux内核2.6.28及以上)。 * 安装iptables和iproute2工具。 ### 内核模块加载 ```bash modprobe xt_TPROXY modprobe nf_tproxy_core ``` ### 配置iptables * **创建mangle表规则**: 捕获并重定向流量到本地的代理端口。 ```bash iptables -t mangle -N DIVERT iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT iptables -t mangle -A PREROUTING -p udp -m socket -j DIVERT iptables -t mangle -A DIVERT -j MARK --set-mark 1 iptables -t mangle -A DIVERT -j ACCEPT ``` * **添加PREROUTING规则**: 将流量重定向到TProxy。 ```bash iptables -t mangle -A PREROUTING -p tcp -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 iptables -t mangle -A PREROUTING -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 ``` ### 配置ip rule和ip route * **设置ip rule**: 为标记流量设置路由规则。 ```bash ip rule add fwmark 1 lookup 100 ``` * **设置路由表**: 配置路由表100,将流量重定向到本地。 ```bash ip route add local 0.0.0.0/0 dev lo table 100 ``` ## 示例:使用TProxy代理HTTP流量 假设你有一个运行在本地12345端口的HTTP代理服务器,可以使用以下配置来透明代理HTTP流量: ### 配置iptables ```bash iptables -t mangle -A PREROUTING -p tcp --dport 80 -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 iptables -t mangle -A PREROUTING -p tcp --dport 443 -j TPROXY --tproxy-mark 0x1/0x1 --on-port 12345 ``` ## 应用场景 * **负载均衡**:TProxy可以将流量透明地分发到多个服务器,实现负载均衡。 * **安全监控**:透明代理可以监控和过滤网络流量,检测和阻止恶意行为。 * **网络优化**:通过代理服务器缓存和优化流量,提升网络性能。 * **访问控制**:基于流量特征进行访问控制和权限管理。 ## 优缺点 **优点**: * 对客户端透明,无需修改客户端配置。 * 支持TCP和UDP流量,适用范围广。 * 与iptables结合,规则配置灵活。 **缺点**: * 需要较高的网络配置和维护技巧。 * 增加了代理服务器的负载,对硬件要求较高。 ## 总结 TProxy是一种强大的透明代理工具,适用于需要透明代理和处理网络流量的各种场景。通过与iptables和iproute2结合使用,TProxy可以灵活地捕获和重定向TCP和UDP流量,实现负载均衡、安全监控和网络优化等功能。尽管配置复杂,但其强大的功能和灵活性使其成为网络管理员和开发者的重要工具。 --- --- url: /en/wiki/Trojan.md description: >- Trojan is a proxy tool based on the HTTPS protocol, designed to covertly and efficiently bypass network censorship. Trojan uses TLS encryption to make its traffic look the same as normal HTTPS traffic, making it difficult to detect and intercept by network censorship mechanisms such as the Great Firewall (GFW) --- # Trojan Trojan is a proxy tool based on the HTTPS protocol, designed to covertly and efficiently bypass network censorship. Trojan uses TLS encryption to make its traffic look the same as normal HTTPS traffic, making it difficult to detect and intercept by network censorship mechanisms such as the Great Firewall (GFW). ## Features of Trojan * **HTTPS protocol**: Trojan uses HTTPS (HTTP based on TLS) for data transmission, so its traffic is difficult to distinguish from ordinary HTTPS traffic, effectively evading traffic analysis and detection. * **Encryption**: Due to the use of TLS, Trojan's traffic is automatically protected by strong encryption to ensure data security and privacy. * **High performance**: Trojan is simple and efficient in design, with excellent performance. It is suitable for various network environments and provides stable and fast proxy services. * **Multi-platform support**: Trojan supports multiple operating systems such as Windows, macOS, Linux, and has corresponding implementations on both the client and the server. * **Easy to deploy**: The deployment of Trojan servers is relatively simple, and is usually used in conjunction with web servers (such as Nginx) to further enhance traffic concealment. ## How Trojan works * **Client configuration**: The user configures the Trojan client locally and specifies information such as the server address, port, and password. * **Server configuration**: Deploy the Trojan server on the remote server, configure the TLS certificate and key, set the listening port and verification password, etc. * **Connection establishment**: The client and the server establish a secure connection through TLS, and all transmitted data is encrypted. * **Data