Skip to content

WireGuard — mihomo ​

mihomo 的 WireGuard 出站在用户态运行,IP 栈可选(gVisor,或 mihomo 自带的 mips 栈 —— 见 ip-stack)。schema 同时提供简化的单 peer 形态(peer 字段位于代理根部)与通过 peers: 的完整多 peer 形态。可选的 amnezia-wg-option 块用于与 AmneziaWG 风格的服务器互通。

出站 ​

proxies: 下 type: wireguard 条目。内嵌 BasicOption,并组合 WireGuardPeerOption 的简化 peer 字段。

字段类型默认值允许值描述
namestring(required)<string>唯一的代理名。
ipstring(unset)<IPv4 CIDR>本地隧道 IPv4 地址(如 10.0.0.2/32)。
ipv6string(unset)<IPv6 CIDR>本地隧道 IPv6 地址。
private-keystring(required)<base64 key>本地私钥。
workersint(CPU-based)<int>加密管线 worker 数。
mtuint1408<bytes>隧道 MTU。
udpboolfalsetrue | false启用 UDP 转发。
persistent-keepaliveint0<seconds>persistent-keepalive 间隔。0 表示禁用。
ip-stackIPStackOption(auto)IPStackOption承载隧道 TCP/UDP 流量的用户态 IP 栈。见下方 ip-stack 表。
amnezia-wg-option*AmneziaWGOption(unset)AmneziaWGOptionAmneziaWG 混淆参数(junk 包、头部掩码)。
peers[]WireGuardPeerOption(use simplified shape)[WireGuardPeerOption]完整的多 peer 列表。设置后内嵌的简化字段被忽略。
remote-dns-resolveboolfalsetrue | false使用 peer 的解析器在 WireGuard 隧道内解析 DNS。
dns[]string[][<DNS server>]remote-dns-resolve 为 true 时隧道内使用的解析器。
refresh-server-ip-intervalint0<seconds>每 N 秒重新解析 peer 主机名。0 禁用周期性重解析。

源码: adapter/outbound/wireguard.go:69-91 · 锚定版本 v1.19.31 (ab405ba)

peers[] —— 多 peer 形态 ​

字段类型默认值允许值描述
serverstring(required)<host>peer 主机名或 IP。
portint(required)<port>peer UDP 端口。
public-keystring(required)<base64 key>peer 公钥。
pre-shared-keystring(unset)<base64 key>可选 PSK。
reserved[]uint8(empty)<3 bytes>3 字节 reserved 字段覆盖。
allowed-ips[]string[][<CIDR>]该 peer 的 Allowed-IPs。

源码: adapter/outbound/wireguard.go:93-100 · 锚定版本 v1.19.31 (ab405ba)

ip-stack ​

字段类型默认值允许值描述
modestringautoauto | gvisor | mipsgvisor 使用 gVisor 网络栈(仅在带 with_gvisor 构建标签的版本中可用,否则启动失败);mips 使用 mihomo 自带的 IP 栈(MIPS 即 mihomo IP stack,与 CPU 架构无关);auto 在编译了 gVisor 时选用它,否则选 mips。
congestion-controllerstring(stack default)cubic | reno | bbr | bbr3mips 栈的 TCP 拥塞控制算法。gVisor 忽略此项。其他取值在启动时被拒绝。

源码: adapter/outbound/wireguard.go:143-146 · 锚定版本 v1.19.31 (ab405ba)

amnezia-wg-option ​

字段类型默认值允许值描述
versionint03 | <other>实现选择器。3 切换到 AmneziaWG v3 实现(下方 v3 专属字段必需);其他任何值(含未设置)使用旧版 v1.x/v2 实现。
jcint0<int>每次握手的 junk 包数量。
jminint0<bytes>junk 包最小尺寸。
jmaxint0<bytes>junk 包最大尺寸。
s1int0<bytes>init 包前的 padding 长度。
s2int0<bytes>response 包前的 padding 长度。
s3int0<bytes>AmneziaWG v1.5+ —— cookie 包前的 padding 长度。
s4int0<bytes>AmneziaWG v1.5+ —— data 包前的 padding 长度。
h1string(unset)<uint32> | <min-max>init 包的 header magic。仅十进制 —— v1.x 为单个 uint32;v2+ 还接受 min-max 区间。
h2string(unset)<uint32> | <min-max>response 包的 header magic。格式同 h1。
h3string(unset)<uint32> | <min-max>cookie 包的 header magic。格式同 h1。
h4string(unset)<uint32> | <min-max>data 包的 header magic。格式同 h1。
i1string(unset)<tag chain>AmneziaWG v1.5+ —— 特殊包 1,以标签链书写,例如 <b 0xf6ab3267fa><r 100>。
i2string(unset)<tag chain>特殊包 2(格式同 i1)。
i3string(unset)<tag chain>特殊包 3(格式同 i1)。
i4string(unset)<tag chain>特殊包 4(格式同 i1)。
i5string(unset)<tag chain>特殊包 5(格式同 i1)。
j1string(unset)<tag chain>仅 AmneziaWG v1.5 —— junk 包 1(标签链)。version 为 3 时会被拒绝。
j2string(unset)<tag chain>仅 AmneziaWG v1.5 —— junk 包 2(标签链)。version 为 3 时会被拒绝。
j3string(unset)<tag chain>仅 AmneziaWG v1.5 —— junk 包 3(标签链)。version 为 3 时会被拒绝。
itimeint640<seconds>仅 AmneziaWG v1.5 —— junk 包发送节奏。version 为 3 时会被拒绝。
header-protection-keystring(unset)<base64 key>AmneziaWG v3 —— 用于加密低熵头部字段的密钥(base64,例如由 awg genkey 生成)。要求 s1–s4 至少为 12。
content-padding-additionstring(unset)<bytes> | <a-b>AmneziaWG v3 —— 为包内容额外添加的随机 padding 区间,单位字节(a 或 a-b)。建议两端设置一致。
rekey-after-timestring(unset)<seconds> | <a-b>AmneziaWG v3 —— 客户端发起新握手前经过的秒数(a 或 a-b)。
rekey-timeoutstring(unset)<seconds> | <a-b>AmneziaWG v3 —— 握手未获响应时,重复握手前等待的秒数。
reject-after-timestring(unset)<seconds> | <a-b>AmneziaWG v3 —— 超过该秒数后客户端强制握手,并拒绝旧会话的入站数据。
keepalive-timeoutstring(unset)<seconds> | <a-b>AmneziaWG v3 —— 自上次发送数据起,经过该秒数后发送 keepalive。
max-handshake-attemptsstring(unset)<int> | <a-b>AmneziaWG v3 —— 握手重复的最大次数。
random-trailersboolfalsetrue | falseAmneziaWG v3.1 —— 在数据包末尾附加随机长度的尾部(并接受对端发来的超出预期长度的包)。
disable-cookiesboolfalsetrue | falseAmneziaWG v3.1 —— 负载过高时也不回复 cookie(跳过 WireGuard 的 MAC2 防 DoS 检查)。

