<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/rss/stylesheet/" type="text/xsl"?>
<rss xmlns:content='http://purl.org/rss/1.0/modules/content/' xmlns:taxo='http://purl.org/rss/1.0/modules/taxonomy/' xmlns:rdf='http://www.w3.org/1999/02/22-rdf-syntax-ns#' xmlns:itunes='http://www.itunes.com/dtds/podcast-1.0.dtd' xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:dc='http://purl.org/dc/elements/1.1/' xmlns:atom='http://www.w3.org/2005/Atom' xmlns:podbridge='http://www.podbridge.com/podbridge-ad.dtd' version='2.0'>
<channel>
  <title>Snicoe&apos;s Blog</title>
  <language>zh-cn</language>
  <generator>microfeed.org</generator>
  <itunes:type>serial</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <atom:link rel="self" href="https://blog-arklink-org.pages.dev/rss/" type="application/rss+xml"/>
  <link>https://blog.arklink.org</link>
  <description>
    <![CDATA[<blockquote><em><u>“这是一步死棋”</u></em></blockquote><p>这里是Snicoe自言自语的地方，随便写点东西，也没啥人看，所以看心情更新一些陈芝麻烂谷子的东西。</p><p>计划有变，我可能不会经常维护此站点，也许可能永久不更新消失在汪洋互联网之中，会回来吗？也许吧，Good Luck！</p><p>社媒: <a href="https://www.instagram.com/snicoe0716" rel="noopener noreferrer" target="_blank">Instagram</a> | <a href="https://www.youtube.com/@snicoeofficial" rel="noopener noreferrer" target="_blank">Youtube</a> | <a href="https://x.com/snicoeofficial" rel="noopener noreferrer" target="_blank">X / Twitter</a></p><p>如果你使用了我的部分服务可以前往<a href="https://status0.arklink.org" rel="noopener noreferrer" target="_blank">Status</a>页面查看可用状态，全部服务均优先运行在IPv6网络。</p><p>本人生理男性并自认为男性，性取向正常，社恐一个，看心情回复❤️。</p>]]>
  </description>
  <itunes:author>Snicoeの自言自语</itunes:author>
  <itunes:image href="https://media-cdn.arklink.org/blog-arklink-org/production/images/channel-35018318ef9161a58e1728b4144ab0a9.png"/>
  <image>
    <title>Snicoe&apos;s Blog</title>
    <url>https://media-cdn.arklink.org/blog-arklink-org/production/images/channel-35018318ef9161a58e1728b4144ab0a9.png</url>
    <link>https://blog.arklink.org</link>
  </image>
  <copyright>©2019-2025</copyright>
  <itunes:category text="Science"/>
  <item>
    <title>做了个没卵用的小实验 | Wireguard Over HTTP/3</title>
    <guid>Eu5eQcR4Mdv</guid>
    <pubDate>Mon, 09 Sep 2024 09:23:45 GMT</pubDate>
    <itunes:explicit>false</itunes:explicit>
    <description>
      <![CDATA[<p>使用的项目是：<a href="https://github.com/apernet/hysteria" rel="noopener noreferrer" target="_blank">https://github.com/apernet/hysteria</a></p><p>看之前建议恶补一下HTTP/3：<a href="https://en.wikipedia.org/wiki/HTTP/3" rel="noopener noreferrer" target="_blank">https://en.wikipedia.org/wiki/HTTP/3</a></p><p>目的只是测试一下wireguard over quic性能，使用hy2(以下全文使用hy2代替hysteria2)将wireguard的udp封装进quic。</p><p>简单配置一下hy2</p><h3><strong>服务端：</strong></h3><p>官方脚本先一把梭</p><pre class="ql-syntax" spellcheck="false">bash &lt;(curl -fsSL https://get.hy2.sh/)
</pre><p>创建自签证书</p><pre class="ql-syntax" spellcheck="false">openssl req -x509 -nodes -newkey ec:&lt;(openssl ecparam -name prime256v1) -keyout /etc/hysteria/server.key -out /etc/hysteria/server.crt -subj "/CN=bing.com" -days 36500 &amp;&amp; sudo chown hysteria /etc/hysteria/server.key &amp;&amp; sudo chown hysteria /etc/hysteria/server.crt
</pre><p>编辑vim /etc/hysteria/config.yaml</p><pre class="ql-syntax" spellcheck="false">listen: :25829
&nbsp;&nbsp;
tls:
&nbsp;cert: /etc/hysteria/server.crt
&nbsp;key: /etc/hysteria/server.key

