Compare commits

...
134 Commits
Author SHA1 Message Date
CallMeR fb78eec84e 精简 Dnsmasq 参数 2025-06-12 01:42:08 +08:00
CallMeR f5e85ddbc2 精简 Dnsmasq 参数 2025-05-27 01:44:54 +08:00
CallMeR 97ffd13089 更新 TS 防火墙 2025-05-20 22:46:34 +08:00
CallMeR 8f08c4af81 更新 TS 服务器配置 2025-05-20 00:18:27 +08:00
CallMeR 1edfd2c06f 更新 TS 服务器 qdisc 参数 2025-04-28 23:34:33 +08:00
CallMeR fc27f25f94 更新 TS 服务器 sysctl 参数 2025-04-26 23:31:18 +08:00
CallMeR 5f8f9603dc 精简 DNS 服务器 sysctl 参数 2025-04-26 11:26:37 +08:00
CallMeR c768194983 精简 SmartDNS 配置 2025-04-18 16:13:37 +08:00
CallMeR 509e328c03 更新 TS 防火墙 2025-04-18 09:57:03 +08:00
CallMeR 1dd2c5ae24 更新 sysctl 参数 2025-04-17 15:17:49 +08:00
CallMeR ea74679b4a 更新防火墙备注 2025-04-16 18:07:10 +08:00
CallMeR 8a6bdbe207 更新 TS 防火墙 2025-04-16 17:46:22 +08:00
CallMeR 7c6c92d7ed 更新 TS 防火墙配置 2025-04-16 17:03:38 +08:00
CallMeR 01f00f4bc7 更新 TS 防火墙配置 2025-04-16 14:08:04 +08:00
CallMeR 6d5693a73a 更新防火墙流表设置 2025-04-16 01:03:48 +08:00
CallMeR a0c8b88bab Revert 更新 TS 防火墙配置 2025-04-15 23:56:33 +08:00
CallMeR 1fe6812f30 更新 TS 防火墙配置 2025-04-15 23:20:36 +08:00
CallMeR 19f5d89152 更新 TS 防火墙配置 2025-04-15 17:29:38 +08:00
CallMeR 5e228452ec 更新 SmartDNS 参数 2025-04-03 17:31:56 +08:00
CallMeR 1e52d61178 更新文案描述 2025-03-28 23:31:32 +08:00
CallMeR d425c1275b 更新 sysctl 生效命令 2025-03-28 22:29:53 +08:00
CallMeR b129dd215d 更新 SmartDNS 参数 2025-03-28 15:52:58 +08:00
CallMeR 613c562c1c 更新软件包描述 2025-03-17 02:56:59 +08:00
CallMeR 184508f0fd 调整 Bing 搜索链接 2025-03-16 23:42:50 +08:00
CallMeR 2b24267c0c 调整 Bing 搜索链接 2025-03-16 23:29:57 +08:00
CallMeR b5a44c52b2 更新软件包描述 2025-03-16 22:51:48 +08:00
CallMeR 1606e0c74b 更新系统 sysctl 参数 2025-03-14 14:38:27 +08:00
CallMeR 5293258eb8 更新 DNS 拦截列表 2025-03-06 00:58:04 +08:00
CallMeR 1c88c7327f 更新 SmartDNS 版本 2025-03-04 01:56:52 +08:00
CallMeR b3fb776f91 跟进 neodevhost 列表上游修改 2025-03-02 00:34:24 +08:00
CallMeR c69fedc984 更新截图 2025-02-02 21:58:17 +08:00
CallMeR 1915273f81 更新截图 2025-02-02 21:34:44 +08:00
CallMeR 8a72ccebbe 更新截图 2025-02-02 21:19:19 +08:00
CallMeR 4600694a36 更新截图 2025-02-02 21:02:06 +08:00
CallMeR fad611823f 更新上游 DNS 2025-02-01 02:16:40 +08:00
CallMeR f13d108c7b 更新文案描述 2025-01-24 23:08:13 +08:00
CallMeR cb205dda2f 更新文案描述 2025-01-20 18:55:03 +08:00
CallMeR d613ea63a1 更新截图 2025-01-20 18:22:16 +08:00
CallMeR 664bf13a20 更新截图 2025-01-20 17:56:45 +08:00
CallMeR ccd3942725 调整部分时间相关参数 2025-01-18 09:26:33 +08:00
CallMeR 573468ca94 调整 Nftables MTU Fixing 2025-01-17 01:34:54 +08:00
CallMeR 2c22ba9212 更新 TS 服务器参数 2025-01-16 17:57:50 +08:00
CallMeR c1c6282713 更新系统软件 2025-01-16 13:08:52 +08:00
CallMeR 8cca306890 调整 Nftables Offload 2025-01-15 21:38:01 +08:00
CallMeR 6b49519190 精简 SYSCTL 参数 2025-01-15 18:21:03 +08:00
CallMeR 688d6e0809 精简 SYSCTL 参数 2025-01-15 17:45:48 +08:00
CallMeR ad51e789de 调整 Nftables Offload 2025-01-15 15:00:05 +08:00
CallMeR 0a7fda4e15 更新 Dnsmasq 参数 2025-01-14 15:25:36 +08:00
CallMeR 100c012314 更新系统软件 2025-01-14 14:55:13 +08:00
CallMeR 945b25304d 简化 oh-my-zsh 安装 2025-01-14 10:42:58 +08:00
CallMeR 82066a8a21 更新备注 2025-01-13 18:02:25 +08:00
CallMeR f8b3bfd75e 更新备注 2025-01-13 17:56:11 +08:00
CallMeR 36d4809b37 调整 Dnsmasq 参数 2025-01-13 16:18:32 +08:00
CallMeR b7e6978342 更新文案描述 2025-01-13 15:39:58 +08:00
CallMeR 03ee8135c8 Fix newline ( 2025-01-08 22:28:27 +08:00
CallMeR 1ce40c7a36 更新内核参数 2025-01-08 22:13:00 +08:00
CallMeR 8d2f3e98de 调整域名顺序 2025-01-08 17:57:25 +08:00
CallMeR c3e0205fdf 调整 SmartDNS 内网域名策略 2025-01-08 17:51:51 +08:00
CallMeR a606d3f6e4 调整 Dnsmasq 内网域名策略 2025-01-08 17:46:19 +08:00
CallMeR 42e0359d03 更新内核参数 2025-01-08 12:09:16 +08:00
CallMeR 0377b500b6 跟进 ICANN | SAC113 调整内网域名 2025-01-07 22:34:03 +08:00
CallMeR 90c7adc62d 精简 TS 防火墙 2025-01-07 13:25:40 +08:00
CallMeR 17c0a3f87d 优化文案描述 2025-01-06 23:48:33 +08:00
CallMeR 3143d46834 更新文案描述 2025-01-06 23:37:32 +08:00
CallMeR 4dda73f087 更新文案描述 2025-01-06 23:29:04 +08:00
CallMeR 45bcf699d9 更新文案描述 2025-01-06 23:18:07 +08:00
CallMeR d153773b1f 更新清理目录 2025-01-06 18:09:39 +08:00
CallMeR 7d8da1f68e 更新清理命令 2025-01-06 18:01:14 +08:00
CallMeR 641aa555b9 更新清理命令 2025-01-06 17:54:23 +08:00
CallMeR 34e55b8daa 更新文案描述 2025-01-06 17:25:31 +08:00
CallMeR 777e4bb9d7 更新清理命令 2025-01-06 17:23:57 +08:00
CallMeR 7dceb23655 更新清理命令 2025-01-06 17:19:22 +08:00
CallMeR 81c5c3456a 整理文档结构 2025-01-06 17:11:27 +08:00
CallMeR 0731dd1fde 更新 Dnsmasq 参数 2025-01-06 02:12:11 +08:00
CallMeR 7e62ab3012 更新 TS 防火墙 2024-12-29 22:52:52 +08:00
CallMeR 14022aebbf 更新 TS 防火墙 2024-12-29 01:51:28 +08:00
CallMeR 8738625ad9 更新文案描述 2024-12-26 13:22:46 +08:00
CallMeR 51a6d0005d 更新文案描述 2024-12-26 13:20:10 +08:00
CallMeR f3a4231218 调整 TS 服务器 Dnsmasq 配置 2024-12-26 12:42:03 +08:00
CallMeR 422384497c 修复描述错误 2024-12-03 13:41:33 +08:00
CallMeR 8c26dd2569 更新广告列表 2024-11-26 12:50:51 +08:00
CallMeR ae963404b7 更新广告列表 2024-11-24 22:16:03 +08:00
CallMeR 96f89812de 更新版本号 2024-11-24 17:28:13 +08:00
CallMeR 968d0637dd 更新截图版本 2024-11-24 17:23:44 +08:00
CallMeR 1166516576 更新 DNS sysctl 参数 2024-11-02 15:37:49 +08:00
CallMeR f664975bcc 更新 DNS sysctl 参数 2024-10-29 14:01:39 +08:00
CallMeR 26fa0b0c10 修复描述错误,Fix: https://gitee.com/callmer/routeros_toss_notes/issues/IB0HER 2024-10-29 13:26:00 +08:00
CallMeR ac2740f888 更新系统 sysctl 参数 2024-10-28 00:32:12 +08:00
CallMeR aa1a12757b 更新系统 sysctl 参数 2024-10-24 18:23:26 +08:00
CallMeR ccef3195ff 更新系统 sysctl 参数 2024-10-23 10:12:01 +08:00
CallMeR dd3bda21f5 更新系统 sysctl 参数 2024-10-22 15:28:58 +08:00
CallMeR 547389c182 更新系统 sysctl 参数 2024-10-22 14:18:09 +08:00
CallMeR ace58ce24d 更新 TS 服务器流控算法 2024-10-21 23:30:53 +08:00
CallMeR adaeb4a650 新增 BTRFS 调整内容 2024-10-19 02:26:04 +08:00
CallMeR fa29b0d633 更新系统 sysctl 参数 2024-10-17 12:57:46 +08:00
CallMeR 94273ae2b6 RFC 9460
Service Binding and Parameter Specification via the DNS (SVCB and HTTPS Resource Records)
2024-10-14 17:53:10 +08:00
CallMeR 2d32561415 更新 SmartDNS 过期缓存 2024-10-13 17:06:50 +08:00
CallMeR 0dcfa86d11 更新 SmartDNS 加速脚本 2024-10-13 16:32:44 +08:00
CallMeR 557ae16217 更新清理缓存命令 2024-10-09 23:43:17 +08:00
CallMeR 49083bf184 更新 SmartDNS 清理缓存 2024-10-08 23:48:01 +08:00
CallMeR 9634a10686 更新清理命令 2024-10-08 23:30:52 +08:00
CallMeR 6f7c78b749 更新清理命令 2024-10-08 23:16:46 +08:00
CallMeR 04fc40c8e1 更新清理命令 2024-10-08 23:08:24 +08:00
CallMeR 05ba8586ae 更新 SmartDNS 参数 2024-10-08 22:56:27 +08:00
