安装 Clash Verge Rev
安装 Docker(仅在 Windows 环境下)
-
下载 Docker:
- 访问 Docker 官方网站。
- 根据操作系统下载相应的 Docker 安装包。
- 安装完成后,确保 Docker 服务正常运行。
-
拉取镜像:
- 打开终端,执行命令:
docker pull clashverge/rev
- 这将下载并安装 Clash Verge Rev 的最新版本。
- 打开终端,执行命令:
-
启动 Docker 容器:
- 运行以下命令启动 Clash Verge Rev:
docker run -it --rm -p 808:808 clashverge/rev
-it使你进入交互式模式,-rm在容器退出后自动删除,-p 808:808将本地 808 端口映射到容器内。
- 运行以下命令启动 Clash Verge Rev:
从源码编译(推荐)
-
克隆仓库:
- 使用 Git 克隆仓库:
git clone https://github.com/clashverge/rev.git
- 进入仓库目录:
cd rev
- 使用 Git 克隆仓库:
-
安装依赖:
- 查看并安装所有依赖项:
make install
- 查看并安装所有依赖项:
-
编译:
- 编译源码:
make
- 编译源码:
-
运行:
- 运行可执行文件:
./rev
- 默认情况下,会启动一个交互式界面,或者你可以使用命令行工具进行操作。
- 运行可执行文件:
配置防火墙策略
创建防火墙规则
-
新建配置文件:
- 打开文本编辑器,创建一个新的 JSON 配置文件,
firewall.json。
- 打开文本编辑器,创建一个新的 JSON 配置文件,
-
定义规则:
- 根据需要定义防火墙规则,以下是一个示例:
{ "firewall": { "name": "允许HTTP和HTTPS", "rules": [ { "outgoing": { "name": "允许HTTP", "destination": "A", "ports": ["80"], "protocol": "tcp" } }, { "outgoing": { "name": "允许HTTPS", "destination": "A", "ports": ["443"], "protocol": "tcp" } } ] } }- 解释:
name:规则名称。outgoing:定义出站规则。destination:目标网络(如 IP 地址或子网)。ports:指定端口。protocol:协议(如 tcp, udp)。
-
保存配置文件:
- 将 JSON 配置保存为
firewall.json。
- 将 JSON 配置保存为
应用防火墙规则
-
启动 Clash Verge Rev:
- 如果是从源码编译,运行:
./rev -c firewall.json
- 如果是用 Docker,进入容器:
docker exec -it clashverge/rev ./rev -c firewall.json
- 如果是从源码编译,运行:
-
验证防火墙状态:
- 使用以下命令查看防火墙状态:
./rev -L
- 查看防火墙规则是否生效。
- 使用以下命令查看防火墙状态:
部署 Guard 模块
创建 Guard 策略
-
新建策略文件:
- 创建一个新的 JSON 文件,
allow.json。
{ "guard": { "name": "允许访问服务器A", "rules": [ { "inbound": { "source": ".../", "destination": "A", "ports": ["80", "443"], "protocol": "tcp" } } ] } } - 创建一个新的 JSON 文件,
-
部署 Guard 模块:
- 启动 Guard:
./rev -g deploy
- 部署完成后,查看 Guard 状态:
./rev -g status
- 启动 Guard:
处理网络协议
解析协议
-
创建协议模型:
- 使用 Model 模块定义协议结构,创建一个
http.json文件定义 HTTP 协议。
{ "model": { "http": { "version": "1.1", "methods": { "GET": { "path": "/", "methods": ["GET"] } } } } } - 使用 Model 模块定义协议结构,创建一个
-
编译协议模型:
- 编译模型:
./rev -m compile
- 查看模型状态:
./rev -m list
- 编译模型:
处理 HTTP 请求
-
创建解析器:
- 编写一个解析器来处理 HTTP 请求,创建
http_handler.js:
const http = require('http'); const model = require('../model/http'); const server = http.createServer((req, res) => { // 处理 HTTP 请求 const method = req.method; const path = req.url; // 根据协议模型处理请求 model.http[method](path, req, res, (next) => { // 定义请求处理逻辑 res.statusCode = 200; res.end('Hello, World!'); }); }); server.listen(808, () => { console.log('服务器正在监听 port 808'); }); - 编写一个解析器来处理 HTTP 请求,创建
-
运行解析器:
- 将解析器部署到 Clash Verge Rev 中:
./rev -p 808 deploy http_handler.js
- 将解析器部署到 Clash Verge Rev 中:
安全防护
入侵检测系统
-
配置规则:
- 定义入侵检测规则,阻止未经授权的访问。
{ "firewall": { "name": "入侵检测", "rules": [ { "outgoing": { "name": "阻止未经授权访问", "destination": ".../", "ports": ["*"], "protocol": "tcp", "state": "new", "action": "block" } } ] } } -
更新防火墙策略:
- 应用新的规则:
./rev -c firewall.json
- 应用新的规则:
日志记录
-
配置日志策略:
- 在防火墙规则中添加日志记录项:
{ "firewall": { "name": "日志记录", "rules": [ { "outgoing": { "name": "记录所有出站流量", "destination": ".../", "ports": ["*"], "protocol": "tcp", "action": "allow", "log": { "prefix": "out", "level": "debug" } } } ] } }
- 在防火墙规则中添加日志记录项:
-
查看日志:
- 查看防火墙日志:
./rev -L firewall.json
- 查看防火墙日志:
测试与验证
使用测试工具
-
测试防火墙规则:
- 使用
nc或curl等工具测试防火墙规则是否生效。
nc -zv 192.168.1.1 80
- 使用
-
测试协议处理:
- 发送 HTTP 请求:
curl http://192.168.1.1:808
- 发送 HTTP 请求:
验证入侵检测
-
模拟攻击:
尝试访问未被允许的端口或地址,观察防火墙是否阻止了攻击。
-
查看防火墙状态:
- 查看当前防火墙规则和状态:
./rev -L
- 查看当前防火墙规则和状态:
优化与扩展
调整配置参数
- 优化性能:
调整防火









