开个玩笑,救星算不上。基于tinyfecvpn与udp2raw的思路搞的一个轻量级内网隧道项目。
特征是建立一个内网隧道,上层使用tcp伪装底下是udp发包并且维持心跳。
AI脸滚键盘键盘出来的,和参考项目比的话也就是用GO写的并且对渣机的支持比较好吧。
怎么说呢,能用能跑。因为跑的是TCP,没有遭运营商的UDP限制策略那么严重。
项目地址
https://github.com/openbmx/lightweight-tunnel
Lightweight Tunnel (轻量级内网隧道)
一个使用 Go 语言开发的轻量级内网隧道工具,支持 TCP 伪装和 FEC 纠错功能。适用于在两个低配置服务器之间建立安全的内网连接。
A lightweight intranet tunnel tool developed in Go, supporting TCP disguise and FEC (Forward Error Correction). Suitable for establishing secure intranet connections between two low-spec servers.
Features (特性)
- 🚀 轻量级设计 - 占用资源少,适合低配置服务器
- 🔒 TCP 伪装 - UDP 数据包伪装成 TCP 连接,绕过防火墙限制
- 🛡️ FEC 纠错 - Forward Error Correction 提供数据包丢失恢复能力
- 🌐 TUN 设备 - 基于 TUN 设备的第三层网络隧道
- ⚡ 高性能 - 使用 Go 协程实现并发处理
- 🎯 简单易用 - 命令行参数或配置文件两种配置方式
Quick Start (快速开始)
Prerequisites (前置要求)
- Linux 系统 (需要 TUN 设备支持)
- Root 权限 (用于创建和配置 TUN 设备)
- Go 1.19+ (仅编译时需要)
Installation (安装)
# Clone the repository
git clone https://github.com/openbmx/lightweight-tunnel.git
cd lightweight-tunnel
# Build
go build -o lightweight-tunnel ./cmd/lightweight-tunnel
# Or install directly
go install ./cmd/lightweight-tunnel
Usage (使用方法)
Server Side (服务端)
# Run as server with default settings
sudo ./lightweight-tunnel -m server -l 0.0.0.0:9000 -t 10.0.0.1/24
# Or use config file
sudo ./lightweight-tunnel -c server.json
Client Side (客户端)
# Run as client
sudo ./lightweight-tunnel -m client -r SERVER_IP:9000 -t 10.0.0.2/24
# Or use config file
sudo ./lightweight-tunnel -c client.json
Configuration File (配置文件)
Generate example configuration files:
./lightweight-tunnel -g config.json
This creates config.json (server) and config.json.client (client).
Example server configuration:
{
"mode": "server",
"local_addr": "0.0.0.0:9000",
"remote_addr": "",
"tunnel_addr": "10.0.0.1/24",
"mtu": 1400,
"fec_data": 10,
"fec_parity": 3,
"timeout": 30,
"keepalive": 10
}
Example client configuration:
{
"mode": "client",
"local_addr": "0.0.0.0:9000",
"remote_addr": "SERVER_IP:9000",
"tunnel_addr": "10.0.0.2/24",
"mtu": 1400,
"fec_data": 10,
"fec_parity": 3,
"timeout": 30,
"keepalive": 10
}
Command Line Options (命令行选项)
-c string
Configuration file path
-m string
Mode: server or client (default "server")
-l string
Local address to listen on (default "0.0.0.0:9000")
-r string
Remote address to connect to (client mode)
-t string
Tunnel IP address and netmask (default "10.0.0.1/24")
-mtu int
MTU size (default 1400)
-fec-data int
FEC data shards (default 10)
-fec-parity int
FEC parity shards (default 3)
-v Show version
-g string
Generate example config file
Architecture (架构)
┌─────────────┐ TCP (disguised) ┌─────────────┐
│ Server │ ◄─────────────────────────────► │ Client │
│ (10.0.0.1) │ with FEC error correction │ (10.0.0.2) │
└──────┬──────┘ └──────┬──────┘
│ │
│ TUN Device TUN Device │
│ │
┌────▼────┐ ┌────▼────┐
│ App/Svc │ │ App/Svc │
└─────────┘ └─────────┘
How It Works (工作原理)
- TUN Device: Creates a virtual network interface for Layer 3 (IP) traffic
- TCP Disguise: Wraps UDP-like packets in TCP connections to bypass firewalls
- FEC: Adds redundant data shards for packet loss recovery
- Keepalive: Maintains connection with periodic heartbeat packets
Testing (测试)
After establishing the tunnel, you can test connectivity:
# On server side, ping client
ping 10.0.0.2
# On client side, ping server
ping 10.0.0.1
# Test with iperf
# Server: iperf -s
# Client: iperf -c 10.0.0.1
Performance Tuning (性能调优)
- MTU: Adjust based on your network (default: 1400)
- FEC Shards: More parity shards = better loss recovery but more overhead
- Keepalive: Shorter interval = faster detection of disconnection
Limitations (限制)
- Currently supports only IPv4
- Single client per server instance
- Requires root/admin privileges for TUN device
- Linux only (uses Linux TUN/TAP interfaces)
References (参考项目)
- udp2raw - UDP to TCP converter
- tinyfecvpn - VPN with FEC
License
MIT License
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
这么说移动qos有救了?具体怎么救?希望有大佬来指路
落地是服务端入口是客户端吗?
@1083819963 #2 服务端和客户端并不绝对 我这里做区分只是方便理解 原则上是双端谁的配置高谁做服务端 因为隧道建立后 核心就一个 内网互通了 尤其是适合哪些有nat限制的优化线路机器 比如说酷雪的9929这种 有端口数量限制的这种 一旦隧道建立了 转发基本上就不需要再局限于那几个破端口了
用fakehttp
@imaxwell #1 这个还是看自己的需要的 比如说我的需求就是 嫌弃一些优化线路的nat鸡 扣扣嗖嗖的就几个端口放在那 通过这玩意 家里挂个虚拟鸡和nat鸡组内网 直接65535个端口全部通 不用再扣扣嗖嗖的死磕那几个破端口了
@coupile #4 没必要 faketcp就行了 如果不是 fakeicmp总是断 我都想fackicmp的
为啥不用udp2raw或phantun或mimic加上wireguard?
@sv6cr #7 问题就在这 udp2raw和wireguard组合起来 不是一个单核小鸡吃得消的 尤其是速度上来后
我这个主要是因为我自己的nat鸡有点多 配置又低 用go憋一个 all in one 岂不是比哪些组合拳更方便一些么 我主打的就是一个all in one
就一个疑问
隧道建立起来防不防gfw
gfw能不能看见隧道里面干了什么?
@dira #0 鸡腿奖励,多谢共享,后续期待能出网络测评的内容,来个晚高峰传输测速什么的。