CallMeR e8cb9b14f4 更新示例输出 2024-10-07 18:08:24 +08:00
CallMeR 7b794c11e4 更新 NTP 服务器 2024-10-07 18:04:33 +08:00
CallMeR d4673a204a 更新实例输出 2024-10-07 18:00:03 +08:00
CallMeR 95913b4d0d 更新 NTP 服务器 2024-10-07 17:52:02 +08:00
CallMeR 964fc699e3 Revert 更新 SmartDNS 参数 2024-10-05 17:44:11 +08:00
CallMeR b3b147ab37 更新 SmartDNS 广告列表 2024-09-27 23:05:48 +08:00
CallMeR cdcc71462b 更新 SmartDNS 参数 2024-09-27 16:05:05 +08:00
CallMeR 999a06f938 更新 Nftables 规则 2024-09-27 14:30:48 +08:00
CallMeR 4bf1e1d523 更新 Nftables 规则 2024-09-27 14:01:18 +08:00
CallMeR ddc60fd6f1 更换 SmartDNS 广告列表 2024-09-19 15:44:11 +08:00
CallMeR c94872a931 更新 SmartDNS 缓存参数 2024-09-15 12:20:03 +08:00
CallMeR d09bd30a25 更新上游 DNS 2024-09-05 13:55:10 +08:00
CallMeR cc5ec05502 更新 SmartDNS 上游 DNS 2024-09-03 13:59:54 +08:00
CallMeR e0894f3e13 更新 PVE 版本 2024-08-24 19:44:32 +08:00
CallMeR 360d5b6cab 更新 DNS 缓存参数 2024-08-24 03:23:26 +08:00
CallMeR 8d2cab7155 更新备注 2024-08-17 22:37:05 +08:00
CallMeR afb5a5859c 更新 Dnsmasq 配置 2024-08-15 19:07:27 +08:00
CallMeR 53c3fe877a 更新 SmartDNS 上游 DoT / DoH 服务器 2024-08-14 21:40:22 +08:00
CallMeR 835cbf9b43 更新上游 DNS 服务器 2024-08-07 22:52:54 +08:00
CallMeR 1b97935413 更新 SmartDNS 插件 2024-08-07 13:30:38 +08:00
CallMeR fc67f6f575 更新 SmartDNS 上游 DNS 2024-08-07 13:22:22 +08:00
CallMeR bc5ea890ad 更新 Dnsmasq 参数 2024-08-02 20:14:17 +08:00
CallMeR fefcd16f82 更新 SmartDNS 参数 2024-08-02 20:10:24 +08:00
CallMeR 10050fa7ff 更新 SmartDNS Plugin 2024-08-02 10:46:49 +08:00
CallMeR 20086c63f7 调整 Dnsmasq 配置 2024-08-02 10:29:56 +08:00
CallMeR 619b96a6fc 调整 SmartDNS 参数 2024-08-02 00:37:42 +08:00
CallMeR 4fbb729d85 关闭 SmartDNS 过期缓存并调整响应 TTL 2024-07-29 01:13:05 +08:00
CallMeR 78fd87188c 停用 Dnsmasq 的 negative 缓存 2024-07-27 11:23:48 +08:00
CallMeR 8a737cfb34 优化 SmartDNS 配置 2024-07-24 23:31:45 +08:00
CallMeR fcfd177593 移除 SmartDNS EDNS 参数 2024-07-24 21:53:31 +08:00
65 changed files with 484 additions and 422 deletions
+3 -3
View File
@@ -6,7 +6,7 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso)
页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.2-1 ISO Installer` 作为演示。
页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.3-1 ISO Installer` 作为演示。
点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。
@@ -162,7 +162,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
演示中 FQDN 为 `node01.fox.home.arpa` ,因此 PVE 的主机名为 `node01`
演示中 FQDN 为 `node01.fox.internal` ,因此 PVE 的主机名为 `node01`
根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254`
@@ -172,7 +172,7 @@ FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|参数|值|说明|
|--|--|--|
|Hostname (FQDN)|`node01.fox.home.arpa`|设置 PVE `域``主机名` |
|Hostname (FQDN)|`node01.fox.internal`|设置 PVE `域``主机名` |
|IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址|
|Gateway|`172.16.1.1`|设置 PVE IPv4 网关|
|DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS |
+10 -14
View File
@@ -15,7 +15,7 @@
使用终端工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。
```bash
## 进入系统软件源配置文件目录
## 进入系统软件源配置目录
$ cd /etc/apt
## 查看系统默认镜像配置
@@ -101,22 +101,15 @@ $ rm -rvf /etc/apt/sources.list.d/pve-enterprise.list /etc/apt/sources.list.d/ce
```bash
## 检查 PVE 免费源
$ cat /etc/apt/sources.list.d/pve-no-subscription.list
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
$ cat /etc/apt/sources.list.d/*
```
如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。
```bash
#### PVE 免费软件源示例输出
#### PVE
deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
#### Ceph
deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription
deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
```
### 1.3. PVE CT 源
@@ -171,10 +164,7 @@ $ apt full-upgrade
$ apt update
## 安装系统软件
$ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具
$ apt install iperf iperf3 iftop sshguard openvswitch-switch
$ apt install btop lm-sensors tmux neovim unzip unattended-upgrades powermgmt-base sshguard
## 安装 CPU 调度调整工具
$ apt install linux-cpupower
@@ -182,6 +172,12 @@ $ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode)
## 安装 Open vSwitch(可选)
$ apt install openvswitch-switch
## 安装网络检测工具(可选)
$ apt install iftop iperf3 iperf
## 更新 PCI 数据库
$ update-pciids
```
+103 -38
View File
@@ -4,15 +4,14 @@
在 PVE 系统调整之前,请确认必要的软件包已经安装完成,本文后续命令均在 SSH 终端下执行。
关于 [Neovim](https://neovim.io/) 的基础使用方法,请参阅:[Neovim 基础教程](https://cn.bing.com/search?q=Neovim+%E5%9F%BA%E7%A1%80%E6%95%99%E7%A8%8B) 。
```bash
## 同步镜像仓库
$ apt update
## 安装系统软件
$ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具
$ apt install iperf iperf3 iftop sshguard openvswitch-switch
$ apt install btop lm-sensors tmux neovim unzip unattended-upgrades powermgmt-base sshguard
## 安装 CPU 调度调整工具
$ apt install linux-cpupower
@@ -20,6 +19,12 @@ $ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode)
## 安装 Open vSwitch(可选)
$ apt install openvswitch-switch
## 安装网络检测工具(可选)
$ apt install iftop iperf3 iperf
## 更新 PCI 数据库
$ update-pciids
```
@@ -38,7 +43,7 @@ $ timedatectl set-timezone Asia/Shanghai
$ date -R
#### 系统时间示例输出
Sun, 25 Jun 2023 12:12:12 +0800
Mon, 20 Jan 2025 18:24:41 +0800
```
Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统使用 `chrony.service` 来同步时间。
@@ -47,7 +52,7 @@ Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统
```bash
## 编辑 chrony 配置文件
$ nano /etc/chrony/chrony.conf
$ nvim /etc/chrony/chrony.conf
```
在编辑器对话框中,将 `pool 2.debian.pool.ntp.org iburst` “注释” 掉,并添加国内的 NTP 服务器。
@@ -59,15 +64,16 @@ $ nano /etc/chrony/chrony.conf
# pool 2.debian.pool.ntp.org iburst ## 在这行前面增加注释符 # 来注释
# Use Custom vendor zone.
pool ntp.tencent.com iburst
pool ntp.aliyun.com iburst
pool ntp.tencent.com iburst
pool cn.pool.ntp.org iburst
```
保存该配置文件后,需重启 `chrony.service` ,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
## 重启 chrony.service
$ systemctl restart chrony.service
## 检查系统 NTP 服务器
@@ -76,8 +82,12 @@ $ chronyc sources -V
#### 系统 NTP 服务器示例输出
MS Name/IP address Stratum Poll Reach LastRx Last sample
===============================================================================
^+ 106.55.184.199 2 6 17 11 +752us[ +273us] +/- 40ms
^* 203.107.6.88 2 6 17 11 -1868us[-2348us] +/- 17ms
^* 203.107.6.88 2 6 17 0 -875us[-2496us] +/- 22ms
^- 106.55.184.199 2 6 17 3 -1331us[-1331us] +/- 50ms
^- time.neu.edu.cn 2 6 17 8 +935us[ +935us] +/- 23ms
^- 119.28.206.193 2 6 65 5 +33us[ +33us] +/- 65ms
^- electrode.felixc.at 2 6 17 11 -1320us[-1320us] +/- 126ms
