diff --git a/family/documents/bring-to-russia.md b/family/documents/bring-to-russia.md index 49731aa3..d1322a4c 100755 --- a/family/documents/bring-to-russia.md +++ b/family/documents/bring-to-russia.md @@ -8,6 +8,7 @@ related: "[[family/documents/trip-packing-list]]" - [x] Старый ноут - [x] Казуу - [x] Диск + - [ ] Шапка - [ ] Ступенька на багажник авто - [x] Кружки пивные - [x] Магнит Сталин diff --git a/family/documents/fasteners-nomenclature.md b/family/documents/fasteners-nomenclature.md index b84a3197..841e133f 100644 --- a/family/documents/fasteners-nomenclature.md +++ b/family/documents/fasteners-nomenclature.md @@ -6,17 +6,14 @@ updated: 2026-05-16 related: "[[family/documents/lerua-shopping]]" --- Распечатать наклейки на банки с крепежом лаки парке - - [ ] ШСГД 4.2х75 - [x] Дюбель 8х40 (1) - [x] Дюбель 6х30 - - [ ] Дюбель 8х48 - - [ ] Дюбель 8х60 - - [x] дюбель гвоздь 6х42 - - [x] Дюбель-гвоздь 6х60 - [x] Бабочки - [x] Дюбель 10х50 (5) - [x] Дюбель 6х37 - [x] Дюбель 8х80 (7) + - [x] дюбель гвоздь 6х40 + - [x] Дюбель-гвоздь 6х60 - [x] Дюбельный крепеж для кабеля на 6 - [x] Дюбель 5х25 (8) - [x] Гвозди 4х120 @@ -26,23 +23,20 @@ related: "[[family/documents/lerua-shopping]]" - [x] Гвозди 2х25 - [x] Шуруп 3х25 (6) - [x] ШСГД 3.5х45 - - [ ] Гвозди 3х85, 4х100 + - [x] Гвозди 3х85, 4х100 - [x] Пресс шайба 18 (19?) - - [ ] Сверельный 16 + - [ ] Сверельный 4.2x16 - [x] Сверельный красный 16 - [x] Сверельный зелёный 16 + - [x] Саморез 2.5х16 (3.2?) - [x] Саморез цинк потай 5х40 + - [x] пресс шайба 4.2х26 - - [x] По металлу острый пресс шайба 4.2х16 - - [ ] По металлу острый пресс шайба 4.2х25 - - [ ] По металлу сверельный пресс шайба 4.2х16 - - [x] Саморез 3.2х16 + - [ ] ШСГД 3.5х35 + - [x] пресс шайба 4.2х16 - [ ] ШСГД 4х90 - [x] ШСГД 3х55 - [x] ШСГД 3.5х51 - - [ ] Золотой 3х25 - - [ ] Золотой 4х42 - - [ ] ШСГД 3.5х35 - [x] ШСГД 3.2х31 - [x] ШСГД 4.2х65 - [x] Золотой 4.2х51 @@ -51,14 +45,24 @@ related: "[[family/documents/lerua-shopping]]" - [x] саморез по металлу с полукруглой (линзовой) головкой, острый. (ШСМ-п/кр) 4x10 PH2 (фото 2) - [x] Золотой 4.2х90 - [x] Золотой 5х70 + - [x] Золотой 4.2х65 - [x] Гвозди 1х25 + - [x] Гвозди 1х20 - [x] шсгд 3.2х25 ! 0 - [x] шсгд 3.5х54 - - [x] Грозди 1х20 - - [x] Саморез 2.5х16 (3) - - [x] Золотой 4.2х65 - [x] ШСГД 3.2х40 + - [x] Саморез 2.5х16 (3) + + - [ ] Саморез 4х16 + - [ ] По металлу острый пресс шайба 4.2х25 + - [ ] Дюбель 8х48 + - [ ] Дюбель 8х60 + + - [ ] Золотой 3х25 + - [ ] Золотой 4х42 + - [ ] Саморез 4х30 PZ2 + - [ ] ШСГД 4.2х75 ## Связанные заметки diff --git a/family/how-to/rasputin-router.md b/family/how-to/rasputin-router.md new file mode 100644 index 00000000..e0b89fe5 --- /dev/null +++ b/family/how-to/rasputin-router.md @@ -0,0 +1,657 @@ +--- +title: Rasputin OpenWrt router +created: '2026-07-22' +updated: '2026-07-22' +tags: + - openwrt + - router + - rasputin + - networking + - vless + - cloudflared +--- +# Rasputin R5S OpenWrt router + +> Status as of 2026-07-22: Rasputin is the OpenWrt edge/LAN router, routing normal LAN traffic through a VLESS/Xray tunnel via `tun0`, with explicit direct-WAN exceptions for upstream LAN access and Mac `cloudflared` QUIC traffic. + +## Identity + +| Field | Value | +|---|---| +| Hostname | `Rasputin` | +| Hardware | FriendlyElec NanoPi R5S | +| Board | `friendlyarm,nanopi-r5s` | +| CPU | ARMv8 Processor rev 0 | +| OpenWrt | `24.10.2`, revision `r28739-d9340319c6` | +| Target | `rockchip/armv8` | +| Kernel | `6.6.93` | +| Rootfs | squashfs | +| LAN IP | `192.168.6.1/24` | +| IPv6 ULA prefix | `fd3b:153e:9be9::/48` | + +## Network Topology + +```text +LAN clients + -> br-lan / 192.168.6.0/24 + -> policy routing + -> most LAN traffic: table vpn -> tun0 -> badvpn-tun2socks -> Xray SOCKS -> VLESS + -> selected exceptions: table main -> WAN device +``` + +WAN is currently represented by both `eth0` and `usb0` in the `wan` firewall zone. At capture time, `eth0` had no carrier, while `usb0` was up and had the default route. + +Current default route: + +```text +default via 10.252.240.133 dev usb0 src 10.252.240.230 +``` + +VPN table: + +```text +default dev tun0 scope link +``` + +## Interfaces + +### LAN + +`br-lan` bridges: + +```text +eth1 +eth2 +phy0-ap0 +``` + +LAN config: + +```text +network.lan=interface +network.lan.device='br-lan' +network.lan.proto='static' +network.lan.ipaddr='192.168.6.1' +network.lan.netmask='255.255.255.0' +network.lan.ip6assign='60' +network.lan.dns='8.8.8.8' +``` + +### WAN + +`eth0`: + +```text +network.wan=interface +network.wan.device='eth0' +network.wan.proto='dhcp' +network.wan.peerdns='0' +network.wan.type='bridge' +``` + +`usb0`: + +```text +network.usbwan=interface +network.usbwan.proto='dhcp' +network.usbwan.device='usb0' +``` + +Firewall `wan` zone includes: + +```text +wan +wan6 +wwan +usbwan +``` + +### VPN + +`tun0` is declared as an unmanaged interface: + +```text +network.vpn=interface +network.vpn.proto='none' +network.vpn.device='tun0' +``` + +`tun0` is created/used by `badvpn-tun2socks`, launched from `/etc/init.d/tunvpn`. + +## DHCP And Static Leases + +DHCP server: + +```text +dhcp.lan=dhcp +dhcp.lan.interface='lan' +dhcp.lan.start='100' +dhcp.lan.limit='150' +dhcp.lan.leasetime='12h' +dhcp.lan.dhcp_option='6,1.1.1.1,1.0.0.1' +dhcp.lan.dhcpv4='server' +dhcp.lan.dhcpv6='server' +dhcp.lan.ra='server' +dhcp.lan.ra_slaac='1' +dhcp.lan.ra_flags='managed-config' 'other-config' +``` + +Static DHCP reservations added 2026-07-14 for the Mac: + +```text +dhcp.@host[0].name='mbp-black-eth' +dhcp.@host[0].mac='00:e0:4c:68:04:88' +dhcp.@host[0].ip='192.168.6.104' + +dhcp.@host[1].name='mbp-black-wifi' +dhcp.@host[1].mac='66:02:b1:8b:2f:94' +dhcp.@host[1].ip='192.168.6.173' +``` + +Backup made before this change: + +```text +/etc/config/dhcp.bak.20260714-195408 +``` + +## VLESS / Xray Stack + +Packages present include: + +```text +badvpn +xray-core +v2ray-core +v2ray-extra +v2ray-geoip +v2ray-geosite +v2raya +luci-app-v2raya +sing-box +nftables-json +iptables-nft +``` + +Runtime processes: + +```text +badvpn-tun2socks --tundev tun0 --netif-ipaddr 10.99.0.2 --netif-netmask 255.255.255.252 --socks-server-addr 127.0.0.1:1080 --loglevel none +/usr/bin/xray run -confdir /etc/xray -config /etc/xray/config.json -format json +``` + +`v2raya` is installed, but the observed UCI service config previously had `enabled='0'`. The active traffic path is the custom `tunvpn` service plus direct Xray config. + +### Xray Config + +File: + +```text +/etc/xray/config.json +``` + +Structure: + +```json +{ + "log": { + "loglevel": "debug", + "access": "/tmp/xray-access.log", + "error": "/tmp/xray-error.log" + }, + "inbounds": [ + { + "tag": "socks-in", + "listen": "127.0.0.1", + "port": 1080, + "protocol": "socks" + } + ], + "outbounds": [ + { + "tag": "proxy", + "protocol": "vless", + "settings": { + "vnext": [ + { + "address": "188.239.191.235", + "port": 443, + "users": [ + { + "id": "", + "flow": "xtls-rprx-vision", + "encryption": "none" + } + ] + } + ] + }, + "streamSettings": { + "network": "tcp", + "security": "reality", + "realitySettings": { + "serverName": "node3.sysnx.net", + "publicKey": "", + "shortId": "", + "fingerprint": "qq" + } + } + } + ], + "routing": { + "rules": [ + { "type": "field", "outboundTag": "proxy", "network": "tcp,udp" } + ] + } +} +``` + +Secrets are intentionally redacted in this note. The live file on the router contains the actual VLESS UUID and REALITY parameters. + +## `tunvpn` Service + +File: + +```text +/etc/init.d/tunvpn +``` + +Purpose: + +- Start `badvpn-tun2socks`. +- Populate routing table `vpn` with default route through `tun0`. +- Add policy rules so LAN traffic uses the VPN table. +- Add explicit Cloudflare Tunnel QUIC bypass rules for the Mac. + +Current script: + +```sh +#!/bin/sh /etc/rc.common +START=95 +STOP=10 + +start() { +badvpn-tun2socks --tundev tun0 --netif-ipaddr 10.99.0.2 --netif-netmask 255.255.255.252 --socks-server-addr 127.0.0.1:1080 --loglevel none & +sleep 2 + +ip route replace default dev tun0 table vpn +# cloudflared QUIC direct bypass for Mac Ethernet/Wi-Fi +ip rule add priority 98 from 192.168.6.173 ipproto udp dport 7844 lookup main 2>/dev/null +ip rule add priority 99 from 192.168.6.104 ipproto udp dport 7844 lookup main 2>/dev/null +ip rule add iif br-lan lookup vpn priority 101 +} + +stop() { +killall badvpn-tun2socks +ip rule del priority 98 2>/dev/null +ip rule del priority 99 2>/dev/null +ip rule del iif br-lan lookup vpn 2>/dev/null +ip route flush table vpn +} +``` + +Backup made before the Cloudflare direct-bypass update: + +```text +/etc/init.d/tunvpn.bak.20260714-195530 +``` + +## Policy Routing + +Current rules: + +```text +0: from all lookup local +98: from 192.168.6.173 ipproto udp dport 7844 lookup main +99: from 192.168.6.104 ipproto udp dport 7844 lookup main +100: from all to 192.168.2.0/24 lookup main +101: from all iif br-lan lookup vpn +32766: from all lookup main +32767: from all lookup default +``` + +Meaning: + +- Mac Wi-Fi `192.168.6.173` UDP/7844 goes direct through `main`. +- Mac Ethernet `192.168.6.104` UDP/7844 goes direct through `main`. +- Traffic to upstream LAN `192.168.2.0/24` goes direct through `main`. +- All other traffic entering from LAN bridge `br-lan` uses `table vpn`. +- `table vpn` sends default traffic through `tun0`. + +`/etc/rc.local` adds the upstream-LAN bypass: + +```sh +# Put your custom commands here that should be executed once +# the system init finished. By default this file does nothing. +ip rule add to 192.168.2.0/24 lookup main priority 100 + +exit 0 +``` + +## Firewall Model + +Default firewall policy: + +```text +input: REJECT +output: ACCEPT +forward: REJECT +``` + +Zones: + +### `lan` + +```text +name='lan' +input='ACCEPT' +output='ACCEPT' +forward='REJECT' +masq='1' +network='lan' +``` + +### `wan` + +```text +name='wan' +input='REJECT' +output='ACCEPT' +forward='REJECT' +masq='1' +mtu_fix='1' +network='wan' 'wan6' 'wwan' 'usbwan' +``` + +### `vpn` + +```text +name='vpn' +input='ACCEPT' +output='ACCEPT' +forward='ACCEPT' +masq='1' +network='vpn' +``` + +Forwarding: + +```text +lan -> vpn +``` + +There is no general `lan -> wan` forwarding. Instead, selected `lan -> wan` traffic is allowed before a LAN-to-WAN killswitch. + +## Important Firewall Rules + +### Cloudflare Tunnel QUIC Direct Bypass + +Added 2026-07-14: + +```text +firewall.@rule[8].name='Allow-Mac-cloudflared-QUIC-direct' +firewall.@rule[8].src='lan' +firewall.