- {
- "log": {
- "access": "/var/log/xray/access.log",
- "error": "/var/log/xray/error.log",
- "loglevel": "warning"
- },
- "routing": {
- "domainStrategy": "IPIfNonMatch",
- "rules": [
- {
- "type": "field",
- "ip": [
- "geoip:cn"
- ],
- "outboundTag": "block"
- }
- ]
- },
- "inbounds": [
- {
- "listen": "127.0.0.1",
- "port": 9999,
- "protocol": "vless",
- "settings": {
- "clients": [
- {
- "id": "",
- "flow": "xtls-rprx-vision"
- }
- ],
- "decryption": "none"
- },
- "streamSettings": {
- "network": "tcp",
- "security": "tls",
- "tlsSettings": {
- "certificates": [
- {
- "certificateFile": "/etc/letsencrypt/live/fullchain.pem",
- "keyFile": "/etc/letsencrypt/live/privkey.pem"
- }
- ]
- }
- },
- "sniffing": {
- "enabled": true,
- "destOverride": [
- "http",
- "tls"
- ]
- }
- }
- ],
- "outbounds": [
- {
- "protocol": "freedom",
- "tag": "direct"
- },
- {
- "protocol": "blackhole",
- "tag": "block"
- }
- ]
- }
复制代码
nginx 配置
- server {
- listen 80;
- server_name 域名;
- # return 301 https://域名$request_uri;
- #日志
- access_log /var/log/nginx/域名.access.log;
- error_log /var/log/nginx/域名.error.log error;
- }
- server {
- listen 443 ssl;
- server_name 域名;
- #证书地址
- ssl_certificate /etc/letsencrypt/live/fullchain.pem;
- ssl_certificate_key /etc/letsencrypt/live/privkey.pem;
- ##SSL认证
- include global/letsencrypt.conf;
- ssl_protocols TLSv1.2 TLSv1.3;
- ssl_ciphers 'TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
- #ssl_early_data on;
- #告诉服务器重写客户端可能报告为自己的首选项
- ssl_prefer_server_ciphers off;
- #指定曲线类型
- ssl_ecdh_curve secp384r1;
- ssl_session_cache shared:SSL:10m;
- ssl_session_timeout 10m;
- ssl_stapling on;
- ssl_stapling_verify on;
- resolver 8.8.4.4 1.1.1.1 1.0.0.1 8.8.8.8;
- location /
- {
- proxy_pass http://127.0.0.1:9999;
- proxy_redirect off;
- proxy_http_version 1.1;
- proxy_set_header Upgrade $http_upgrade;
- proxy_set_header Connection "upgrade";
- proxy_set_header Host $host;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- }
- }
复制代码
怎么不能用
客户端如何配置是不是客户端的问题 |