transmission**: Once the connection is established, all client-requested data is forwarded to the target address through the Trojan server, and the response data is also returned to the client through the Trojan server. ## Application scenarios * **Bypassing network censorship**: Since its traffic is disguised as ordinary HTTPS traffic, Trojan can effectively bypass various network censorship and blockades. * **Privacy protection**: Through TLS encryption, Trojan ensures the privacy and security of user data during transmission. * **Efficient proxy**: Suitable for network proxy needs that require high performance and stability, such as browsing the web, streaming, online games, etc. ## Relationship with other proxy tools Trojan is similar to proxy tools such as [Shadowsocks](/en/wiki/Shadowsocks) and [VMess](/en/wiki/VMess), which are tools used for scientific Internet access and bypassing network censorship. Unlike these tools, Trojan pays more attention to the concealment of traffic and its similarity to regular HTTPS traffic, so it performs better in some strict network censorship environments. --- --- url: /wiki/Trojan.md description: >- Trojan是一种基于HTTPS协议的代理工具,设计目的是为了隐蔽和高效地绕过网络审查。Trojan利用TLS加密,使其流量看起来与正常的HTTPS流量无异,从而难以被防火长城(GFW)等网络审查机制检测和拦截 --- # Trojan Trojan是一种基于HTTPS协议的代理工具,设计目的是为了隐蔽和高效地绕过网络审查。Trojan利用TLS加密,使其流量看起来与正常的HTTPS流量无异,从而难以被防火长城(GFW)等网络审查机制检测和拦截。 ## Trojan 的特点 * **HTTPS协议**:Trojan使用HTTPS(基于TLS的HTTP)进行数据传输,因此其流量与普通的HTTPS流量难以区分,有效规避流量分析和检测。 * **加密**:由于使用了TLS,Trojan的流量自动得到强加密保护,确保数据的安全性和隐私性。 * **高性能**:Trojan设计简洁高效,性能优异,适用于各种网络环境,提供稳定和快速的代理服务。 * **多平台支持**:Trojan支持Windows、macOS、Linux等多种操作系统,客户端和服务器均有相应的实现。 * **易于部署**:Trojan服务器的部署相对简单,通常与Web服务器(如Nginx)结合使用,以进一步增强流量隐蔽性。 ## Trojan 的工作原理 * **客户端配置**:用户在本地配置Trojan客户端,指定服务器地址、端口、密码等信息。 * **服务器配置**:在远程服务器上部署Trojan服务端,配置TLS证书和密钥,设置监听端口和验证密码等。 * **连接建立**:客户端与服务器通过TLS建立安全连接,传输的数据全部经过加密处理。 * **数据传输**:一旦连接建立,所有客户端请求的数据通过Trojan服务器转发到目标地址,响应数据同样通过Trojan服务器返回客户端。 ## 应用场景 * **绕过网络审查**:由于其流量伪装为普通HTTPS流量,Trojan可以有效绕过各种网络审查和封锁。 * **隐私保护**:通过TLS加密,Trojan确保用户数据在传输过程中的隐私和安全。 * **高效代理**:适用于需要高性能和稳定性的网络代理需求,如浏览网页、流媒体、在线游戏等。 ## 与其他代理工具的关系 Trojan与[Shadowsocks](/wiki/Shadowsocks)、[VMess](/wiki/VMess)等代理工具类似,都是用于科学上网和绕过网络审查的工具。与这些工具不同的是,Trojan更注重流量的隐蔽性和与常规HTTPS流量的相似性,从而在一些严格的网络审查环境中表现更为出色。 --- --- url: /en/wiki/UDP.md description: >- UDP (User Datagram Protocol) is a simple, connectionless communication protocol at the transport layer. Compared with TCP, UDP is lighter and has lower latency, but does not provide reliable transmission services. UDP is suitable for application scenarios that require high data transmission speed and efficiency but low reliability. --- # UDP UDP (User Datagram Protocol) is a simple, connectionless communication protocol at the transport layer. Compared with [TCP](/en/wiki/TCP), UDP is lighter and has lower latency, but does not provide reliable transmission services. UDP is suitable for application scenarios that require high data transmission speed and efficiency but low reliability. ## Features of UDP * **Connectionless**: UDP does not need to establish a connection to send datagrams, reducing communication overhead and latency. * **Unreliable transmission**: UDP does not guarantee the order and integrity of data packets, does not provide a retransmission mechanism, and data packets may be lost, duplicated, or arrive out of order. * **Lightweight**: The UDP header is only 8 bytes. Compared with the TCP header, UDP has less overhead and is suitable for applications with high real-time requirements. * **Support broadcast and multicast**: UDP supports broadcast (Broadcast) and multicast (Multicast), and can send data to multiple targets