^- dns1.synet.edu.cn 1 6 17 13 -44us[ -44us] +/- 22ms
```
## 2. CPU 调度器
@@ -97,10 +107,10 @@ analyzing CPU 0:
hardware limits: 800 MHz - 2.70 GHz
available cpufreq governors: conservative ondemand userspace powersave performance schedutil
current policy: frequency should be within 800 MHz and 2.70 GHz.
The governor "ondemand" may decide which speed to use
The governor "performance" may decide which speed to use
within this range.
current CPU frequency: Unable to call hardware
current CPU frequency: 800 MHz (asserted by call to kernel)
current CPU frequency: 2.60 GHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
@@ -136,7 +146,7 @@ analyzing CPU 0:
$ cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_governor
#### 设备 CPU - J4125 示例输出
ondemand
performance
#### 设备 CPU - N6005 示例输出
performance
@@ -163,11 +173,11 @@ performance powersave
- CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器创建 `cpupower` 的配置文件。
本文使用 `powersave` 调度器为演示,使用 `neovim` 编辑器创建 `cpupower` 的配置文件。
```bash
## 创建 cpupower 配置文件
$ nano /etc/default/cpupower
## 创建 cpupower 默认配置文件
$ nvim /etc/default/cpupower
```
在配置文件中修改以下配置项,并保存。
@@ -181,11 +191,11 @@ CPUPOWER_STOP_OPTS="frequency-set -g performance"
```
使用 `nano` 编辑器创建 `cpupower` 服务配置文件,以满足系统自动化设置需求。
进一步创建 `cpupower` 服务配置文件,以满足系统自动化设置需求。
```bash
## 创建 cpupower 服务配置文件
$ nano /etc/systemd/system/cpupower.service
## 创建 cpupower.service 配置文件
$ nvim /etc/systemd/system/cpupower.service
```
在服务配置文件中修改以下配置项,并保存。
@@ -275,11 +285,11 @@ $ systemctl status apt-daily-upgrade.timer
#### 系统定时器示例输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Active: active (waiting) since Tue 2023-08-01 13:01:19 CST; 27min ago
Trigger: Wed 2023-08-02 06:14:50 CST; 16h left
Active: active (waiting) since Mon 2025-01-20 18:12:44 CST; 19min ago
Trigger: Tue 2025-01-21 06:52:19 CST; 12h left
Triggers: ● apt-daily-upgrade.service
Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Jan 20 18:12:44 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
```
### 4.2.配置更新策略
@@ -292,10 +302,8 @@ Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt u
## 配置自动更新策略
$ dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
## 选择 “是”
<Yes>
```
进一步调整 `20auto-upgrades` 配置文件。
@@ -305,7 +313,7 @@ Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
$ cd /etc/apt/apt.conf.d
## 编辑 20auto-upgrades 配置文件
$ nano /etc/apt/apt.conf.d/20auto-upgrades
$ nvim /etc/apt/apt.conf.d/20auto-upgrades
```
删除里面全部内容,添加以下配置项,并保存。
@@ -326,7 +334,7 @@ APT::Periodic::CleanInterval "1";
```bash
## 编辑 50unattended-upgrades 配置文件
$ nano /etc/apt/apt.conf.d/50unattended-upgrades
$ nvim /etc/apt/apt.conf.d/50unattended-upgrades
```
配置文件中,被修改的参数解释如下:
@@ -417,13 +425,13 @@ $ systemctl status apt-daily-upgrade.timer
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf
Active: active (waiting) since Tue 2023-08-01 13:37:41 CST; 9s ago
Trigger: Wed 2023-08-02 01:30:00 CST; 11h left
Active: active (waiting) since Mon 2025-01-20 18:43:03 CST; 7s ago
Trigger: Tue 2025-01-21 01:30:00 CST; 6h left
Triggers: ● apt-daily-upgrade.service
Aug 01 13:37:41 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Aug 01 13:37:41 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Jan 20 18:43:03 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Jan 20 18:43:03 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Jan 20 18:43:03 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
```
## 5.硬件直通
@@ -436,7 +444,7 @@ Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt u
```bash
## 编辑 Grub 配置文件
$ nano /etc/default/grub
$ nvim /etc/default/grub
```
在编辑器对话框中修改 `GRUB_CMDLINE_LINUX_DEFAULT` 参数,注意命令中间的空格。
@@ -470,7 +478,7 @@ $ update-grub
```bash
## 编辑系统配置文件
$ nano /etc/modules
$ nvim /etc/modules
```
在配置文件中添加以下配置项,并保存。
@@ -565,7 +573,64 @@ $ find /sys/kernel/iommu_groups/ -type l
/sys/kernel/iommu_groups/9/devices/0000:00:1c.6
```
## 6.系统清理
## 6. BTRFS 调整
**额外说明:**
1. 本节专为 `BTRFS` 单盘 `RAID0`(条带模式)安装的 PVE 系统设计,使用其他安装模式时,请跳过此节。
2. `BTRFS` 文件系统当前仍为技术预览状态,请谨慎操作。
3. 有关在 PVE 中使用 `BTRFS` 的详情,请参阅 [Proxmox VE - BTRFS](https://pve.proxmox.com/wiki/BTRFS) 。
安装 PVE 时,若使用了 `BTRFS` 单盘 `RAID0` 的安装模式,系统默认未启用 swap 和 zstd 压缩,需要手动开启。
通常情况下,内存与 swap 的 **推荐** 比例为 `1:1` 。本机具有 `16GB` 内存,因此设置 `16GB` swap 空间。
执行以下命令,在 `BTRFS` 文件系统中创建子卷,并配置激活 swapfile 。
```bash
## 创建用于存放交换文件的子卷
$ btrfs subvolume create /swap
## 在子卷中创建 16GB 的交换文件
$ btrfs filesystem mkswapfile --size 16g --uuid clear /swap/swapfile
## 激活交换文件
$ swapon /swap/swapfile
```
此时还需进一步修改系统的 `fstab` 配置文件,以启用 `BTRFS` 的 zstd 压缩功能并确保 swap 在系统启动时自动激活。
```bash
## 编辑 fstab 配置文件
$ nvim /etc/fstab
```
`fstab` 为系统关键配置文件,直接影响系统启动,修改此文件时,请注意以下几点:
- 仅修改根目录 `/` 对应的挂载选项,添加 `compress=zstd` 参数。
- 在文件末尾新增一行,添加 swap 的自动挂载。
-**不要** 修改其余配置参数,尤其是设备的唯一标识符( `UUID` ),切勿修改。
修改完成后,示例如下。
```bash
#### 系统 fstab 示例配置
# <file system> <mount point> <type> <options> <dump> <pass>
UUID=<DO-NOT-EDIT-YOUR-UUID> / btrfs defaults,compress=zstd 0 1
UUID=<YOUR-UUID> /boot/efi vfat defaults 0 1
proc /proc proc defaults 0 0
/swap/swapfile none swap defaults 0 0
```
## 7.系统清理
PVE 系统配置完成后,可执行以下命令,对系统进行清理。
@@ -574,10 +639,10 @@ PVE 系统配置完成后,可执行以下命令,对系统进行清理。
$ apt clean && apt autoclean && apt autoremove --purge
## 清理系统缓存
$ rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ bash -c 'find /var/cache/apt/ /var/lib/apt/lists/ /tmp/ -type f -print -delete'
## 清理系统日志
$ find /var/log/ -type f | xargs rm -rvf
$ bash -c 'find /var/log/ -type f -print -delete'
## 清理命令历史记录文件
$ rm -rvf ~/.bash_history && history -c
+16 -8
View File
@@ -8,7 +8,7 @@
访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bookworm` 云镜像以及对应的校验文件。
![下载镜像](img/p04/download_generic_image_qcow2.jpg)
![下载镜像](img/p04/download_generic_image_qcow2.jpeg)
## 1.创建虚拟机
@@ -126,24 +126,32 @@ $ sha512sum debian-12-generic-amd64.qcow2
$ qm importdisk 1001 debian-12-generic-amd64.qcow2 local-lvm
#### 镜像导入示例输出
Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
unused0: successfully imported disk 'local-lvm:vm-1001-disk-0'
```
磁盘导入成功后,虚拟机硬件列表中将显示一块未使用的磁盘设备,可鼠标 **双击** 该设备进行配置调整。
![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg)
鼠标 **双击** 该未使用的磁盘,点击 `添加`
当宿主机使用 `SSD` 作为物理存储设备,并且虚拟磁盘采用 `精简置备` Thin Provisioning 模式时,可考虑开启以下选项:
- `丢弃` (Discard) 选项,有助于存储空间回收。
- `SSD仿真` SSD Emulation) 选项,让虚拟机将虚拟磁盘视为 `SSD` 存储设备。