auth:
&nbsp;type: password
&nbsp;password: 3P3s1nVbzh6yY8BXspfnFruBmnzVwFcfzpC9vBJ

masquerade:
&nbsp;type: proxy
&nbsp;proxy:
&nbsp;&nbsp;url: https://microsoft.com/
&nbsp;&nbsp;rewriteHost: true
</pre><p>启动服务</p><pre class="ql-syntax" spellcheck="false">systemctl disable hysteria-server
</pre><h3><strong>客户端：</strong></h3><p>下载二进制文件。</p><p><a href="https://v2.hysteria.network/docs/getting-started/Installation/" rel="noopener noreferrer" target="_blank">https://v2.hysteria.network/docs/getting-started/Installation/</a></p><p>创建config.yaml，如果使用ipv6地址进行传输，注意添加[]，ipv6地址的冒号与yaml语法冲突。</p><pre class="ql-syntax" spellcheck="false">server: "[2001:abc::]:25819"

auth: 3P3s1nVbzh6yY8BXspfnFruBmnzVwFcfzpC9vBJ

bandwidth:
&nbsp;up: 50 mbps
&nbsp;down: 300 mbps

udpForwarding: #监听本地51820，转发到目标机器20002端口
&nbsp;- listen: 0.0.0.0:51820
&nbsp;&nbsp;remote: 127.0.0.1:20002
&nbsp;&nbsp;timeout: 20s
</pre><p>wireguard配置就简单了</p><p>参见<a href="https://blog.arklink.org/i/wireguardor-5S4pGQ_kLDE/" rel="noopener noreferrer" target="_blank">https://blog.arklink.org/i/wireguardor-5S4pGQ_kLDE/</a></p><p>记得配置防火墙规则,wg1更改为你的wireguard接口，ens2更改为自己的出口接口。</p><pre class="ql-syntax" spellcheck="false">PostUp = iptables -A FORWARD -i wg1 -j ACCEPT; iptables -t nat -A POSTROUTING -o ens2 -j MASQUERADE;
PostDown = iptables -D FORWARD -i wg1 -j ACCEPT; iptables -t nat -D POSTROUTING -o ens2 -j MASQUERADE;
</pre><h2>最后直接进行一个激情的测速！</h2><p>手机Wireguard连接到一个X86 CHR再markrouting到海外的服务器，笑死你能分清哪一个是走wireguard原生/hy2转发wireguard/原生hy2吗，结果是没啥区别，笑麻了。</p><p>你还别说hy2确实猛，辣鸡欧洲小鸡也能跑出这种带宽。<img src="https://media-cdn.arklink.org/blog-arklink-org/production/media/rich-editor/items/Eu5eQcR4Mdv/image-d43e6b29f441fb75136837cbd778a064.png"></p><p><img src="https://media-cdn.arklink.org/blog-arklink-org/production/media/rich-editor/items/Eu5eQcR4Mdv/image-a650ca426038a91706e65aefef1649bf.png"></p><p><img src="https://media-cdn.arklink.org/blog-arklink-org/production/media/rich-editor/items/Eu5eQcR4Mdv/image-3f76f56f7348afb31b5db5fff149d9ee.jpg"></p>]]>
    </description>
    <link>https://blog.arklink.org/i/or-wireguard-over-http3-Eu5eQcR4Mdv/</link>
    <itunes:episodeType>full</itunes:episodeType>
  </item>
</channel>
</rss>