at the same time. ## UDP packet structure The structure of the UDP packet is very simple and consists of the following fields: * **Source Port (Source Port, 16 bits)**: The port number of the sender. * **Destination Port (Destination Port, 16 bits)**: The port number of the receiver. * **Length (Length, 16 bits)**: The total length of the UDP header and data part. * **Checksum (Checksum, 16 bits)**: The checksum used for error detection. ```plaintext +-------------------+-------------------+ | Source Port | Destination Port | +-------------------+-------------------+ | Length | Checksum | +-------------------+-------------------+ | Data (variable) | +---------------------------------------+ ``` ## Usage scenarios UDP is suitable for application scenarios that have high requirements for real-time performance but low requirements for reliability, including: * **Real-time audio and video transmission**: such as VoIP, video conferencing, and online live broadcasting, which require low latency and high efficiency, and can accept even partial packet loss. * **Online games**: such as multiplayer online games, which require fast-response communication and allow occasional data loss. * **DNS query**: The Domain Name System (DNS) uses UDP for querying and quickly responding to user requests. * **Internet of Things (IoT) device communication**: Many IoT devices use UDP for lightweight, low-latency data transmission. ## Advantages and Disadvantages **Advantages**: * Low latency: Due to the lack of connection and simple header, UDP transmission latency is low. * Low overhead: The UDP header is only 8 bytes, and the communication overhead is low. * Supports broadcast and multicast: Suitable for applications that need to send data to multiple targets at the same time. **Disadvantages**: * Unreliable: There is no retransmission and confirmation mechanism, and data packets may be lost, duplicated or out of order. * No flow control: There is no flow control mechanism, which can easily cause network congestion. ## Example: UDP communication The following is a simple UDP client and server example, implemented in Python. ### Server code ```python import socket # Create UDP socket server_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) server_socket.bind(('localhost', 12345)) print("UDP server listening on port 12345...") while True: data, addr = server_socket.recvfrom(1024) # Receive data print(f"Received data from {addr}: {data.decode()}") response = f"Received: {data.decode()}" server_socket.sendto(response.encode(), addr) # Send response ``` ### Client code ```python import socket # Create UDP socket client_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) server_address = ('localhost', 12345) message = "Hello, UDP Server!" client_socket.sendto(message.encode(), server_address) # Send data data, server = client_socket.recvfrom(1024) # Receive response print(f"Received response from server: {data.decode()}") client_socket.close() ``` ## Summary UDP is a simple, fast, low-latency transport layer protocol suitable for applications with high real-time requirements, such as audio and video transmission, online games, and DNS queries. Although UDP does not provide reliable transmission services, its lightweight and support for broadcast and multicast make it very useful in many applications. Through reasonable selection and configuration, UDP can provide efficient network communication services in specific scenarios. --- --- url: /wiki/UDP.md description: >- UDP(User Datagram Protocol,用户数据报协议)是传输层的一种简单、无连接的通信协议,与TCP相比,UDP更轻量、低延迟,但不提供可靠的传输服务。UDP适用于对数据传输速度和效率要求较高、对可靠性要求较低的应用场景。 --- # UDP UDP(User Datagram Protocol,用户数据报协议)是传输层的一种简单、无连接的通信协议,与[TCP](/wiki/TCP)相比,UDP更轻量、低延迟,但不提供可靠的传输服务。UDP适用于对数据传输速度和效率要求较高、对可靠性要求较低的应用场景。 ## UDP 的特点 * **无连接**:UDP不需要建立连接即可发送数据报文(Datagram),减少了通信开销和延迟。 * **不可靠传输**:UDP不保证数据包的顺序和完整性,不提供重传机制,数据包可能丢失、重复或乱序到达。 * **轻量级**:UDP头部只有8个字节,相比TCP的头部,UDP开销更小,适合实时性要求高的应用。 * **支持广播和多播**:UDP支持广播(Broadcast)和多播(Multicast),可以同时向多个目标发送数据。 ## UDP 数据包结构 UDP数据包的结构非常简单,由以下几个字段组成: * **源端口(Source Port,16位)**:发送方的端口号。 * **目的端口(Destination Port,16位)**:接收方的端口号。 * **长度(Length,16位)**:UDP头部和数据部分的总长度。 * **校验和(Checksum,16位)**:用于错误检测的校验和。 ```plaintext +-------------------+-------------------+ | Source Port | Destination Port | +-------------------+-------------------+ | Length | Checksum | +-------------------+-------------------+ | Data (variable) | +---------------------------------------+ ``` ## 使用场景 UDP适用于对实时性要求高但对可靠性要求不高的应用场景,包括: * **实时音视频传输**:如VoIP、视频会议和在线直播,要求低延迟和高效率,即使有部分数据包丢失也能接受。 * **在线游戏**:如多人在线游戏,需要快速响应的通信,允许偶尔的数据丢失。 * **DNS查询**:域名系统(DNS)使用UDP进行查询,快速响应用户请求。 * **物联网(IoT)设备通信**:许多物联网设备使用UDP进行轻量级、低延迟的数据传输。 ## 优缺点 **优点**: * 低延迟:由于无连接和简单头部,UDP传输延迟较低。 * 开销小:UDP头部只有8个字节,通信开销小。 * 支持广播和多播:适合需要同时向多个目标发送数据的应用。 **缺点**: * 不可靠:没有重传和确认机制,数据包可能丢失、重复或乱序。 * 无流量控制:不具备流量控制机制,容易导致网络拥塞。 ## 示例:UDP通信 以下是一个简单的UDP客户端和服务器示例,使用Python实现。 ### 服务器代码 ```python import socket # 创建UDP socket server_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) server_socket.bind(('localhost', 12345)) print("UDP服务器在端口12345监听...") while True: data, addr = server_socket.recvfrom(1024) # 接收数据 print(f"收到来自{addr}的数据:{data.decode()}") response = f"已接收:{data.decode()}" server_socket.sendto(response.encode(), addr) # 发送响应 ``` ### 客户端代码 ```python import socket # 创建UDP socket client_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) server_address = ('localhost', 12345) message = "Hello, UDP Server!" client_socket.sendto(message.encode(), server_address) # 发送数据 data, server = client_socket.recvfrom(1024) # 接收响应 print(f"从服务器收到响应:{data.decode()}") client_socket.close() ``` ## 总结 UDP是一种简单、快速、低延迟的传输层协议,适用于实时性要求高的应用,如音视频传输、在线游戏和DNS查询。虽然UDP不提供可靠的传输服务,但其轻量级和支持广播、多播的特点使其在许多应用中非常有用。通过合理选择和配置,UDP可以在特定场景下提供高效的网络通信服务。 --- --- url: /en/wiki/VMess.md description: >- VMess is an encrypted transmission protocol used in the V2Ray project to achieve secure communication between clients and servers. V2Ray is a powerful network proxy tool that supports multiple protocols and advanced features, and VMess is one of the most commonly used protocols. --- # VMess VMess is an encrypted transmission protocol used in the V2Ray project to achieve secure communication between clients and servers. V2Ray is a powerful network proxy tool that supports multiple protocols and advanced features, and VMess is one of the most commonly used protocols. ## Features of VMess * **Encryption**: The VMess protocol uses multiple encryption methods to protect transmitted data and prevent data from being monitored or tampered with. Common encryption methods include AES, ChaCha20, etc. * **Authentication**: VMess includes a two-way authentication mechanism for clients and servers, ensuring that only authenticated clients can connect to the server, thereby preventing unauthorized access. * **Obfuscation**: To prevent traffic from being detected and identified, VMess supports a variety of traffic obfuscation methods, making its traffic look like ordinary HTTPS or other types of traffic. * **Multi-protocol support**: VMess can be used in combination with a variety of transport protocols, including [TCP](/en/wiki/TCP), mKCP, WebSocket, HTTP/2, QUIC, etc., which enhances flexibility and concealment. ## How VMess works * **Client configuration**: The user configures the V2Ray client locally and specifies