在弹出的对话框中,确认 `IO thread` 选项为 **勾选** 状态,并点击 `添加`
![虚拟机使用该磁盘](img/p04/vm_enable_hd.jpeg)
导入的镜像只有 `2G` 磁盘空间,为了后续方便使用,需要对磁盘进行扩容。
导入的镜像只有 `3G` 磁盘空间,为了后续方便使用,需要对磁盘进行扩容。
鼠标 **单击** 选中该磁盘,选择页面顶部 `磁盘操作` 菜单的子菜单 `调整大小`
![虚拟机磁盘扩容](img/p04/vm_hd_resize.jpeg)
在弹出的对话框中,给该磁盘增加 `18G` 磁盘空间。
在弹出的对话框中,给该磁盘增加 `21G` 磁盘空间。
![虚拟机磁盘增加18G](img/p04/vm_hd_18g.jpeg)
![虚拟机磁盘增加18G](img/p04/vm_hd_scale_up.jpeg)
### 2.3.添加 CloudInit
@@ -203,7 +211,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
|--|--|--|
|用户|`fox`|新系统的管理员账户|
|密码|`********`|使用强密码|
|DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS域|`fox.internal`|内网域名(可选)|
|DNS服务器|`172.16.1.1`|本机 DNS 服务器|
|SSH公钥|`无`|使用秘钥登录服务器,暂不使用|
|Upgrade packages|`是`|启动时更新软件包,保持默认即可|
@@ -231,7 +239,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
|参数|值|说明|
|--|--|--|
|DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS域|`fox.internal`|内网域名(可选)|
|DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器|
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
+58 -53
View File
@@ -142,7 +142,7 @@ $ lsattr /etc/apt/sources.list.d/debian.sources
```bash
## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
$ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 更新软件源
$ sudo apt update
@@ -155,19 +155,42 @@ $ sudo apt full-upgrade
```bash
## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git btop tmux cron nftables sshguard neovim
$ sudo apt install qemu-guest-agent btop tmux logrotate cron neovim zsh git
## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils
$ sudo apt install nftables sshguard lsof knot-dnsutils
## 安装网络检测工具(可选)
$ sudo apt install iftop iperf3 iperf
## 写入磁盘
$ sudo sync
```
### 1.4.调整内核参数
### 1.4.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 使用清华大学镜像站安装 oh-my-zsh
$ cd && git clone --depth=1 https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git
$ cd ohmyzsh/tools && REMOTE=https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git sh install.sh
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
## oh-my-zsh 安装后清理
$ cd && rm -rvf ohmyzsh .bash_history .zsh_history .shell.pre-oh-my-zsh
```
### 1.5.调整内核参数
由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整内核参数来简单优化性能。
@@ -178,7 +201,7 @@ $ sudo sync
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
```
在配置文件末尾输入以下配置项,注意配置中间的空格。
在配置文件中添加以下配置项,注意配置中间的空格。
```bash
# This configuration file is customized by fox,
@@ -188,21 +211,26 @@ kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1
net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_max_syn_backlog = 512
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 4096 87380 26214400
net.ipv4.tcp_wmem = 4096 16384 655360
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
@@ -213,10 +241,10 @@ net.ipv6.conf.default.use_tempaddr = 0
```bash
## 让内核参数生效
$ sudo sysctl -f
$ sudo sysctl --system
```
### 1.5.调整系统时间
### 1.6.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
@@ -236,7 +264,7 @@ Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需
调整 NTP 服务器参数,执行以下命令。
```bash
## 创建 NTP 配置文件的目录
## 创建 NTP 配置目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件
@@ -250,14 +278,14 @@ $ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
# Optimize system NTP server.
[Time]
NTP=ntp.tencent.com ntp.aliyun.com
NTP=ntp.aliyun.com ntp.tencent.com cn.pool.ntp.org
```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
## 重启 systemd-timesyncd.service
$ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器
@@ -270,23 +298,23 @@ $ sudo systemctl status systemd-timesyncd.service
#### NTP 服务示例输出
● systemd-timesyncd.service - Network Time Synchronization
Loaded: loaded (/lib/systemd/system/systemd-timesyncd.service; enabled; preset: enabled)
Active: active (running) since Mon 2023-06-26 16:16:00 CST; 16s ago
Active: active (running) since Mon 2024-10-07 18:06:29 CST; 9s ago
Docs: man:systemd-timesyncd.service(8)
Main PID: 18829 (systemd-timesyn)
Status: "Contacted time server 106.55.184.199:123 (ntp.tencent.com)."
Tasks: 2 (limit: 2355)
Main PID: 1706 (systemd-timesyn)
Status: "Contacted time server 203.107.6.88:123 (ntp.aliyun.com)."
Tasks: 2 (limit: 2315)
Memory: 1.4M
CPU: 37ms
CPU: 113ms
CGroup: /system.slice/systemd-timesyncd.service
└─18829 /lib/systemd/systemd-timesyncd
└─1706 /lib/systemd/systemd-timesyncd
Jun 26 16:48:00 DNST01 systemd[1]: Starting systemd-timesyncd.service - Network Time Synchronization...
Jun 26 16:48:00 DNST01 systemd[1]: Started systemd-timesyncd.service - Network Time Synchronization.
Jun 26 16:48:00 DNST01 systemd-timesyncd[18829]: Contacted time server 106.55.184.199:123 (ntp.tencent.com).
Jun 26 16:48:00 DNST01 systemd-timesyncd[18829]: Initial clock synchronization to Mon 2023-06-26 16:16:16.000000 CST.
Oct 07 18:06:29 DNS01 systemd[1]: Starting systemd-timesyncd.service - Network Time Synchronization...
Oct 07 18:06:29 DNS01 systemd[1]: Started systemd-timesyncd.service - Network Time Synchronization.
Oct 07 18:06:29 DNS01 systemd-timesyncd[1706]: Contacted time server 203.107.6.88:123 (ntp.aliyun.com).
Oct 07 18:06:29 DNS01 systemd-timesyncd[1706]: Initial clock synchronization to Mon 2024-10-07 18:06:29.499548 CST.
```
### 1.6.配置自动更新
### 1.7.配置自动更新
配置 Debian 云镜像的系统自动更新,与配置 PVE 系统自动更新方法基本一致,参阅 [03.PVE系统调整](./03.PVE系统调整.md) 。
@@ -303,10 +331,8 @@ $ sudo systemctl status apt-daily-upgrade.timer
## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
## 选择 “是”
<Yes>
```
进一步调整 `20auto-upgrades` 配置文件。
@@ -393,7 +419,7 @@ $ sudo systemctl restart apt-daily-upgrade.timer
$ sudo systemctl status apt-daily-upgrade.timer
```
### 1.7.配置定时任务
### 1.8.配置定时任务
本步骤为可选操作,主要设置系统定时重启。
@@ -414,40 +440,19 @@ $ sudo crontab -e
```
### 1.8.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
### 1.9.清理系统
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
```bash
## 清理系统软件包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
$ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 清理系统缓存
$ sudo rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ sudo bash -c 'find /var/cache/apt/ /var/cache/smartdns/ /var/lib/apt/lists/ /tmp/ -type f -print -delete'
## 清理系统日志
$ sudo find /var/log/ -type f | xargs sudo rm -rvf
$ sudo bash -c 'find /var/log/ -type f -print -delete'
## 清理命令历史记录文件
$ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c
