This commit is contained in:
sijie.sun
2026-02-05 18:30:47 +08:00
parent 77e19000b5
commit 512dac6f08
182 changed files with 13050 additions and 10123 deletions
+9
View File
@@ -0,0 +1,9 @@
version: 2
updates:
# Enable version updates for npm
- package-ecosystem: npm
# Look for `package.json` and `lock` files in the `root` directory
directory: /
# Check the npm registry for updates every day (weekdays)
schedule:
interval: weekly
@@ -0,0 +1,21 @@
name: Dependabot auto-approve
on: pull_request
permissions:
pull-requests: write
jobs:
dependabot:
runs-on: ubuntu-latest
if: github.actor == 'dependabot[bot]'
steps:
- name: Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v2
with:
github-token: "${{ secrets.GITHUB_TOKEN }}"
- name: Approve a PR
run: gh pr review --approve "$PR_URL"
env:
PR_URL: ${{github.event.pull_request.html_url}}
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
+100
View File
@@ -0,0 +1,100 @@
# 构建 VitePress 站点并将其部署到 GitHub Pages 的示例工作流程
#
name: Deploy VitePress site to Pages
on:
# 在针对 `main` 分支的推送上运行。如果你
# 使用 `master` 分支作为默认分支,请将其更改为 `master`
push:
branches: [main]
# 允许你从 Actions 选项卡手动运行此工作流程
workflow_dispatch:
# 设置 GITHUB_TOKEN 的权限,以允许部署到 GitHub Pages
permissions:
contents: read
pages: write
id-token: write
# 只允许同时进行一次部署,跳过正在运行和最新队列之间的运行队列
# 但是,不要取消正在进行的运行,因为我们希望允许这些生产部署完成
concurrency:
group: pages
cancel-in-progress: false
jobs:
# 构建工作
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 1 # 如果未启用 lastUpdated,则不需要
submodules: recursive
- uses: pnpm/action-setup@v3 # 如果使用 pnpm,请取消注释
with:
version: 9
run_install: false
# - uses: oven-sh/setup-bun@v1 # 如果使用 Bun,请取消注释
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 21
cache: pnpm # 或 pnpm / yarn
# - name: Clone EasyTier
# uses: GuillaumeFalourd/clone-github-repo-action@v2.3
# with:
# depth: 1
# branch: 'main'
# owner: 'EasyTier'
# repository: 'EasyTier'
# - name: Build EasyTier Web
# run: |
# cd EasyTier
# pnpm -r install
# WEB_BASE_URL=/web pnpm -r build
# cd ..
# mkdir -p public/web
# cp -r EasyTier/easytier-web/frontend/dist/* public/web/
# rm -rf EasyTier
- name: Setup Pages
uses: actions/configure-pages@v4
- name: Install dependencies
run: pnpm -r install # 或 pnpm install / yarn install / bun install
- name: Build with VitePress
run: pnpm run docs:build # 或 pnpm docs:build / yarn docs:build / bun run docs:build
- name: Upload artifact
uses: actions/upload-pages-artifact@v3
with:
path: .vitepress/dist
- name: Upload OSS
if: ${{ github.ref == 'refs/heads/main' }}
uses: Menci/upload-to-oss@main
with:
access-key-id: ${{ secrets.ALIYUN_OSS_ACCESS_ID }}
access-key-secret: ${{ secrets.ALIYUN_OSS_ACCESS_KEY }}
endpoint: ${{ secrets.ALIYUN_OSS_ENDPOINT }}
bucket: ${{ secrets.ALIYUN_OSS_BUCKET }}
local-path: .vitepress/dist
remote-path: /
no-delete-remote-files: false
retry: 5
delay-html-file-upload: true
# 部署工作
deploy:
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
needs: build
runs-on: ubuntu-latest
name: Deploy
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v4
+14
View File
@@ -0,0 +1,14 @@
*.log
*.tgz
.DS_Store
.idea
.temp
.vite_opt_cache
.vscode
!.vscode/settings.json
!.vscode/extensions.json
dist
cache
temp
node_modules
.vitepress/cache
+3
View File
@@ -0,0 +1,3 @@
[submodule ".vitepress/third_party/lumen"]
path = .vitepress/third_party/lumen
url = https://github.com/KKRainbow/lumen.git
+2
View File
@@ -0,0 +1,2 @@
shamefully-hoist=true
strict-peer-dependencies=false
-41
View File
@@ -1,41 +0,0 @@
// ../../Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/index.js
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/fonts.css";
// ../../Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/without-fonts.js
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/vars.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/base.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/utils.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/components/custom-block.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/components/vp-code.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/components/vp-code-group.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/components/vp-doc.css";
import "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/styles/components/vp-sponsor.css";
import VPBadge from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPBadge.vue";
