VPN Awesome
约 3 分钟阅读
标签:资源精选
- 组网场景
- 基础设施组网 - 例如 Kubernetes 混合云
- tinc, n2n, ipsec
- 用户组网 - 例如 公司员工接入
- nebula, wireguard, innernet, ipsec
- 服务组网 - 例如 游戏,VoIP
- n2n, tinc
- 基础设施组网 - 例如 Kubernetes 混合云
- Mesh 网络模式
- L3 - TCP/IP - tun,utun 设备
- Mesh 有 IPAM 功能或预先手动分配好 IP
- 不支持 DHCP 等 L2 层协议
- 偏向用户层
- L2 - Ethernet - tap 设备
- 功能更加通用,但一般移动设备接入不支持作为 Mesh 节点
- 偏向基础设施层
- 支持作为桥接、支持更灵活的组网
- 目前 macOS 无法支持 tap 设备
- L3 - TCP/IP - tun,utun 设备
- Wireguard Awesome笔记WireGuard Awesome值得关注 Wiretrustee · 目前只有 Tailscale 的 移动端支持 Mesh · Vanilla WireGuard · wireguard-go · MIT, Golang · Go 实现 wg · wireguard-apple打开:/notes/service/network/vpn/wireguard/awesome
- Proxy Awesome笔记Proxy AwesomeNote · 建议基于 overlay 组件内部 proxy,更安全,更好跨网。 · 对外暴露甚至选择 · | protocol | transport | UDP | Note | · | socks4 | tcp | ❌ | · | socks5 | tcp | ✅ |打开:/notes/service/network/proxy/awesome
| Protocol | Port | Usage |
|---|---|---|
| PPTP | 47/GRE, 1723/TCP | PPTP data path |
| L2TP/IKEv2 (ESP) | 50 | IPSec data path |
| OpenVPN | 443/TCP, 1194/UDP | OpenVPN connections |
| SSTP/SSL (TCP) | 443 | SSTP control and data path |
| L2TP | 500/UDP, 1701/TCP, 4500/UDP | L2TP (IPSec control path) |
| IKEv2 (UDP) | 500, 4500 | IKEv2 (IPSec control path) |
| WireGuard (UDP) | 51820 | Incoming connections |
Awesome
- octelium/octeliumGitHuboctelium/octelium
- AGPL-3.0, Apache-2.0, Go
VPN/私有网络
- VPN/私有网络 指整个网络纬度, 区分 L2, L3
功能
| vs. | License | protocol | TUN/TAP | relay | P2P | mesh | NAT | policy |
|---|---|---|---|---|---|---|---|---|
| tinc笔记Tincgsliepen/tinc 是什么? · GPLv2+, C · 2 层、3 层 NAT 穿透直连组网的 Mesh VPN · 加密、认证、压缩 · 自动全 Mesh 路由 · NAT 穿透 · bridge ethernet segments打开:/notes/service/network/vpn/tinc | GPLv2 | UDP/TCP | ✅/✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| n2n | GPLv3 | UDP | ❌/✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| nebula笔记nebulaslackhq/nebula 是什么? · MIT, Go · P2P overlay 网络 - 类似 Tinc · Layer 3 - IP 层 - 不支持 MAC - 预先配置网络 · 注重性能和简洁 · 支持 iOS 和 Android - DefinedNet/mobilenebula打开:/notes/service/network/vpn/nebula | MIT | UDP/Noise | ✅/❌ | ❌ | ✅ | ✅ | ✅ | ✅ |
| zerotier笔记Zerotierzerotier/ZeroTierOne · BSL, C++ · 中心化 P2P Mesh VPN · 2 层 网络 · 支持授权管理 · 支持 地址 配置 · 支持路由下发 · 依赖官方 root 服务器 · Manual · Router Configuration Tips打开:/notes/service/network/vpn/zerotier | BSL | UDP | ❌/✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| wireguard | GPL | UDP/Noise | ✅/❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
平台
| vs. | android/ios | windows/macos/linux |
|---|---|---|
| wireguard | ✅/✅ | ✅/✅/✅ |
| zerotier笔记Zerotierzerotier/ZeroTierOne · BSL, C++ · 中心化 P2P Mesh VPN · 2 层 网络 · 支持授权管理 · 支持 地址 配置 · 支持路由下发 · 依赖官方 root 服务器 · Manual · Router Configuration Tips打开:/notes/service/network/vpn/zerotier | 🔴/🔴 | ✅/✅/✅ |