@rule[8].dest='wan' +firewall.@rule[8].src_ip='192.168.6.104' '192.168.6.173' +firewall.@rule[8].proto='udp' +firewall.@rule[8].dest_port='7844' +firewall.@rule[8].target='ACCEPT' +``` + +The nft realization appears in `forward_lan` before the killswitch: + +```text +ip saddr { 192.168.6.104, 192.168.6.173 } udp dport 7844 jump accept_to_wan comment "!fw4: Allow-Mac-cloudflared-QUIC-direct" +``` + +At capture time, this rule had matched traffic: + +```text +counter packets 19 bytes 27636 +``` + +This confirms that Mac `cloudflared` QUIC traffic was hitting the direct-WAN exception. + +### Upstream LAN Bypass + +```text +firewall.@rule[10].name='Allow-upstream-LAN' +firewall.@rule[10].src='lan' +firewall.@rule[10].dest='wan' +firewall.@rule[10].target='ACCEPT' +firewall.@rule[10].dest_ip='192.168.2.0/24' '192.168.0.1' +``` + +### Downstream LAN Access + +```text +firewall.@rule[11].name='Allow-downstream-LAN' +firewall.@rule[11].src='wan' +firewall.@rule[11].dest='lan' +firewall.@rule[11].target='ACCEPT' +firewall.@rule[11].src_ip='192.168.2.0/24' '192.168.0.1' +``` + +### KillSwitch + +```text +firewall.@rule[12].name='KillSwitch' +firewall.@rule[12].src='lan' +firewall.@rule[12].dest='wan' +firewall.@rule[12].proto='all' +firewall.@rule[12].target='REJECT' +``` + +In nft `forward_lan`, ordering is important: + +```text +1. Allow-Mac-cloudflared-QUIC-direct +2. Allow-upstream-LAN +3. KillSwitch +4. Accept lan to vpn forwarding +5. Accept DNAT port forwards +6. Reject to LAN +``` + +This ordering means only explicit `lan -> wan` exceptions escape; everything else either goes through VPN routing or is rejected from WAN. + +Backup made before the Cloudflare firewall change: + +```text +/etc/config/firewall.bak.20260714-195530 +``` + +## Port Forwarding + +There is a port-forward named `LocalSend-to-mbp-black-eth`: + +```text +firewall.@redirect[0].name='LocalSend-to-mbp-black-eth' +firewall.@redirect[0].src='wan' +firewall.@redirect[0].dest='lan' +firewall.@redirect[0].src_ip='192.168.2.0/24' +firewall.@redirect[0].proto='tcp udp' +firewall.@redirect[0].src_dport='53317' +firewall.@redirect[0].dest_ip='192.168.6.104' +firewall.@redirect[0].dest_port='53317' +firewall.@redirect[0].target='DNAT' +``` + +Reflection rules exist for LAN clients hitting the router WAN IP on port `53317`, redirecting to `192.168.6.104:53317`. + +## Cloudflare Tunnel / Mac Bypass Context + +Problem addressed: + +- Mac runs `cloudflared` for `zulip.qentra.top`. +- Router routes normal LAN traffic through VLESS via `tun0`. +- Cloudflare Tunnel connector traffic should go direct to WAN rather than through VLESS. + +Chosen solution: + +1. Mac `cloudflared` should use QUIC, not HTTP/2. +2. Cloudflare Tunnel QUIC is UDP destination port `7844`. +3. Router sends only Mac UDP/7844 through `main` table. +4. Firewall allows only Mac UDP/7844 from LAN to WAN before the KillSwitch. + +Mac-side LaunchDaemon observed earlier: + +```text +/Library/LaunchDaemons/com.cloudflare.cloudflared.plist +``` + +Original args observed before the change: + +```text +cloudflared tunnel --protocol http2 run --token +``` + +Target Mac-side args: + +```text +cloudflared tunnel --protocol quic run --token +``` + +Manual Mac commands provided for that change: + +```sh +sudo cp /Library/LaunchDaemons/com.cloudflare.cloudflared.plist \ + /Library/LaunchDaemons/com.cloudflare.cloudflared.plist.bak.