import Layout from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/Layout.vue";
import { default as default2 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPHomeHero.vue";
import { default as default3 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPHomeFeatures.vue";
import { default as default4 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPHomeSponsors.vue";
import { default as default5 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPDocAsideSponsors.vue";
import { default as default6 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPTeamPage.vue";
import { default as default7 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPTeamPageTitle.vue";
import { default as default8 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPTeamPageSection.vue";
import { default as default9 } from "C:/Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/components/VPTeamMembers.vue";
var theme = {
Layout,
enhanceApp: ({ app }) => {
app.component("Badge", VPBadge);
}
};
var without_fonts_default = theme;
export {
default5 as VPDocAsideSponsors,
default3 as VPHomeFeatures,
default2 as VPHomeHero,
default4 as VPHomeSponsors,
default9 as VPTeamMembers,
default6 as VPTeamPage,
default8 as VPTeamPageSection,
default7 as VPTeamPageTitle,
without_fonts_default as default
};
//# sourceMappingURL=@theme_index.js.map
-7
View File
@@ -1,7 +0,0 @@
{
"version": 3,
"sources": ["../../../../../Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/index.js", "../../../../../Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/without-fonts.js"],
"sourcesContent": ["import './styles/fonts.css';\nexport * from './without-fonts';\nexport { default as default } from './without-fonts';\n", "import './styles/vars.css';\nimport './styles/base.css';\nimport './styles/utils.css';\nimport './styles/components/custom-block.css';\nimport './styles/components/vp-code.css';\nimport './styles/components/vp-code-group.css';\nimport './styles/components/vp-doc.css';\nimport './styles/components/vp-sponsor.css';\nimport VPBadge from './components/VPBadge.vue';\nimport Layout from './Layout.vue';\n// Note: if we add more optional components here, i.e. components that are not\n// used in the theme by default unless the user imports them, make sure to update\n// the `lazyDefaultThemeComponentsRE` regex in src/node/build/bundle.ts.\nexport { default as VPHomeHero } from './components/VPHomeHero.vue';\nexport { default as VPHomeFeatures } from './components/VPHomeFeatures.vue';\nexport { default as VPHomeSponsors } from './components/VPHomeSponsors.vue';\nexport { default as VPDocAsideSponsors } from './components/VPDocAsideSponsors.vue';\nexport { default as VPTeamPage } from './components/VPTeamPage.vue';\nexport { default as VPTeamPageTitle } from './components/VPTeamPageTitle.vue';\nexport { default as VPTeamPageSection } from './components/VPTeamPageSection.vue';\nexport { default as VPTeamMembers } from './components/VPTeamMembers.vue';\nconst theme = {\n Layout,\n enhanceApp: ({ app }) => {\n app.component('Badge', VPBadge);\n }\n};\nexport default theme;\n"],
"mappings": ";AAAA,OAAO;;;ACAP,OAAO;AACP,OAAO;AACP,OAAO;AACP,OAAO;AACP,OAAO;AACP,OAAO;AACP,OAAO;AACP,OAAO;AACP,OAAO,aAAa;AACpB,OAAO,YAAY;AAInB,SAAoB,WAAXA,gBAA6B;AACtC,SAAoB,WAAXA,gBAAiC;AAC1C,SAAoB,WAAXA,gBAAiC;AAC1C,SAAoB,WAAXA,gBAAqC;AAC9C,SAAoB,WAAXA,gBAA6B;AACtC,SAAoB,WAAXA,gBAAkC;AAC3C,SAAoB,WAAXA,gBAAoC;AAC7C,SAAoB,WAAXA,gBAAgC;AACzC,IAAM,QAAQ;AAAA,EACV;AAAA,EACA,YAAY,CAAC,EAAE,IAAI,MAAM;AACrB,QAAI,UAAU,SAAS,OAAO;AAAA,EAClC;AACJ;AACA,IAAO,wBAAQ;",
"names": ["default"]
}
-19
View File
@@ -1,19 +0,0 @@
{
"hash": "7958035b",
"browserHash": "24330d08",
"optimized": {
"vue": {
"src": "../../../../../Users/35154/AppData/Local/pnpm/global/5/.pnpm/vue@3.2.47/node_modules/vue/dist/vue.runtime.esm-bundler.js",
"file": "vue.js",
"fileHash": "0201f78f",
"needsInterop": false
},
"@theme/index": {
"src": "../../../../../Users/35154/AppData/Local/pnpm/global/5/.pnpm/vitepress@1.0.0-alpha.75_@algolia+client-search@4.17.0_@types+node@18.16.3/node_modules/vitepress/dist/client/theme-default/index.js",
"file": "@theme_index.js",
"fileHash": "925c57a5",
"needsInterop": false
}
},
"chunks": {}
}
-3
View File
@@ -1,3 +0,0 @@
{
"type": "module"
}
-9516
View File
File diff suppressed because it is too large Load Diff
File diff suppressed because one or more lines are too long
+25
View File