| nebula笔记nebulaslackhq/nebula 是什么? · MIT, Go · P2P overlay 网络 - 类似 Tinc · Layer 3 - IP 层 - 不支持 MAC - 预先配置网络 · 注重性能和简洁 · 支持 iOS 和 Android - DefinedNet/mobilenebula打开:/notes/service/network/vpn/nebula | ✅/✅ | ✅/✅/✅ |
| tinc笔记Tincgsliepen/tinc 是什么? · GPLv2+, C · 2 层、3 层 NAT 穿透直连组网的 Mesh VPN · 加密、认证、压缩 · 自动全 Mesh 路由 · NAT 穿透 · bridge ethernet segments打开:/notes/service/network/vpn/tinc | 🟠/🟠 | ✅/🟡/✅ |
| n2n | ✅/🟡 | ✅/🟡/✅ |
| legend | for |
|---|---|
| ✅ | Yes |
| ❌ | No |
| 🟡 | Partial |
| 🟠 | Maybe |
| 🔴 | Close source |
- tinc笔记Tincgsliepen/tinc 是什么? · GPLv2+, C · 2 层、3 层 NAT 穿透直连组网的 Mesh VPN · 加密、认证、压缩 · 自动全 Mesh 路由 · NAT 穿透 · bridge ethernet segments打开:/notes/service/network/vpn/tinc
- gsliepen/tincGitHubgsliepen/tincgsliepen/tinc 是什么? · GPLv2+, C · 2 层、3 层 NAT 穿透直连组网的 Mesh VPN · 加密、认证、压缩 · 自动全 Mesh 路由 · NAT 穿透 · bridge ethernet segments笔记:Tinc
- n2n
- android switch-iot/hin2nGitHubswitch-iot/hin2n
- ios Oliver0624/hin2n-iosGitHubOliver0624/hin2n-ios
- nebula笔记nebulaslackhq/nebula 是什么? · MIT, Go · P2P overlay 网络 - 类似 Tinc · Layer 3 - IP 层 - 不支持 MAC - 预先配置网络 · 注重性能和简洁 · 支持 iOS 和 Android - DefinedNet/mobilenebula打开:/notes/service/network/vpn/nebula
- MIT, Go
- 基于 Noise 协议, WG 底层协议
- zerotier笔记Zerotierzerotier/ZeroTierOne · BSL, C++ · 中心化 P2P Mesh VPN · 2 层 网络 · 支持授权管理 · 支持 地址 配置 · 支持路由下发 · 依赖官方 root 服务器 · Manual · Router Configuration Tips打开:/notes/service/network/vpn/zerotier
- BSL, C++
- 默认基于官方 controller, 可以 selfhost 但还是会用到官方的节点进行传播
- 连接稳定性一般, 使用 官方 controller 免费最多 100 节点
- relay over moon
- dswd/vpncloudGitHubdswd/vpncloud
- P2P VPN
- vs. Tinc, Nebula, OpenVPN, WG
- hwdsl2/setup-ipsec-vpnGitHubhwdsl2/setup-ipsec-vpnLibreswan · strongSwan · Openswan · Arch Linux Wiki: StrongSwan · setup-ipsec-vpn · Debian Wiki: IPsec · Alpine Package: ipsec-tools笔记:IPsec
- How adsl Works
- proxysu/ProxySUGitHubproxysu/ProxySU
- anderspitman/awesome-tunnelingGitHubanderspitman/awesome-tunneling
- userspace
- TunSafe/TunSafeGitHubTunSafe/TunSafe
- cjdelisle/cjdnsGitHubcjdelisle/cjdns
- GPLv3, C+Python
- encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for routing
- 提供 Zero-Configuration Networking
- windows
- tap-windows
- wintun
- yggdrasil-network/yggdrasil-goGitHubyggdrasil-network/yggdrasil-go
- routing as an encrypted IPv6 overlay network
- pojntfx/weronGitHubpojntfx/weron
- AGPL-3.0, Golang
- P2P VPN over WebRTC
- qdm12/gluetunGitHubqdm12/gluetun
- MIT, Go
- VPN to HTTP/Socks Proxy
- VPN client in a thin Docker container for multiple VPN providers, written in Go, and using OpenVPN or Wireguard, DNS over TLS, with a few proxy servers built-in.
