WireGuard 配置

Chute 支持 WireGuard 作为出站代理协议。你可以在 [Proxy] 段中内联配置 WireGuard,也可以定义一个命名的 [WireGuard] 段并引用它。

WireGuard 段

[WireGuard] 段定义了一个完整的 WireGuard 隧道配置,可以通过名称从 WireGuard 代理服务器中引用。

[WireGuard wg0]
private-key = base64_private_key
peer-public-key = base64_peer_public_key
self-ip = 10.0.0.2
self-ip-v6 = fd00::2
preshared-key = base64_preshared_key
server = example.com
port = 51820
wg-mtu = 1420
keepalive = 25

参数

键 必填 描述
private-key 是 WireGuard 私钥,base64 编码
peer-public-key 是 对等公钥,base64 编码
self-ip 否 WireGuard 接口的本地 IPv4 地址(默认 10.0.0.2,WireGuard 与 AmneziaWG 均是)
self-ip-v6 否 WireGuard 接口的本地 IPv6 地址
preshared-key 否 用于抵御量子计算攻击的预共享密钥
server 是* 远程服务器地址(当代理行未指定时使用;代理行优先)
port 是* 远程服务器端口(优先级与 server 相同)
wg-mtu 否 WireGuard 接口的 MTU(默认:1420)。段内的 mtu 会被读作 wg-mtu;显式写出的 wg-mtu 优先
keepalive 否 持久保活间隔(秒)。不写则不发送保活
allowed-ips 否 该对等节点承载的目的地址,逗号分隔的 CIDR(例如 allowed-ips = 10.0.0.0/8, 192.168.1.0/24)。去往范围之外地址的连接会被拒绝(TCP)或丢弃(UDP)。不写,或同时列出 0.0.0.0/0 与 ::/0,表示所有目的地址;不是 CIDR 的条目会被忽略并记一条警告
reserved 否 WireGuard 握手头部的保留字节(例如 reserved=0,1,2)——会被解析,但当前引擎不会应用,并记录一条警告

* server 和 port 必须出现在该段或引用它的 [Proxy] 行中;否则该策略会因不完整而被拒绝。

Surge 的 peer 写法

段也可以按 Surge 的方式描述对等节点:

[WireGuard wg0]
private-key = base64_private_key
self-ip = 10.0.0.2
mtu = 1280
peer = (public-key = base64_peer_public_key, endpoint = example.com:51820, preshared-key = base64_preshared_key, keepalive = 25, client-id = 1/2/3, allowed-ips = "0.0.0.0/0, ::/0")
  • public-key 变为 peer-public-key,endpoint(host:port,或 [v6]:port)变为 server 与 port,client-id = a/b/c 变为 reserved,preshared-key 和 keepalive 名称不变。直接写在段中的键优先于 peer 中的同一项。当前引擎会解析 reserved,但不会应用它。
  • 只使用一个对等节点;第二个对等节点会以提示(advisory)报告并被忽略。
  • allowed-ips 会被编译,并对 WireGuard 的 TCP 与 UDP 强制生效:目标地址不在对等节点 CIDR 范围内时会被拒绝或丢弃,因为该对等节点无法把它路由回来。Surge 的段内键 dns-server 和 prefer-ipv6 仍会保留但不起作用,并出现在被忽略选项的提示中。
  • 保存配置时,该段会用上述键写回,而不再是 peer = (…) 这一行。

用法

从代理服务器中引用该段:

[Proxy]
WG = wireguard, section-name=wg0

[Proxy Group]
WGGroup = select, WG

[Rule]
IP-CIDR,10.0.0.0/8,WGGroup
FINAL,DIRECT

可以定义多个 [WireGuard] 段用于不同隧道:

[WireGuard us]
private-key = ...
peer-public-key = ...
self-ip = 10.0.1.2

[WireGuard eu]
private-key = ...
peer-public-key = ...
self-ip = 10.0.2.2

注意:WireGuard 运行在自身的 UDP 隧道上,并使用用户态 TCP/IP 协议栈。名称(例如 wg0)区分大小写。

AmneziaWG 段

Chute 还支持 AmneziaWG,一种带流量混淆的 WireGuard 变体。[AmneziaWG <name>] 段接受与 [WireGuard] 段相同的键,外加以下混淆参数:

  • jc、jmin、jmax —— 垃圾包数量及大小范围。jc 大于零时,jmin 与 jmax 都必须设置,且 jmax 不得小于 jmin,否则隧道将被拒绝建立。
  • s1、s2、s3、s4 —— 在 init/response/cookie/transport 包前添加的垃圾数据。s1–s3 不得超过 64 字节(s4 为 32),且 s1 + 148 必须不等于 s2 + 92,否则隧道将被拒绝建立。
  • h1、h2、h3、h4 —— 自定义消息类型头部值。每个都是十进制数或 32 位以内的 start-end 范围,且必须大于 4,因为 1–4 是 WireGuard 自己的消息类型;四个值不能重叠,否则隧道会被拒绝。
  • i1、i2、i3、i4、i5 —— 特殊垃圾包定义。无法解析的定义会使隧道被拒绝。

被拒绝的参数组合会在日志里记为 WireGuard: AmneziaWG parameters rejected: <原因>,随后隧道以 Failed to create BoringTun tunnel 失败。

策略通过类型 amneziawg(别名 awg)引用该段:

[AmneziaWG awg0]
private-key = base64_private_key
peer-public-key = base64_peer_public_key
self-ip = 10.0.0.2
server = example.com
port = 51820
jc = 4
jmin = 40
jmax = 70
s1 = 15
s2 = 60
h1 = 123456
h2 = 67543
h3 = 32345
h4 = 123123

[Proxy]
AWG = amneziawg, section-name=awg0

交叉校验规则:

  • 在普通 [WireGuard] 段中使用 AmneziaWG 参数属于配置错误——请改用 [AmneziaWG] 段。
  • reserved 不能在 [AmneziaWG] 段中使用:它写入的头部字节与 h4 替换的字节相同,因此这种组合会被作为错误拒绝。
  • 不含任何混淆参数的 [AmneziaWG] 段会得到一条提示——它的行为与普通 WireGuard 相同。
S. Smart Rabbit LLC © All Rights Reserved            updated 2026-09-29 21:57:05

本页为英文版的翻译。如内容有出入,以英文版为准。

results matching ""

    No results matching ""