@@ -0,0 +1,25 @@
<script setup lang="ts">
import { useData } from 'vitepress'
import { computed } from 'vue'
const props = defineProps<{
repo: string
type?: 'Date' | 'Timeline'
}>()
const { isDark } = useData()
const url = computed(() =>
`https://star-history.com/#${props.repo}&${props.type || 'Date'}`,
)
const imgUrl = computed(() =>
`https://api.star-history.com/svg?repos=${props.repo}&type=${props.type || 'Date'}${isDark.value ? '&theme=dark' : ''}`,
)
</script>
<template>
<a :href="url">
<img alt="Star History Chart" :src="imgUrl">
</a>
</template>
-52
View File
@@ -1,52 +0,0 @@
import { defineConfig } from 'vitepress'
// https://vitepress.dev/reference/site-config
export default defineConfig({
title: 'Easytier',
description: '一个简单、安全、去中心化的内网穿透 VPN 组网方案,使用 Rust 语言和 Tokio 框架实现',
locales: {
root: {
label: '简体中文',
lang: 'zh-CN',
title: 'Easytier',
description: '一个简单、安全、去中心化的内网穿透 VPN 组网方案,使用 Rust 语言和 Tokio 框架实现'
},
en: {
label: 'English',
lang: 'en',
title: 'Easytier',
description: 'A simple, secure, decentralized VPN mesh network solution, implemented using Rust language and Tokio framework.'
}
},
themeConfig: {
// https://vitepress.dev/reference/default-theme-config
sidebar: [
{ text: '简介', link: '/guide/introduction' },
{ text: '安装', link: '/guide/installation' },
{
text: '组网',
link: '/guide/networking',
items: [
{ text: '双节点', link: '/guide/network/two-node' },
{ text: '多节点', link: '/guide/network/multi-node' },
{ text: '子网代理(点对网)', link: '/guide/network/point-to' },
{ text: '无公网IP', link: '/guide/network/without-public-ip' },
{ text: '使用 WireGuard 客户端接入', link: '/guide/network/use-wireguard-client' }
]
},
{
items: [
{ text: '路线图', link: '/guide/roadmap' },
{ text: '社区和贡献', link: '/guide/community-and-contribution' },
{ text: '许可证', link: '/guide/license' },
{ text: '联系方式', link: '/guide/contact' },
]
}
],
socialLinks: [
{ icon: 'github', link: 'https://github.com/KKRainbow/EasyTier' }
]
}
})
+126
View File
@@ -0,0 +1,126 @@
import fs from 'node:fs'
import { defineConfig } from 'vitepress'
export const cn = defineConfig({
title: 'EasyTier - 简单、安全、去中心化的异地组网方案',
lang: 'cn',
description: '一个简单、安全、去中心化的内网穿透 SD-WAN 异地组网方案,使用 Rust 语言和 Tokio 框架实现',
themeConfig: {
sidebar: [
{
text: '开始',
items: [
{ text: '功能简介', link: '/guide/introduction' },
{ text: '安装 CLI', link: '/guide/installation' },
{ text: '安装 GUI', link: '/guide/installation_gui' },
{ text: '常见问题', link: '/guide/faq' },
],
},
{
text: '命令行工具组网',
link: '/guide/networking',
items: [
{ text: '去中心组网', link: '/guide/network/decentralized-networking' },
{ text: '使用 Web 控制台组网', link: '/guide/network/web-console' },
{ text: '使用 WireGuard 客户端接入', link: '/guide/network/use-easytier-with-wireguard-client' },
{ text: '子网代理(点对网)', link: '/guide/network/point-to-networking' },
{ text: '带宽延迟优化(KCP 代理)', link: '/guide/network/kcp-proxy' },
{ text: '高级功能', collapsed: true, items: [
{ text: '网对网', link: '/guide/network/network-to-network' },
{ text: '无 TUN 模式(免 Root 权限)', link: '/guide/network/no-root' },
{ text: 'SOCKS5', link: '/guide/network/socks5' },
{ text: '搭建共享节点', link: '/guide/network/host-public-server' },
{ text: '改善 P2P', link: '/guide/network/p2p-optimize' },
{ text: '魔法 DNS', link: '/guide/network/magic-dns' },
{ text: 'ACL', link: '/guide/config/acl' },
] },
{ text: '开机自启(注册服务)', collapsed: true, items: [
{ text: '一键安装服务', link: '/guide/network/oneclick-install-as-service' },
{ text: '安装为 Windows 服务', link: '/guide/network/install-as-a-windows-service' },
{ text: '安装为 Linux systemd 服务', link: '/guide/network/install-as-a-systemd-service' },
{ text: '安装为 macOS 服务', link: '/guide/network/install-as-a-macos-service' },
] },
{ text: '其他配置', link: '/guide/network/configurations' },
{ text: '配置文件', link: '/guide/network/config-file' },
],
},
{
text: '图形界面 GUI 组网',
link: 'guide/gui/index',
items: [
{ text: '手动组网', link: '/guide/gui/manual' },
{ text: 'WireGuard 接入', link: '/guide/gui/vpn_portal' },
{ text: '子网代理', link: '/guide/gui/subnet_proxy' },
{ text: 'EasyTier 管理器', link: '/guide/gui/easytier-manager' },
{ text: 'EasyTier 游戏联机启动器', link: '/guide/gui/easytier-game' },
{ text: 'AstralGame 联机工具', link: '/guide/gui/astral-game' },
{ text: 'EasyTier 鸿蒙版', link: '/guide/gui/easytier-harmonyos' },
{ text: 'QtEasyTier 组网工具', link: '/guide/gui/qteasytier' },
],
},
{
items: [
{ text: '关于 P2P', link: '/guide/aboutp2p' },
{ text: '性能测试', link: '/guide/perf' },