+107 -119
View File
@@ -65,7 +65,7 @@
`启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
`启动延时``10` ,表示该虚拟机在 PVE 启动后,延迟 `10`后自动启动
`启动延时``15` ,表示该虚拟机启动后,延迟 `15`再启动下一个虚拟机
![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg)
@@ -216,10 +216,10 @@ $ mkdir -p /tmp/SmartDNS
$ cd /tmp/SmartDNS
## 下载 SmartDNS 安装包
$ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release46/smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
$ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release46.1/smartdns.1.2025.03.02-1533.x86_64-linux-all.tar.gz
## 解压缩 SmartDNS 安装包
$ tar zxf smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
$ tar zxf smartdns.*.x86_64-linux-all.tar.gz
## 进入安装包目录
$ cd smartdns
@@ -248,7 +248,7 @@ $ sudo systemctl enable smartdns.service
若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。
```bash
## 创建 SmartDNS 配置文件目录
## 创建 SmartDNS 配置目录
$ sudo mkdir -p /etc/smartdns.d
## 下载广告规则配置文件
@@ -273,105 +273,7 @@ $ sudo chattr +i /opt/smartdns-plugin.sh
$ sudo bash /opt/smartdns-plugin.sh
```
### 6.2. SmartDNS 主配置
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
修改 `SmartDNS` 主配置文件之前,建议关闭 `SmartDNS` 并清理 DNS 缓存文件。
```bash
## 关闭 smartdns.service
$ sudo systemctl stop smartdns.service
## 清理缓存
$ sudo rm -rvf /var/cache/smartdns
## 清理进程标识文件
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
```
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 SmartDNS 主配置文件
$ sudo mv /etc/smartdns/smartdns.conf /etc/smartdns/smartdns.conf.bak
```
使用 `neovim` 编辑器创建 `SmartDNS` 主配置文件,执行以下命令。
```bash
## 创建 SmartDNS 主配置文件
$ sudo nvim /etc/smartdns/smartdns.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 由于修改了缓存路径,`SmartDNS` 的缓存将在系统重启时自动删除,请根据实际情况进行调整
- `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
- `edns-client-subnet` 为 EDNS 客户端子网,演示中 `202.103.24.68` 为湖北武汉市 DNS 服务器地址,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
```bash
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
#
# For use common DNS server as upstream DNS server,
# please modify 'server' parameter according to
# your network environment.
#
# eg:
# server 119.29.29.29
# server 223.5.5.5
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
cache-file /tmp/smartdns.cache
log-level notice
bind [::]:6053@lo
bind-tcp [::]:6053@lo
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
prefetch-domain yes
serve-expired-prefetch-time 21600
force-qtype-SOA 65
max-query-limit 1024
edns-client-subnet 202.103.24.68
server-tcp 119.29.29.29 -group dnspod -exclude-default-group
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
server-tcp 223.5.5.5 -group alidns -exclude-default-group
server-tcp 2400:3200::1 -group alidns -exclude-default-group
nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
server-tls dot.pub
server-tls dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
```
### 6.3.定时任务
### 6.2.定时任务
本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
@@ -401,20 +303,107 @@ $ sudo crontab -e
30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
```
### 6.4.配置 Dnsmasq
### 6.3. SmartDNS 主配置
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/)
修改 `SmartDNS` 主配置文件之前,建议关闭 `SmartDNS` 并清理 DNS 缓存文件。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
## 关闭 smartdns.service
$ sudo systemctl stop smartdns.service
## 清理进程标识文件
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
```
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 SmartDNS 主配置文件
$ sudo mv /etc/smartdns/smartdns.conf /etc/smartdns/smartdns.conf.bak
```
使用 `neovim` 编辑器创建 `SmartDNS` 主配置文件,执行以下命令。
```bash
## 创建 SmartDNS 主配置文件
$ sudo nvim /etc/smartdns/smartdns.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
```bash
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
#
# For use common DNS server as upstream DNS server,
# please modify 'server' parameter according to
# your network environment.
#
# eg:
# server 223.5.5.5
# server 180.184.1.1
# server 119.29.29.29
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
log-level notice
log-console yes
bind [::]:6053@lo
bind-tcp [::]:6053@lo
cache-size 32768
max-query-limit 1024
max-reply-ip-num 16
prefetch-domain yes
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
serve-expired-prefetch-time 28800
rr-ttl-min 60
rr-ttl-max 28800
rr-ttl-reply-max 14400
server-tcp 180.184.1.1 -bootstrap-dns
server-tcp 114.114.114.114 -bootstrap-dns
server-tcp 2400:3200::1 -bootstrap-dns
server-tls dot.pub
server-tls dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
```
### 6.4.配置 Dnsmasq
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令。
```bash
## 创建 Dnsmasq 配置目录
$ sudo mkdir -p /etc/dnsmasq.d
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
$ sudo nvim /etc/dnsmasq.d/10-server-dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
@@ -423,7 +412,7 @@ $ sudo nvim /etc/dnsmasq.conf
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- 配置文件中内网域名为 `fox.internal` ,请根据实际情况进行调整
- `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器
@@ -440,27 +429,28 @@ log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
max-cache-ttl=7200
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
interface=eth0
rebind-domain-ok=/fox.internal/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-negcache
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/
server=/lan/
server=/local/
@@ -470,10 +460,8 @@ server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=/fox.internal/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
```
+94 -66
View File
@@ -11,7 +11,7 @@
|参数|值|说明|
|--|--|--|
|虚拟机名称|`SVR01`| TS 服务器 `主机名` |
|DNS 域|`fox.home.arpa`| TS 服务器 `Cloud-Init` |
|DNS 域|`fox.internal`| TS 服务器 `Cloud-Init` |
|DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` |
|IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` |
@@ -113,7 +113,7 @@ $ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring
```bash
## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
$ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 更新软件源
$ sudo apt update
@@ -126,22 +126,45 @@ $ sudo apt full-upgrade
```bash
## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git btop tmux cron nftables sshguard neovim
$ sudo apt install qemu-guest-agent btop tmux logrotate cron neovim zsh git
## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils dnsmasq conntrack
$ sudo apt install dnsmasq conntrack nftables sshguard lsof knot-dnsutils
## 安装 TS
$ sudo apt install tailscale
## 安装网络检测工具(可选)
$ sudo apt install iftop iperf3 iperf
## 写入磁盘
$ sudo sync
```
### 1.4.调整内核模块
### 1.4.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 使用清华大学镜像站安装 oh-my-zsh
$ cd && git clone --depth=1 https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git
$ cd ohmyzsh/tools && REMOTE=https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git sh install.sh
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
## oh-my-zsh 安装后清理
$ cd && rm -rvf ohmyzsh .bash_history .zsh_history .shell.pre-oh-my-zsh
```
### 1.5.调整内核模块
使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。
@@ -160,7 +183,7 @@ nf_conntrack
```
### 1.5.调整内核参数
### 1.6.调整内核参数
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
@@ -169,7 +192,7 @@ nf_conntrack
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
```
在配置文件末尾输入以下配置项,注意配置中间的空格。
在配置文件中添加以下配置项,注意配置中间的空格。
```bash
# This configuration file is customized by fox,
@@ -178,7 +201,7 @@ $ sudo nvim /etc/sysctl.d/99-sysctl.conf
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = cake
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
@@ -192,6 +215,9 @@ net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
@@ -205,7 +231,8 @@ net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.igmp_max_memberships = 256
@@ -215,13 +242,15 @@ net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_adv_win_scale = -2
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv4.tcp_max_syn_backlog = 512
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 8192 262144 536870912
net.ipv4.tcp_wmem = 4096 16384 536870912
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
@@ -242,10 +271,10 @@ net.netfilter.nf_conntrack_tcp_timeout_established = 7440
```bash
## 让内核参数生效
$ sudo sysctl -f
$ sudo sysctl --system
```
### 1.6.调整系统时间
### 1.7.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
@@ -262,7 +291,7 @@ Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需
调整 NTP 服务器参数,执行以下命令。
```bash
## 创建 NTP 配置文件的目录
## 创建 NTP 配置目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件
@@ -276,21 +305,21 @@ $ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
# Optimize system NTP server.
[Time]
NTP=ntp.tencent.com ntp.aliyun.com
NTP=ntp.aliyun.com ntp.tencent.com cn.pool.ntp.org
```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
## 重启 systemd-timesyncd.service
$ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器
$ sudo systemctl status systemd-timesyncd.service
```
### 1.7.配置自动更新
### 1.8.配置自动更新
配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。
@@ -298,10 +327,8 @@ $ sudo systemctl status systemd-timesyncd.service
## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
## 选择 “是”
<Yes>
```
进一步调整 `20auto-upgrades` 配置文件。
@@ -357,7 +384,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
Unattended-Upgrade::Automatic-Reboot-Time "13:00";
```
@@ -375,7 +402,7 @@ $ sudo systemctl edit apt-daily-upgrade.timer
[Timer]
OnCalendar=
OnCalendar=02:00
OnCalendar=12:00
RandomizedDelaySec=0
```
@@ -392,7 +419,7 @@ $ sudo systemctl restart apt-daily-upgrade.timer
$ sudo systemctl status apt-daily-upgrade.timer
```
### 1.8.配置防火墙
### 1.9.配置防火墙
修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。
@@ -423,7 +450,7 @@ $ sudo nvim /etc/nftables.conf
$ sudo systemctl restart nftables.service
```
### 1.9.调整系统端口
### 1.10.调整系统端口
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
@@ -462,7 +489,7 @@ $ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
$ sudo systemctl restart systemd-resolved.service
```
### 1.10.配置 Dnsmasq
### 1.11.配置 Dnsmasq
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
@@ -474,18 +501,18 @@ $ sudo systemctl status dnsmasq.service
$ sudo systemctl enable dnsmasq.service
```
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令。
```bash
## 备份 Dnsmasq 配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
## 创建 Dnsmasq 配置目录
$ sudo mkdir -p /etc/dnsmasq.d
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
$ sudo nvim /etc/dnsmasq.d/10-server-dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
@@ -494,11 +521,11 @@ $ sudo nvim /etc/dnsmasq.conf
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- 配置文件中内网域名为 `fox.internal` ,请根据实际情况进行调整
- `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整
- `server=/ts.net/100.100.100.100` TS 服务 `MagicDNS` 专用 DNS 服务器
- `server=/fox.home.arpa/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
- `server=/fox.internal/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
- `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用
```bash
@@ -514,26 +541,28 @@ log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
max-cache-ttl=7200
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
interface=eth0,tailscale0
rebind-domain-ok=/fox.internal/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-round-robin
no-negcache
no-resolv
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/
server=/lan/
server=/local/
@@ -544,9 +573,7 @@ server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=/fox.internal/172.16.1.1
server=172.16.1.1
```
@@ -558,31 +585,12 @@ server=172.16.1.1
$ sudo systemctl restart dnsmasq.service
```
### 1.11.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
## 2.配置 Tailscale
## 2. Tailscale
根据不同的启动参数,TS 服务将具有不同的业务能力。
### 2.1.启动模式
若仅需 TS 组网功能,执行以下命令。
```bash
@@ -613,6 +621,8 @@ $ sudo tailscale up --advertise-exit-node --accept-routes --advertise-routes=172
执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。
### 2.2.自动更新
目前 TS 将跟随系统自动更新,若需额外开启 TS 的自动更新功能,执行以下命令。
```bash
@@ -623,5 +633,23 @@ $ sudo tailscale set --auto-update
$ sudo tailscale set --auto-update=false
```
### 2.3.定时任务
本步骤为可选操作,主要用于设置 TS 定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
30 10 * * * /usr/bin/systemctl restart tailscaled.service
```
至此,TS 服务器已配置完成。
+5 -5
View File
@@ -3,13 +3,13 @@
## 介绍
PVE 虚拟化平台的安装以及折腾手记。
- PVE ISO 版本:8.2-1 (更新时间: 2024-04-24)
- PVE ISO 版本:8.3-1 (更新时间: 2024-11-21)
- 演示机:
- CPU英特尔奔腾 Silver N6005 处理器
- 内存:16 GB
- 网卡:英特尔以太网控制器 I226-V
- 硬盘:500 GB NVMe 固态硬盘
- CPUN6005
- 内存:16GB DDR4
- 网卡:I226-V
- 硬盘:500GB NVMe
- PVE 网络:
- IPv4 网络
Binary file not shown.