源码: adapter/outbound/wireguard.go:102-141 · 锚定版本 v1.19.31 (ab405ba)

示例 ​

简化的单 peer 出站:

yaml
proxies:
  - name: wg-simple
    type: wireguard
    server: wg.example.com
    port: 51820
    private-key: <base64>
    public-key: <base64 peer key>
    ip: 10.0.0.2/32
    ipv6: fd00::2/128
    allowed-ips: ['0.0.0.0/0', '::/0']
    udp: true
    persistent-keepalive: 25

多 peer 出站(如 hub-and-spoke 拓扑):

yaml
proxies:
  - name: wg-multi
    type: wireguard
    private-key: <base64>
    ip: 10.0.0.2/32
    udp: true
    peers:
      - server: spoke1.example.com
        port: 51820
        public-key: <base64-spoke1>
        allowed-ips: ['10.0.1.0/24']
      - server: spoke2.example.com
        port: 51820
        public-key: <base64-spoke2>
        allowed-ips: ['10.0.2.0/24']

AmneziaWG 兼容的出站:

yaml
proxies:
  - name: awg
    type: wireguard
    server: awg.example.com
    port: 12345
    private-key: <base64>
    public-key: <base64>
    ip: 10.13.13.2/32
    allowed-ips: ['0.0.0.0/0']
    udp: true
    amnezia-wg-option:
      jc: 4
      jmin: 40
      jmax: 80
      s1: 0
      s2: 0
      h1: 123456
      h2: 67543
      h3: 123123
      h4: 32345

AmneziaWG v3 出站:

yaml
proxies:
  - name: awg3
    type: wireguard
    server: awg.example.com
    port: 12345
    private-key: <base64>
    public-key: <base64>
    ip: 10.13.13.2/32
    allowed-ips: ['0.0.0.0/0']
    udp: true
    amnezia-wg-option:
      version: 3
      jc: 4
      jmin: 40
      jmax: 80
      s1: 16
      s2: 16
      s3: 16
      s4: 16
      h1: 100000-199999
      h2: 200000-299999
      h3: 300000-399999
      h4: 400000-499999
      header-protection-key: <base64 key>
      content-padding-addition: 0-32

说明 ​

  • mihomo 同时接受简化形态(顶层 server / port / public-key / allowed-ips)与完整的 peers: 列表。设置 peers 时内嵌的简化字段被忽略。
  • remote-dns-resolve: true 让 WireGuard 通过 dns: 列出的解析器在隧道内查询 DNS(而不使用本地解析器)。当本地 DNS 不能到达目标时有用。
  • refresh-server-ip-interval 仅在 peer 的 server 是主机名时有意义;按固定间隔重新解析,适合动态 DNS 端点。
  • amnezia-wg-option 字段有版本之分:s3 / s4 / i1-i5 属于 AmneziaWG v1.5+;j1 / j2 / j3 / itime 仅 v1.5(v2 及以上不使用);header-protection-key、content-padding-addition 与五个时序字段仅 v3,random-trailers / disable-cookies 需 v3.1。v3 字段要求 version: 3,且不能与仅 v1.5 的字段混用 —— 两种实现都会拒绝对方的参数。见源码注释 adapter/outbound/wireguard.go:103-140。
  • ip-stack.mode: auto 在包含 gVisor 的构建中选用 gVisor,否则选用 mihomo 自带的 mips 栈;congestion-controller 只对 mips 生效。mihomo 的 OpenVPN 与 MASQUE 出站也有同样的 ip-stack 块。

跨内核说明 ​

  • Xray-core 始终使用 peers:(没有简化形态),并暴露 Linux 快路径相关的 noKernelTun 字段,字段名为 camelCase(secretKey、address、publicKey)。参见 WireGuard — Xray-core。
  • sing-box 把 WireGuard 配置为 endpoints[] 下的 端点,而非 outbounds[] 条目。字段名为 snake_case(private_key、allowed_ips)。参见 WireGuard — sing-box。

源码: adapter/outbound/wireguard.go:69-141 · v1.19.31 (ab405ba)

由 Argsment 出品的 Core Tutorial