the address, port, UUID (user ID), encryption method and other information of the VMess server to be connected. * **Server configuration**: Configure V2Ray on the remote server and set the VMess protocol and related parameters, including the client UUID allowed to connect. * **Connection establishment**: The client initiates a connection request, and the server establishes an encrypted channel by verifying the client's UUID and other information. * **Data transmission**: Once the connection is established, all data transmission between the client and the server is carried out through an encrypted channel to ensure security and privacy. --- --- url: /wiki/VMess.md description: >- VMess是V2Ray项目中使用的一种加密传输协议,用于实现客户端和服务器之间的安全通信。V2Ray是一个强大的网络代理工具,支持多种协议和高级功能,而VMess是其中最常用的协议之一。 --- # VMess VMess是V2Ray项目中使用的一种加密传输协议,用于实现客户端和服务器之间的安全通信。V2Ray是一个强大的网络代理工具,支持多种协议和高级功能,而VMess是其中最常用的协议之一。 ## VMess 的特点 * **加密**:VMess协议使用多种加密方法保护传输数据,防止数据被监听或篡改。常用的加密方式包括AES、ChaCha20等。 * **验证**:VMess包含客户端和服务器的双向验证机制,确保只有经过认证的客户端才能连接到服务器,从而防止未授权访问。 * **混淆**:为了防止流量被检测和识别,VMess支持多种流量混淆方式,使得其流量看起来像普通的HTTPS或其他类型流量。 * **多协议支持**:VMess可以与多种传输协议结合使用,包括[TCP](/wiki/TCP)、mKCP、WebSocket、HTTP/2、QUIC等,增强了灵活性和隐蔽性。 ## VMess 的工作原理 * **客户端配置**:用户在本地配置V2Ray客户端,指定要连接的VMess服务器的地址、端口、UUID(用户标识)、加密方式等信息。 * **服务器配置**:在远程服务器上配置V2Ray,设置VMess协议及相关参数,包括允许连接的客户端UUID。 * **连接建立**:客户端发起连接请求,服务器通过验证客户端的UUID等信息,建立加密通道。 * **数据传输**:一旦连接建立,客户端和服务器之间的所有数据传输都通过加密通道进行,确保安全和隐私。 --- --- url: /en/wiki/Wireguard.md description: >- WireGuard is a modern virtual private network (VPN) protocol designed to be simple, efficient, and secure. It was developed by Jason A. Donenfeld to provide better performance and stronger security than traditional VPN protocols such as OpenVPN and IPsec. --- # WireGuard WireGuard is a modern virtual private network (VPN) protocol designed to be simple, efficient, and secure. It was developed by Jason A. Donenfeld to provide better performance and stronger security than traditional VPN protocols such as OpenVPN and IPsec. Here is a detailed introduction to WireGuard: ## Features of WireGuard * **High performance**: WireGuard's code base is very lean, with only a few thousand lines of code, compared to OpenVPN and IPsec, which have tens of thousands of lines of code. The lean code base improves performance, allowing WireGuard to run on low-resource devices and provide low latency and high throughput. * **Security**: WireGuard uses modern encryption algorithms such as ChaCha20, Poly1305, Curve25519, etc. to ensure the security and integrity of data transmission. Its design principle is "default security", without complex configuration options, reducing the security risks caused by configuration errors. * **Easy configuration**: WireGuard is very simple to configure, using key pairs for authentication and encryption. Each client and server has a unique private key and public key pair, and the configuration file is concise and clear. * **Cross-platform support**: WireGuard supports a variety of operating systems, including Linux, Windows, macOS, iOS, Android, etc. Users can easily deploy and use WireGuard on different devices. * **Fast connection**: WireGuard uses a static virtual IP address, the connection speed is very fast, and there is no need to establish a complex handshake protocol, thereby reducing the connection time. ## Working principle * **Key pair**: Each client and server has a unique private key and public key pair, the public key is used to identify the other party, and the private key is used to encrypt communication. * **Static IP address**: Each client and server is assigned a static virtual IP address, which is used within the VPN