Before

Width:  |  Height:  |  Size: 209 KiB

After

Width:  |  Height:  |  Size: 211 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 280 KiB

After

Width:  |  Height:  |  Size: 293 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 300 KiB

After

Width:  |  Height:  |  Size: 308 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 147 KiB

After

Width:  |  Height:  |  Size: 455 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 23 KiB

After

Width:  |  Height:  |  Size: 48 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 292 KiB

After

Width:  |  Height:  |  Size: 303 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 265 KiB

After

Width:  |  Height:  |  Size: 318 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 98 KiB

After

Width:  |  Height:  |  Size: 269 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 186 KiB

After

Width:  |  Height:  |  Size: 203 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 294 KiB

After

Width:  |  Height:  |  Size: 303 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 217 KiB

After

Width:  |  Height:  |  Size: 220 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 111 KiB

After

Width:  |  Height:  |  Size: 194 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 271 KiB

After

Width:  |  Height:  |  Size: 331 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 106 KiB

After

Width:  |  Height:  |  Size: 281 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 401 KiB

After

Width:  |  Height:  |  Size: 370 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 133 KiB

After

Width:  |  Height:  |  Size: 429 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 122 KiB

After

Width:  |  Height:  |  Size: 375 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 73 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 499 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 579 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 196 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 46 KiB

After

Width:  |  Height:  |  Size: 143 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 123 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 73 KiB

After

Width:  |  Height:  |  Size: 125 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

After

Width:  |  Height:  |  Size: 158 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 107 KiB

After

Width:  |  Height:  |  Size: 168 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 192 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 223 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 184 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 47 KiB

After

Width:  |  Height:  |  Size: 129 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 80 KiB

After

Width:  |  Height:  |  Size: 205 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

After

Width:  |  Height:  |  Size: 185 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 135 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 61 KiB

After

Width:  |  Height:  |  Size: 139 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 187 KiB

After

Width:  |  Height:  |  Size: 154 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

After

Width:  |  Height:  |  Size: 179 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 70 KiB

After

Width:  |  Height:  |  Size: 175 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 157 KiB

After

Width:  |  Height:  |  Size: 252 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 100 KiB

After

Width:  |  Height:  |  Size: 198 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

After

Width:  |  Height:  |  Size: 129 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 384 KiB

After

Width:  |  Height:  |  Size: 288 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 127 KiB

After

Width:  |  Height:  |  Size: 79 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 300 KiB

After

Width:  |  Height:  |  Size: 198 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 151 KiB

After

Width:  |  Height:  |  Size: 92 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 220 KiB

After

Width:  |  Height:  |  Size: 231 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 201 KiB

After

Width:  |  Height:  |  Size: 144 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 171 KiB