{ text: '路线图', link: '/guide/roadmap' },
{ text: '社区和贡献', link: '/guide/community-and-contribution' },
{ text: '隐私政策', link: '/guide/privacy' },
{ text: '许可证', link: '/guide/license' },
{ text: '联系方式', link: '/guide/contact' },
],
},
],
nav: [
],
footer: {
message: '基于 Apache License 2.0 许可发布',
copyright: '版权所有 © 2024-present EasyTier | '
+ '<a href="https://beian.miit.gov.cn/">'
+ '<img src="https://img.alicdn.com/tfs/TB1..50QpXXXXX7XpXXXXXXXXXX-40-40.png" alt="ICP 备案" style="width: 16px; height: 16px; display: inline-block; margin-bottom: -4px;">'
+ '浙ICP备2024137671号-1</a>',
},
editLink: {
pattern: 'https://github.com/EasyTier/easytier.github.io/edit/main/:path',
text: '在 GitHub 上编辑此页面',
},
docFooter: {
prev: '上一页',
next: '下一页',
},
outline: {
label: '页面导航',
},
lastUpdated: {
text: '最后更新于',
formatOptions: {
dateStyle: 'short',
timeStyle: 'medium',
},
},
langMenuLabel: '多语言',
returnToTopLabel: '回到顶部',
sidebarMenuLabel: '菜单',
darkModeSwitchLabel: '主题',
lightModeSwitchTitle: '切换到浅色模式',
darkModeSwitchTitle: '切换到深色模式',
},
})
export const cnSearch = {
translations: {
button: {
buttonText: '搜索文档',
buttonAriaLabel: '搜索文档',
},
modal: {
noResultsText: '无法找到相关结果',
resetButtonTitle: '清除查询条件',
footer: {
selectText: '选择',
navigateText: '切换',
closeText: '关闭',
},
},
},
}
+124
View File
@@ -0,0 +1,124 @@
import fs from 'node:fs'
import { defineConfig } from 'vitepress'
export const en = defineConfig({
title: 'EasyTier - A Simple, Secure, Decentralized SD-WAN Solution',
lang: 'en',
description: 'A simple, secure, decentralized SD-WAN solution for intranet penetration, implemented using Rust and the Tokio framework',
themeConfig: {
sidebar: [
{
text: 'Getting Started',
items: [
{ text: 'Introduction', link: '/en/guide/introduction' },
{ text: 'Installation CLI', link: '/en/guide/installation' },
{ text: 'Installation GUI', link: '/en/guide/installation_gui' },
{ text: 'FAQ', link: '/en/guide/faq' },
],
},
{
text: 'Command Line Networking',
link: '/en/guide/networking',
items: [
{ text: 'Decentralized Networking', link: '/en/guide/network/decentralized-networking' },
{ text: 'Networking with Web Console', link: '/en/guide/network/web-console' },
{ text: 'Using WireGuard Client', link: '/en/guide/network/use-easytier-with-wireguard-client' },
{ text: 'Subnet Proxy (Point-to-Network)', link: '/en/guide/network/point-to-networking' },
{ text: 'Bandwidth and Latency Optimization (KCP Proxy)', link: '/en/guide/network/kcp-proxy' },
{ text: 'Advanced Features', collapsed: true, items: [
{ text: 'Network-to-Network', link: '/en/guide/network/network-to-network' },
{ text: 'No TUN Mode (No Root Required)', link: '/en/guide/network/no-root' },
{ text: 'SOCKS5', link: '/en/guide/network/socks5' },
{ text: 'Hosting Public Server', link: '/en/guide/network/host-public-server' },
{ text: 'P2P Optimization', link: '/en/guide/network/p2p-optimize' },
{ text: 'Magic DNS', link: '/en/guide/network/magic-dns' },
{ text: 'ACL', link: '/en/guide/config/acl' },
] },
{ text: 'Autostart (Register Service)', collapsed: true, items: [
{ text: 'One-Click Install Service', link: '/en/guide/network/oneclick-install-as-service' },
{ text: 'Install as Windows Service', link: '/en/guide/network/install-as-a-windows-service' },
{ text: 'Install as Linux systemd Service', link: '/en/guide/network/install-as-a-systemd-service' },
{ text: 'Install as macOS Service', link: '/en/guide/network/install-as-a-macos-service' },
] },
{ text: 'Other Configurations', link: '/en/guide/network/configurations' },
{ text: 'Configuration File', link: '/en/guide/network/config-file' },
],
},
{
text: 'GUI Networking',
link: '/en/guide/gui/index',
items: [
{ text: 'Manual Networking', link: '/en/guide/gui/manual' },
{ text: 'WireGuard Access', link: '/en/guide/gui/vpn_portal' },
{ text: 'Subnet Proxy', link: '/en/guide/gui/subnet_proxy' },
{ text: 'EasyTier Manager', link: '/en/guide/gui/easytier-manager' },
{ text: 'EasyTier Game Launcher', link: '/en/guide/gui/easytier-game' },
{ text: 'Astral Game Connection Tool', link: '/en/guide/gui/astral-game' },
{ text: 'QtEasyTier', link: '/en/guide/gui/qteasytier' },
],
},
{
items: [
{ text: 'Performance Testing', link: '/en/guide/perf' },
{ text: 'Roadmap', link: '/en/guide/roadmap' },
{ text: 'Community and Contribution', link: '/en/guide/community-and-contribution' },
{ text: 'Privacy Policy', link: '/en/guide/privacy' },