$(date +%Y%m%d-%H%M%S) + +sudo /usr/libexec/PlistBuddy \ + -c "Set :ProgramArguments:3 quic" \ + /Library/LaunchDaemons/com.cloudflare.cloudflared.plist + +sudo launchctl bootout system /Library/LaunchDaemons/com.cloudflare.cloudflared.plist +sudo launchctl bootstrap system /Library/LaunchDaemons/com.cloudflare.cloudflared.plist +``` + +Verify on Mac: + +```sh +plutil -p /Library/LaunchDaemons/com.cloudflare.cloudflared.plist +tail -50 /Library/Logs/com.cloudflare.cloudflared.err.log +``` + +Expected log clue: + +```text +protocol=quic +``` + +Router-side counters can verify traffic is hitting the bypass: + +```sh +nft list chain inet fw4 forward_lan +``` + +Look for increasing counters on: + +```text +Allow-Mac-cloudflared-QUIC-direct +``` + +## Current Effective Traffic Behavior + +```text +Mac 192.168.6.104 UDP/7844 -> main routing table -> WAN direct +Mac 192.168.6.173 UDP/7844 -> main routing table -> WAN direct +Any LAN client -> 192.168.2.0/24 -> main routing table -> WAN/upstream LAN +Other LAN traffic -> vpn routing table -> tun0 -> Xray/VLESS +LAN -> WAN not explicitly allowed -> rejected by KillSwitch +``` + +## Operational Commands + +Restart VPN tunnel policy: + +```sh +/etc/init.d/tunvpn restart +``` + +Restart firewall: + +```sh +/etc/init.d/firewall restart +``` + +Show policy routing: + +```sh +ip rule show +ip route show table vpn +ip route show table all +``` + +Show Cloudflare direct firewall counter: + +```sh +nft list chain inet fw4 forward_lan +``` + +Show Xray logs: + +```sh +tail -100 /tmp/xray-access.log +tail -100 /tmp/xray-error.log +``` + +Show active proxy processes: + +```sh +ps w | grep -Ei 'xray|badvpn|tun2socks' | grep -v grep +``` + +Show current DHCP static leases: + +```sh +uci show dhcp | grep -E 'mbp-black|192.168.6.104|192.168.6.173|00:e0:4c:68:04:88|66:02:b1:8b:2f:94' +``` + +## Recovery / Rollback + +DHCP backup from Mac static lease change: + +```text +/etc/config/dhcp.bak.20260714-195408 +``` + +Routing service backup from Cloudflare direct-bypass change: + +```text +/etc/init.d/tunvpn.bak.20260714-195530 +``` + +Firewall backup from Cloudflare direct-bypass change: + +```text +/etc/config/firewall.bak.20260714-195530 +``` + +Rollback example: + +```sh +cp /etc/init.d/tunvpn.bak.20260714-195530 /etc/init.d/tunvpn +chmod +x /etc/init.d/tunvpn +cp /etc/config/firewall.bak.20260714-195530 /etc/config/firewall +/etc/init.d/tunvpn restart +/etc/init.d/firewall restart +``` + +Rollback DHCP static leases: + +```sh +cp /etc/config/dhcp.bak.20260714-195408 /etc/config/dhcp +uci commit dhcp +/etc/init.d/dnsmasq restart +``` + +## Notes And Pitfalls + +- The Cloudflare bypass depends on Mac `cloudflared` using QUIC. If the Mac falls back to HTTP/2/TCP/443, the router exception will not match. +- There are two Mac source IPs because the Mac can use Ethernet or Wi-Fi. +- Both Mac IPs are now static DHCP reservations on Rasputin. +- `ip rule` can match `ipproto udp dport 7844` on this OpenWrt build; this was tested and confirmed before making the persistent change. +- The firewall allow alone would not be sufficient, because policy routing rule `101` sends LAN ingress to `table vpn`. The direct `ip rule`s at priorities `98` and `99` must remain before priority `101`. +- Rule order in `forward_lan` matters: Cloudflare direct allow must stay above `KillSwitch`. +- `eth0` was down at the 2026-07-22 capture; `usb0` was active and part of the `wan` firewall zone. +- Secrets are redacted here intentionally. Consult the live router files only when the actual VLESS or Cloudflare credentials are needed.