logo NodeSeekbeta

[QOS救星]Lightweight Tunnel (轻量级内网隧道)

开个玩笑,救星算不上。基于tinyfecvpn与udp2raw的思路搞的一个轻量级内网隧道项目。
特征是建立一个内网隧道,上层使用tcp伪装底下是udp发包并且维持心跳。
AI脸滚键盘键盘出来的,和参考项目比的话也就是用GO写的并且对渣机的支持比较好吧。
怎么说呢,能用能跑。因为跑的是TCP,没有遭运营商的UDP限制策略那么严重。

项目地址
https://github.com/openbmx/lightweight-tunnel

Lightweight Tunnel (轻量级内网隧道)

一个使用 Go 语言开发的轻量级内网隧道工具,支持 TCP 伪装和 FEC 纠错功能。适用于在两个低配置服务器之间建立安全的内网连接。

A lightweight intranet tunnel tool developed in Go, supporting TCP disguise and FEC (Forward Error Correction). Suitable for establishing secure intranet connections between two low-spec servers.

Features (特性)

  • 🚀 轻量级设计 - 占用资源少,适合低配置服务器
  • 🔒 TCP 伪装 - UDP 数据包伪装成 TCP 连接,绕过防火墙限制
  • 🛡️ FEC 纠错 - Forward Error Correction 提供数据包丢失恢复能力
  • 🌐 TUN 设备 - 基于 TUN 设备的第三层网络隧道
  • ⚡ 高性能 - 使用 Go 协程实现并发处理
  • 🎯 简单易用 - 命令行参数或配置文件两种配置方式

Quick Start (快速开始)

Prerequisites (前置要求)

  • Linux 系统 (需要 TUN 设备支持)
  • Root 权限 (用于创建和配置 TUN 设备)
  • Go 1.19+ (仅编译时需要)

Installation (安装)

# Clone the repository
git clone https://github.com/openbmx/lightweight-tunnel.git
cd lightweight-tunnel

# Build
go build -o lightweight-tunnel ./cmd/lightweight-tunnel

# Or install directly
go install ./cmd/lightweight-tunnel

Usage (使用方法)

Server Side (服务端)
# Run as server with default settings
sudo ./lightweight-tunnel -m server -l 0.0.0.0:9000 -t 10.0.0.1/24

# Or use config file
sudo ./lightweight-tunnel -c server.json
Client Side (客户端)
# Run as client
sudo ./lightweight-tunnel -m client -r SERVER_IP:9000 -t 10.0.0.2/24

# Or use config file
sudo ./lightweight-tunnel -c client.json

Configuration File (配置文件)

Generate example configuration files:

./lightweight-tunnel -g config.json

This creates config.json (server) and config.json.client (client).

Example server configuration:

{
  "mode": "server",
  "local_addr": "0.0.0.0:9000",
  "remote_addr": "",
  "tunnel_addr": "10.0.0.1/24",
  "mtu": 1400,
  "fec_data": 10,
  "fec_parity": 3,
  "timeout": 30,
  "keepalive": 10
}

Example client configuration:

{
  "mode": "client",
  "local_addr": "0.0.0.0:9000",
  "remote_addr": "SERVER_IP:9000",
  "tunnel_addr": "10.0.0.2/24",
  "mtu": 1400,
  "fec_data": 10,
  "fec_parity": 3,
  "timeout": 30,
  "keepalive": 10
}

Command Line Options (命令行选项)

  -c string
        Configuration file path
  -m string
        Mode: server or client (default "server")
  -l string
        Local address to listen on (default "0.0.0.0:9000")
  -r string
        Remote address to connect to (client mode)
  -t string
        Tunnel IP address and netmask (default "10.0.0.1/24")
  -mtu int
        MTU size (default 1400)
  -fec-data int
        FEC data shards (default 10)
  -fec-parity int
        FEC parity shards (default 3)
  -v    Show version
  -g string
        Generate example config file

Architecture (架构)

┌─────────────┐         TCP (disguised)         ┌─────────────┐
│   Server    │ ◄─────────────────────────────► │   Client    │
│  (10.0.0.1) │    with FEC error correction    │  (10.0.0.2) │
└──────┬──────┘                                  └──────┬──────┘
       │                                                │
       │ TUN Device                            TUN Device │
       │                                                │
  ┌────▼────┐                                      ┌────▼────┐
  │ App/Svc │                                      │ App/Svc │
  └─────────┘                                      └─────────┘

How It Works (工作原理)

  1. TUN Device: Creates a virtual network interface for Layer 3 (IP) traffic
  2. TCP Disguise: Wraps UDP-like packets in TCP connections to bypass firewalls
  3. FEC: Adds redundant data shards for packet loss recovery
  4. Keepalive: Maintains connection with periodic heartbeat packets

Testing (测试)

After establishing the tunnel, you can test connectivity:

# On server side, ping client
ping 10.0.0.2

# On client side, ping server
ping 10.0.0.1

# Test with iperf
# Server: iperf -s
# Client: iperf -c 10.0.0.1

Performance Tuning (性能调优)

  • MTU: Adjust based on your network (default: 1400)
  • FEC Shards: More parity shards = better loss recovery but more overhead
  • Keepalive: Shorter interval = faster detection of disconnection

Limitations (限制)

  • Currently supports only IPv4
  • Single client per server instance
  • Requires root/admin privileges for TUN device
  • Linux only (uses Linux TUN/TAP interfaces)

References (参考项目)

License

MIT License

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

123
  • 这么说移动qos有救了?具体怎么救?希望有大佬来指路

  • 落地是服务端入口是客户端吗?

  • @1083819963 #2 服务端和客户端并不绝对 我这里做区分只是方便理解 原则上是双端谁的配置高谁做服务端 因为隧道建立后 核心就一个 内网互通了 尤其是适合哪些有nat限制的优化线路机器 比如说酷雪的9929这种 有端口数量限制的这种 一旦隧道建立了 转发基本上就不需要再局限于那几个破端口了

  • 用fakehttp

  • @imaxwell #1 这个还是看自己的需要的 比如说我的需求就是 嫌弃一些优化线路的nat鸡 扣扣嗖嗖的就几个端口放在那 通过这玩意 家里挂个虚拟鸡和nat鸡组内网 直接65535个端口全部通 不用再扣扣嗖嗖的死磕那几个破端口了

  • @coupile #4 没必要 faketcp就行了 如果不是 fakeicmp总是断 我都想fackicmp的

  • @sv6cr #7 问题就在这 udp2raw和wireguard组合起来 不是一个单核小鸡吃得消的 尤其是速度上来后
    我这个主要是因为我自己的nat鸡有点多 配置又低 用go憋一个 all in one 岂不是比哪些组合拳更方便一些么 我主打的就是一个all in one

  • 就一个疑问
    隧道建立起来防不防gfw
    gfw能不能看见隧道里面干了什么?

  • @dira #0 鸡腿奖励,多谢共享,后续期待能出网络测评的内容,来个晚高峰传输测速什么的。 xhj003

123

你好啊,陌生人!

我的朋友,看起来你是新来的,如果想参与到讨论中,点击下面的按钮!

📈用户数目📈

目前论坛共有72745位seeker

🎉欢迎新用户🎉