{ text: 'License', link: '/en/guide/license' },
{ text: 'Contact', link: '/en/guide/contact' },
],
},
],
nav: [
],
footer: {
message: 'Released under the Apache License 2.0',
copyright: 'Copyright © 2024-present EasyTier | '
+ '<a href="https://beian.miit.gov.cn/">'
+ '<img src="https://img.alicdn.com/tfs/TB1..50QpXXXXX7XpXXXXXXXXXX-40-40.png" alt="ICP Record" style="width: 16px; height: 16px; display: inline-block; margin-bottom: -4px;">'
+ 'Zhejiang ICP No. 2024137671-1</a>',
},
editLink: {
pattern: 'https://github.com/EasyTier/easytier.github.io/edit/main/:path',
text: 'Edit this page on GitHub',
},
docFooter: {
prev: 'Previous Page',
next: 'Next Page',
},
outline: {
label: 'Page Navigation',
},
lastUpdated: {
text: 'Last Updated',
formatOptions: {
dateStyle: 'short',
timeStyle: 'medium',
},
},
langMenuLabel: 'Languages',
returnToTopLabel: 'Back to Top',
sidebarMenuLabel: 'Menu',
darkModeSwitchLabel: 'Theme',
lightModeSwitchTitle: 'Switch to Light Mode',
darkModeSwitchTitle: 'Switch to Dark Mode',
},
})
export const enSearch = {
translations: {
button: {
buttonText: 'Search Docs',
buttonAriaLabel: 'Search Docs',
},
modal: {
noResultsText: 'No results found',
resetButtonTitle: 'Clear search query',
footer: {
selectText: 'Select',
navigateText: 'Navigate',
closeText: 'Close',
},
},
},
}
+64
View File
@@ -0,0 +1,64 @@
// @ts-expect-error ignore next line
import taskLists from 'markdown-it-task-lists'
import { withMermaid } from 'vitepress-plugin-mermaid'
import { cn, cnSearch } from './cn'
import { en } from './en'
export default withMermaid({
base: '/',
lastUpdated: true,
head: [
['link', { rel: 'icon', type: 'image/png', sizes: '32x32', href: '/easytier.png' }],
['meta', { name: 'msvalidate.01', content: 'C6CB41F1DA6096106497701D002B19AD' }],
['meta', { name: 'author', content: 'EasyTier' }],
['meta', { name: 'keywords', content: 'easytier,SD-WAN,networking' }],
['meta', { property: 'og:type', content: 'website' }],
['meta', { property: 'og:title', content: 'EasyTier' }],
['meta', { property: 'og:description', content: 'EasyTier official' }],
['meta', { property: 'og:image', content: 'https://easytier.cn/easytier.png' }],
['link', { rel: 'canonical', href: 'https://easytier.cn' }],
],
themeConfig: {
siteTitle: 'EasyTier',
logo: '/easytier.png',
search: {
provider: 'local',
options: {
locales: {
root: { ...cnSearch },
},
},
},
socialLinks: [
{
icon: 'gmail',
link: 'mailto:sunsijie@buaa.edu.cn',
ariaLabel: 'Email',
},
{
icon: 'qq',
link: 'https://qm.qq.com/q/wFoTUChqZW',
ariaLabel: 'qq',
},
],
},
locales: {
root: { label: '简体中文', ...cn },
en: { label: 'English', ...en },
},
markdown: {
config: (md) => {
md.use(taskLists)
},
},
vue: {
template: {
compilerOptions: { isCustomElement: tag => tag === 'iconify-icon' },
},
},
sitemap: {
hostname: 'https://easytier.cn',
},
})
+5
View File
@@ -0,0 +1,5 @@
import type { TwikooData } from '@theojs/lumen'
export const Twikoo_Data: TwikooData = {
envId: 'https://twikoo.easytier.cn', // 修改成部署的Twikoo地址
}
+67
View File
@@ -0,0 +1,67 @@
import type { EnhanceAppContext } from 'vitepress'
import { baiduAnalytics, HomeUnderline, trackPageview } from '@theojs/lumen'
import DefaultTheme from 'vitepress/theme'
import Layout from './layout.vue'
import '@theojs/lumen/theme'
import '@theojs/lumen/doc-blocks-border'
/**
* Add noopener to links with text fragments
*/
function initNoopenerLinks() {
if (typeof window === 'undefined')
return
const processLinks = () => {
document.querySelectorAll('a').forEach((link) => {
const href = link.getAttribute('href')
// Add noopener to links with text fragments
if (href && href.includes(':~:text=')) {
const rel = link.getAttribute('rel') || ''
if (!rel.includes('noopener')) {
const newRel = rel ? `${rel} noopener` : 'noopener'
link.setAttribute('rel', newRel.trim())
}
const target = link.getAttribute('target') || ''
if (!target) {
link.setAttribute('target', '_blank')
}
}
})
}
// Process links on load
if (document.readyState === 'loading') {
document.addEventListener('DOMContentLoaded', processLinks)
}
else {
processLinks()
}
// Process dynamically added links
const observer = new MutationObserver(processLinks)
observer.observe(document.body, {
childList: true,
subtree: true,
})
}
export default {
extends: DefaultTheme,
Layout,
enhanceApp: (ctx: EnhanceAppContext) => {
const { app } = ctx