network. * **Encrypted communication**: All communications between the client and the server are encrypted using a strong encryption algorithm to ensure data security and privacy. * **Routing**: The client accesses the Internet or intranet resources through the virtual IP address of the WireGuard server, and the server is responsible for forwarding traffic. ## Application scenarios * **Remote access**: With WireGuard, users can securely access devices in the company's internal network or at home, which is suitable for remote office and remote management. * **Privacy protection**: When using WireGuard to connect to public Wi-Fi, all user traffic is transmitted through an encrypted channel to prevent data from being stolen and monitored. * **Bypassing geographical restrictions**: By connecting to WireGuard servers located in different countries, users can bypass geographical restrictions and access blocked content and services. * **Intranet interconnection**: Enterprises can use WireGuard to securely connect networks in different offices to form a unified intranet. ## Comparison with other VPN protocols * **Performance**: WireGuard has higher performance, lower latency, and greater throughput than OpenVPN and IPsec, making it suitable for high-bandwidth applications. * **Security**: WireGuard uses modern encryption algorithms and default security configurations, reducing the risk of configuration errors, while OpenVPN and IPsec configurations are relatively complex. * **Simplicity**: WireGuard configuration is simple and clear, easy to deploy and maintain, while OpenVPN and IPsec configuration files are more complex and have higher maintenance costs. ## Summary WireGuard is an efficient, secure, and simple VPN protocol that is suitable for a variety of network environments and application scenarios. Its high performance, strong security, and ease of use make it an excellent choice for modern VPN solutions. With WireGuard, users can achieve secure remote access, protect privacy, bypass geographical restrictions, and interconnect within the enterprise intranet. --- --- url: /wiki/Wireguard.md description: >- WireGuard是一种现代化的虚拟专用网络(VPN)协议,设计简单、高效且安全。它由Jason A. Donenfeld开发,旨在提供比传统VPN协议(如OpenVPN和IPsec)更好的性能和更强的安全性。 --- # WireGuard WireGuard是一种现代化的虚拟专用网络(VPN)协议,设计简单、高效且安全。它由Jason A. Donenfeld开发,旨在提供比传统VPN协议(如OpenVPN和IPsec)更好的性能和更强的安全性。以下是WireGuard的详细介绍: ## WireGuard的特点 * **高性能**:WireGuard的代码库非常精简,只有几千行代码,相比之下,OpenVPN和IPsec有成千上万行代码。精简的代码库提高了性能,使得WireGuard可以在低资源设备上运行,并提供低延迟和高吞吐量。 * **安全性**:WireGuard采用现代化的加密算法,如ChaCha20、Poly1305、Curve25519等,确保数据传输的安全性和完整性。其设计原则是“默认安全”,没有复杂的配置选项,降低了配置错误带来的安全风险。 * **简便配置**:WireGuard的配置非常简单,使用密钥对进行身份验证和加密。每个客户端和服务器都有一个唯一的私钥和公钥对,配置文件简洁明了。 * **跨平台支持**:WireGuard支持多种操作系统,包括Linux、Windows、macOS、iOS、Android等,用户可以在不同设备上轻松部署和使用WireGuard。 * **快速连接**:WireGuard采用静态的虚拟IP地址,连接速度非常快,不需要建立复杂的握手协议,从而减少了连接时间。 ## 工作原理 * **密钥对**:每个客户端和服务器都有一个唯一的私钥和公钥对,公钥用于标识对方,私钥用于加密通信。 * **静态IP地址**:每个客户端和服务器分配一个静态的虚拟IP地址,这些地址在VPN网络内使用。 * **加密通信**:客户端和服务器之间的所有通信都使用强加密算法进行加密,确保数据的安全性和隐私性。 * **路由**:客户端通过WireGuard服务器的虚拟IP地址访问互联网或内网资源,服务器负责转发流量。 ## 应用场景 * **远程访问**:通过WireGuard,用户可以安全地访问公司内部网络或个人家中的设备,适用于远程办公和远程管理。 * **保护隐私**:使用WireGuard连接公共Wi-Fi时,用户的所有流量都通过加密通道传输,防止数据被窃取和监视。 * **绕过地域限制**:通过连接到位于不同国家的WireGuard服务器,用户可以绕过地域限制,访问被屏蔽的内容和服务。 * **内网互联**:企业可以使用WireGuard将不同办公室的网络安全地连接起来,形成一个统一的内网。 ## 与其他VPN协议的比较 * **性能**:WireGuard比OpenVPN和IPsec性能更高,延迟更低,吞吐量更大,适合高带宽应用。 * **安全性**:WireGuard使用现代加密算法,默认安全配置,降低了配置错误的风险,而OpenVPN和IPsec的配置相对复杂。 * **简便性**:WireGuard配置简单明了,易于部署和维护,而OpenVPN和IPsec的配置文件较为复杂,维护成本较高。 ## 总结 WireGuard是一种高效、安全、简便的VPN协议,适用于各种网络环境和应用场景。其高性能、强安全性和易用性使得它成为现代VPN解决方案的优秀选择。通过WireGuard,用户可以实现安全的远程访问、保护隐私、绕过地域限制以及企业内网互联。