- 支持 AirVPN, Cyberghost, ExpressVPN, FastestVPN, Giganews, HideMyAss, IPVanish, IVPN, Mullvad, NordVPN, Perfect Privacy, Privado, Private Internet Access, PrivateVPN, ProtonVPN, PureVPN, SlickVPN, Surfshark, TorGuard, VPNSecure.me, VPNUnlimited, Vyprvpn, WeVPN, Windscribe
- 支持 OpenVPN
- 支持 Wireguard
- ooni/minivpnGitHubooni/minivpn
- GPLv3, Go
- minimalistic OpenVPN implementation in Go
- EasyTier/EasytierGitHubEasyTier/Easytier
- LGPLv3, Rust, Tokio, Vue
- WireGuard, Mesh VPN
- 国人维护
Tunnel/通道
Tunnel/通道 指连接、端口纬度, 区分协议协议类型
- rtctunnel/rtctunnelGitHubrtctunnel/rtctunnel
tunnels over WebRTC
- MIT, Go
- fatedier/frpGitHubfatedier/frpfatedier/frp 是什么? · 基于端口的 4 层反向代理 · 基于 vhost 的 7 层反向代理 · 服务端支持 http, tcp, udp, kcp · 服务端支持 ws 暴露 - TCP over Websocket · 代理支持 tcp,udp,http,https,stcp,xtcp笔记:FRP
- Apache-2.0, Go
- rapiz1/ratholeGitHubrapiz1/rathole
- Apache-2.0, Rust
- stunnel
- ehang-io/npsGitHubehang-io/npsehang-io/nps 是什么? · GPL · 内网穿透代理服务 · 类似 frp (Apache 2.0) - 管理界面和功能相对更加完善 · 目前开发停滞,转向闭源收费笔记:nps
- GPL-3, Go
- 转向闭源收费, 开源开发停滞
- slirp
- ghostunnel/ghostunnelGitHubghostunnel/ghostunnel
- Apache-2.0, Go
- SSL/TLS proxy with mTLS for securing non-TLS backend applications.
- ptunnel
- tunnel over icmp
Tunnel Library
- jpillora/chiselGitHubjpillora/chisel
- rancher/remotedialerGitHubrancher/remotedialerrancher/remotedialer · 使用 websocket 建立通道 · tcp over websocket · 内部会管理多个客户端 · 通过通道进行 - 相当于通过远程进行调用 · Adopter · k3s, rancher笔记:remotedialer
- inlets
流控/防火墙
- OpenClash
- Passwall
- Surge
- adg+passw+smart
Provider
- nordvpn
- wirdguard
- openvpn
- expressvpn
- openvpn
- Surfshark
- socks5
- ProxyEmpire
- BeeProxy
关联信息
反向链接和本文引用的外部资料。
反向链接
- Network Awesome笔记 · VPN Awesome
VPN Awesome · Proxy Awesome · cjdelisle/cjdns · GPLv3, C+Python · encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for ro...
- VPN笔记 · Awesome
Awesome · FAQ
References
GitHub
22 条- anderspitman/awesome-tunnelinggithub.com/anderspitman/awesome-tunneling
- cjdelisle/cjdnsgithub.com/cjdelisle/cjdns
- dswd/vpncloudgithub.com/dswd/vpncloud
- EasyTier/Easytiergithub.com/EasyTier/Easytier
- ehang-io/npsgithub.com/ehang-io/nps
- fatedier/frpgithub.com/fatedier/frp
- ghostunnel/ghostunnelgithub.com/ghostunnel/ghostunnel
- gsliepen/tincgithub.com/gsliepen/tinc
另有 14 个未显示 references。
其他外链
5 条- kitz.co.uk/adsl/equip.htmkitz.co.uk/adsl/equip.htm
- vpncloud.ddswd.de/features/comparisonvpncloud.ddswd.de/features/comparison
- www.cs.uit.no/~daniels/PingTunnelwww.cs.uit.no/~daniels/PingTunnel
- www.ivpn.net/knowledgebase/troubleshooting/how-do-i-change-the-port-or-protocol-used-to-connectwww.ivpn.net/knowledgebase/troubleshooting/how-do-i-change-the-port-or-protocol-used-to-connect
- www.stunnel.orgwww.stunnel.org/
另有 14 个 references 未显示。