baiduAnalytics({ baiduId: '0afa8cd5bd78fd0c960f8af5dc6af333' })
if (typeof window !== 'undefined') {
trackPageview('0afa8cd5bd78fd0c960f8af5dc6af333', window.location.href)
// Initialize noopener for text fragment links
initNoopenerLinks()
}
app.component('Home', HomeUnderline)
},
} as any
+151
View File
@@ -0,0 +1,151 @@
<script setup lang="ts">
import { ShareButton, Twikoo } from '@theojs/lumen'
import { useData } from 'vitepress'
import DefaultTheme from 'vitepress/theme'
import { h, nextTick, provide } from 'vue'
import { Twikoo_Data } from '../data/Twikoo'
const { isDark } = useData()
function enableTransitions() {
return 'startViewTransition' in document
&& window.matchMedia('(prefers-reduced-motion: no-preference)').matches
}
provide('toggle-appearance', async ({ clientX: x, clientY: y }: MouseEvent) => {
if (!enableTransitions()) {
isDark.value = !isDark.value
return
}
const clipPath = [
`circle(0px at ${x}px ${y}px)`,
`circle(${Math.hypot(
Math.max(x, innerWidth - x),
Math.max(y, innerHeight - y),
)}px at ${x}px ${y}px)`,
]
await document.startViewTransition(async () => {
isDark.value = !isDark.value
await nextTick()
}).ready
document.documentElement.animate(
{ clipPath: isDark.value ? clipPath.reverse() : clipPath },
{
duration: 300,
easing: 'ease-in',
pseudoElement: `::view-transition-${isDark.value ? 'old' : 'new'}(root)`,
},
)
})
const Layout = h(DefaultTheme.Layout, null, {
'aside-outline-before': () => h(ShareButton),
'doc-after': () => h(Twikoo, { Twikoo_Data }),
})
</script>
<template>
<Layout />
</template>
<style>
::view-transition-old(root),
::view-transition-new(root) {
animation: none;
mix-blend-mode: normal;
}
::view-transition-old(root),
.dark::view-transition-new(root) {
z-index: 1;
}
::view-transition-new(root),
.dark::view-transition-old(root) {
z-index: 9999;
}
footer.VPFooter {
display: block !important;
}
.filter-select {
/* styling */
border: thin solid rgb(5, 176, 142);
border-radius: 4px;
display: inline-block;
font: inherit;
line-height: 1em;
padding: 0.5em 3.5em 0.5em 1em;
/* reset */
margin: 0;
-webkit-box-sizing: border-box;
-moz-box-sizing: border-box;
box-sizing: border-box;
-webkit-appearance: none;
-moz-appearance: none;
min-width: 15rem;
background-image: linear-gradient(45deg, transparent 50%, gray 50%),
linear-gradient(135deg, gray 50%, transparent 50%), linear-gradient(to right, #ccc, #ccc);
background-position:
calc(100% - 20px) calc(1em),
calc(100% - 15px) calc(1em),
calc(100% - 2.5em) 0.5em;
background-size:
5px 5px,
5px 5px,
1px 1.5em;
background-repeat: no-repeat;
}
.filter-select:focus {
background-image: linear-gradient(45deg, green 50%, transparent 50%),
linear-gradient(135deg, transparent 50%, green 50%), linear-gradient(to right, #ccc, #ccc);
background-position:
calc(100% - 15px) 1em,
calc(100% - 20px) 1em,
calc(100% - 2.5em) 0.5em;
background-size:
5px 5px,
5px 5px,
1px 1.5em;
background-repeat: no-repeat;
border-color: green;
outline: 0;
}
.download-link-span {
display: inline-block;
margin: 0.25rem 0.15rem;
color: #fff !important;
border: none;
padding: 0.3rem 0.6rem;
background: linear-gradient(135deg, #05b08e 0%, #048a6f 100%);
text-decoration: none !important;
border-radius: 6px;
font-size: 0.9em;
font-weight: 500;
transition: all 0.3s ease;
box-shadow: 0 2px 8px rgba(5, 176, 142, 0.2);
}
.download-link-span:hover {
background: linear-gradient(135deg, #048a6f 0%, #036b59 100%);
box-shadow: 0 4px 12px rgba(5, 176, 142, 0.35);
transform: translateY(-2px);
}
.download-link-span:active {
transform: translateY(0);
box-shadow: 0 2px 4px rgba(5, 176, 142, 0.2);
}
</style>
+73
View File
@@ -0,0 +1,73 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications, including but not limited to software source code, documentation source, and configuration files.