After

Width:  |  Height:  |  Size: 110 KiB

+8 -3
View File
@@ -5,21 +5,26 @@ kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1
net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_max_syn_backlog = 512
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 4096 87380 26214400
net.ipv4.tcp_wmem = 4096 16384 655360
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
+9 -10
View File
@@ -10,27 +10,28 @@ log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
max-cache-ttl=7200
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
interface=eth0
rebind-domain-ok=/fox.internal/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-negcache
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/
server=/lan/
server=/local/
@@ -40,8 +41,6 @@ server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=/fox.internal/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
+5 -5
View File
@@ -1,18 +1,18 @@
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/dnsmasq_plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
$ sudo curl -LR -o /opt/dnsmasq-plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/dnsmasq_plugin.sh
$ sudo chmod +x /opt/dnsmasq-plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/dnsmasq_plugin.sh
$ sudo chattr +i /opt/dnsmasq-plugin.sh
## 执行脚本
$ sudo bash /opt/dnsmasq_plugin.sh
$ sudo bash /opt/dnsmasq-plugin.sh
## 设置 crontab
25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf
35 9 * * * /usr/bin/bash /opt/dnsmasq_plugin.sh
35 9 * * * /usr/bin/bash /opt/dnsmasq-plugin.sh
+16 -20
View File
@@ -6,43 +6,39 @@
# your network environment.
#
# eg:
# server 119.29.29.29
# server 223.5.5.5
# server 180.184.1.1
# server 119.29.29.29
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
cache-file /tmp/smartdns.cache
log-level notice
log-console yes
bind [::]:6053@lo
bind-tcp [::]:6053@lo
cache-size 32768
max-query-limit 1024
max-reply-ip-num 16
prefetch-domain yes
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
prefetch-domain yes
serve-expired-prefetch-time 21600
serve-expired-prefetch-time 28800
force-qtype-SOA 65
max-query-limit 1024
edns-client-subnet 202.103.24.68
rr-ttl-min 60
rr-ttl-max 28800
rr-ttl-reply-max 14400
server-tcp 119.29.29.29 -group dnspod -exclude-default-group
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
server-tcp 223.5.5.5 -group alidns -exclude-default-group
server-tcp 2400:3200::1 -group alidns -exclude-default-group
nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
server-tcp 180.184.1.1 -bootstrap-dns
server-tcp 114.114.114.114 -bootstrap-dns
server-tcp 2400:3200::1 -bootstrap-dns
server-tls dot.pub
server-tls dns.alidns.com
+1 -1
View File
@@ -3,7 +3,7 @@ set -e
WORKDIR="$(mktemp -d)"
CONFDIR="/etc/smartdns.d"
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114)
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114 2402:4e00:: 2400:3200::1)
GROUP=(flash)
# Others: 223.6.6.6 119.28.28.28
# Not using best possible CDN pop: 1.2.4.8 210.2.4.8
+12 -6
View File
@@ -4,7 +4,7 @@
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = cake
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
@@ -18,6 +18,9 @@ net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
@@ -31,7 +34,8 @@ net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.igmp_max_memberships = 256
@@ -41,13 +45,15 @@ net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_adv_win_scale = -2
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv4.tcp_max_syn_backlog = 512
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 8192 262144 536870912
net.ipv4.tcp_wmem = 4096 16384 536870912
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
+10 -10
View File
@@ -10,26 +10,28 @@ log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
max-cache-ttl=7200
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
interface=eth0,tailscale0
rebind-domain-ok=/fox.internal/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-round-robin
no-negcache
no-resolv
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/
server=/lan/
server=/local/
@@ -40,8 +42,6 @@ server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=/fox.internal/172.16.1.1
server=172.16.1.1
+25 -59
View File
@@ -7,6 +7,7 @@ table inet router
flush table inet router
table inet router {
#
# Flowtable
#
@@ -26,17 +27,17 @@ table inet router {
type filter hook input priority filter; policy drop;
iif "lo" accept comment "defconf: accept traffic from loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows"
tcp flags syn / fin,syn,rst,ack counter jump syn_flood comment "defconf: rate limit TCP-SYN packets"
tcp flags & (fin | syn | rst | ack) == syn jump syn_flood comment "defconf: rate limit new TCP connections"
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
iifname "tailscale0" jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related flow add @ft comment "defconf: track forwarded flows"
ct state established,related flow add @ft;
ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows"
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
iifname "tailscale0" jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
}
chain output {
@@ -44,28 +45,22 @@ table inet router {
oif "lo" accept comment "defconf: accept traffic towards loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows"
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
chain prerouting {
type filter hook prerouting priority filter; policy accept;
iifname "eth0" jump helper_lan comment "defconf: handle LAN IPv4 / IPv6 helper assignment"
iifname "tailscale0" jump helper_tailscale comment "tsconf: handle TS IPv4 / IPv6 helper assignment"
oifname "tailscale0" jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
chain syn_flood {
limit rate 200/second burst 100 packets return comment "defconf: accept SYN packets below rate-limit"
counter drop comment "defconf: drop excess packets"
limit rate 50/second burst 100 packets return comment "defconf: accept new TCP connections below rate-limit"
counter drop comment "defconf: drop excess new TCP connections"
}
chain input_lan {
ct status dnat counter accept comment "lanconf: accept port redirect"
ct status dnat accept comment "lanconf: accept port redirect"
jump accept_from_lan
}
chain forward_lan {
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward"
ct status dnat counter accept comment "lanconf: accept port forward"
jump accept_to_tailscale comment "tsconf: accept LAN to TS forwarding"
ct status dnat accept comment "lanconf: accept port forwards"
jump accept_to_lan
}
@@ -73,17 +68,13 @@ table inet router {
jump accept_to_lan
}
chain helper_lan {
}
chain accept_from_lan {
iifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
iifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain accept_to_lan {
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv4 leakage"
meta nfproto ipv6 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv6 leakage"
oifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent LAN NATv4 leakage"
oifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain input_tailscale {
@@ -91,23 +82,22 @@ table inet router {
}
chain forward_tailscale {
counter jump accept_to_lan comment "tsconf: accept TS to LAN forward"
counter jump accept_to_tailscale
jump accept_to_lan comment "tsconf: accept TS to LAN forwarding"
jump accept_to_tailscale
}
chain output_tailscale {
counter jump accept_to_tailscale
}
chain helper_tailscale {
jump accept_to_tailscale
}
chain accept_from_tailscale {
iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
meta nfproto ipv4 iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 traffic"
meta nfproto ipv6 iifname "tailscale0" counter accept comment "tsconf: accept TS IPv6 traffic"
}
chain accept_to_tailscale {
oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
meta nfproto ipv4 oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 traffic"
meta nfproto ipv6 oifname "tailscale0" counter accept comment "tsconf: accept TS IPv6 traffic"
}
@@ -117,7 +107,7 @@ table inet router {
chain dstnat {
type nat hook prerouting priority dstnat; policy accept;
iifname "eth0" meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic"
iifname { "eth0", "tailscale0" } meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic"
}
chain srcnat {
@@ -131,21 +121,7 @@ table inet router {
}
chain srcnat_lan {
meta nfproto ipv4 counter masquerade comment "defconf: masquerade IPv4 LAN traffic"
meta nfproto ipv6 counter masquerade comment "defconf: masquerade IPv6 LAN traffic"
}
#
# Raw rules (notrack)
#
chain raw_prerouting {
type filter hook prerouting priority raw; policy accept;
}
chain raw_output {
type filter hook output priority raw; policy accept;
meta nfproto ipv4 counter masquerade comment "defconf: masquerade LAN IPv4 traffic"
}
@@ -153,24 +129,14 @@ table inet router {
# Mangle rules
#
chain mangle_prerouting {
type filter hook prerouting priority mangle; policy accept;
}
chain mangle_postrouting {
type filter hook postrouting priority mangle; policy accept;
}
chain mangle_input {
type filter hook input priority mangle; policy accept;
}
chain mangle_output {
type route hook output priority mangle; policy accept;
oifname "eth0" tcp flags syn / fin,syn,rst tcp option maxseg size set rt mtu comment "defconf: zone LAN IPv4 / IPv6 egress MTU fixing"
}
chain mangle_forward {
type filter hook forward priority mangle; policy accept;
iifname "eth0" tcp flags syn / fin,syn,rst tcp option maxseg size set rt mtu comment "defconf: zone LAN IPv4 / IPv6 ingress MTU fixing"
}
}