"Object" form shall mean any form resulting from mechanical transformation or translation of a Source form, including but not limited to compiled object code, generated documentation, and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or Object form, made available under the License, as indicated by a copyright notice that is included in or attached to the work (an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object form, that is based on (or derived from) the Work and for which the editorial revisions, annotations, elaborations, or other modifications represent, as a whole, an original work of authorship. For the purposes of this License, Derivative Works shall not include works that remain separable from, or merely link (or bind by name) to the interfaces of, the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including the original version of the Work and any modifications or additions to that Work or Derivative Works thereof, that is intentionally submitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner. For the purposes of this definition, "submitted" means any form of electronic, verbal, or written communication sent to the Licensor or its representatives, including but not limited to communication on electronic mailing lists, source code control systems, and issue tracking systems that are managed by, or on behalf of, the Licensor for the purpose of discussing and improving the Work, but excluding communication that is conspicuously marked or otherwise designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received by Licensor and subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable (except as stated in this section) patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work, where such license applies only to those patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s) alone or by combination of their Contribution(s) with the Work to which such Contribution(s) was submitted. If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions:
(a) You must give any other recipients of the Work or Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file, excluding those notices that do not pertain to any part of the Derivative Works, in at least one of the following places: within a NOTICE text file distributed as part of the Derivative Works; within the Source form or documentation, if provided along with the Derivative Works; or, within a display generated by the Derivative Works, if and wherever such third-party notices normally appear. The contents of the NOTICE file are for informational purposes only and do not modify the License. You may add Your own attribution notices within Derivative Works that You distribute, alongside or as an addendum to the NOTICE text from the Work, provided that such additional attribution notices cannot be construed as modifying the License.
You may add Your own copyright statement to Your modifications and may provide additional or different license terms and conditions for use, reproduction, or distribution of Your modifications, or for any such Derivative Works as a whole, provided Your use, reproduction, and distribution of the Work otherwise complies with the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License, without any additional terms or conditions. Notwithstanding the above, nothing herein shall supersede or modify the terms of any separate license agreement you may have executed with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory, whether in tort (including negligence), contract, or otherwise, unless required by applicable law (such as deliberate and grossly negligent acts) or agreed to in writing, shall any Contributor be liable to You for damages, including any direct, indirect, special, incidental, or consequential damages of any character arising as a result of this License or out of the use or inability to use the Work (including but not limited to damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses), even if such Contributor has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing the Work or Derivative Works thereof, You may choose to offer, and charge a fee for, acceptance of support, warranty, indemnity, or other liability obligations and/or rights consistent with this License. However, in accepting such obligations, You may act only on Your own behalf and on Your sole responsibility, not on behalf of any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against, such Contributor by reason of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following boilerplate notice, with the fields enclosed by brackets "[]" replaced with your own identifying information. (Don't include the brackets!) The text should be enclosed in the appropriate comment syntax for the file format. We also recommend that a file or class name and description of purpose be included on the same "printed page" as the copyright notice for easier identification within third-party archives.
Copyright 2023 sunsijie
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
+1
View File
@@ -0,0 +1 @@
[简体中文](https://easytier.github.io/) | [English](https://easytier.github.io/en)
Binary file not shown.

After

Width:  |  Height:  |  Size: 39 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.9 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.6 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 84 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 7.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 54 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 39 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 28 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 32 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 13 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 50 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 19 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 127 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.6 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 18 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 16 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 9.8 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.9 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 21 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 524 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 669 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 796 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 976 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 580 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 16 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 58 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 18 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 125 KiB

After

Width:  |  Height:  |  Size: 13 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 104 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 16 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 24 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 13 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 15 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 17 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 15 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 39 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 35 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.6 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.8 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 49 KiB

BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 7.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.8 KiB

+12 -2
View File
@@ -1,3 +1,13 @@
<script setup>
import StarHistory from '../../.vitepress/components/starHistory.vue'
</script>
# Community and Contribution
We welcome and encourage community contributions! If you want to get involved, please submit a [GitHub PR](https://github.com/KKRainbow/EasyTier/pulls). Detailed contribution guidelines can be found in [CONTRIBUTING.md](https://github.com/KKRainbow/EasyTier/blob/main/CONTRIBUTING.md).
We welcome and encourage community contributions! If you want to get involved, please submit a [GitHub PR](https://github.com/EasyTier/EasyTier/pulls).
Detailed contribution guidelines can be found in the [Contributing](https://github.com/EasyTier/EasyTier/blob/main/CONTRIBUTING.md) document.
## Star History
<StarHistory repo="EasyTier/EasyTier" type="Timeline" />
+220
View File
@@ -0,0 +1,220 @@
# Easytier ACL Feature Guide 🛡️
## 📖 Table of Contents
1. [Core Concepts](#-core-concepts)
2. [How It Works](#-how-it-works)
3. [Configuration Details](#-configuration-details)
4. [Common Use Case Examples](#-common-use-case-examples)
5. [Best Practices and Notes](#-best-practices-and-notes)
---
## 🧠 Core Concepts
Understanding the following key concepts is essential for configuring ACL:
- **ACL (Access Control List)**: A set of rules used to allow or deny network traffic. Easytier's 2.4.0 update introduced IP-based ACL control, and version 2.4.3 added a zero-trust ACL mechanism based on identity groups, making policies more flexible.
- **Chain**: A collection of rules. Chains have types; for example, `chain_type = 1` represents an inbound chain, processing traffic sent to the local machine.
- **Rule**: Defines traffic matching conditions (such as protocol, port, source/target groups) and the action to take upon a match (allow or deny).
- **Group**: A logical identity tag. A node (server, computer, etc.) can declare that it belongs to one or more groups (e.g., `admin`, `database`).
- **Group Declaration**: A node needs to know in advance all the group names it might communicate with and their corresponding shared secrets. The secret is used to verify whether the group membership claimed by other nodes is valid.
- **Priority**: Rules are matched in descending order of priority value. Once traffic matches a rule, its action is executed, and subsequent matching stops.
---
## 🔧 Configuration Details
ACL configuration must be added to Easytier's configuration file `config.yaml`.
### 1. Define Groups and Secrets
This is the most critical step. Each node needs to declare which groups it belongs to in its configuration and configure the shared secrets for all related groups.
```yaml
# This section defines the groups this node will join (for generating identity proof)
[acl.acl_v1.group]
members = ["admin", "web-server"] # This node's identity: both an administrator and a web server
# This section defines all groups "known" to this node and their secrets (for verifying peer identities)
[[acl.acl_v1.group.declares]]
group_name = "admin"
group_secret = "super-secret-admin-key" # Please use a more complex key!
[[acl.acl_v1.group.declares]]
group_name = "web-server"
group_secret = "web-server-secret-key"
[[acl.acl_v1.group.declares]]
group_name = "database"
group_secret = "database-secret-key"
[[acl.acl_v1.group.declares]]
group_name = "guest"
group_secret = "guest-secret-key"
```
> **⚠️ Important Notes**:
> - `members`: Defines this node's identity.
> - `declares`: Acts as the node's "address book" and must include definitions for all groups in the network that might communicate. The `declares` section must be completely consistent across all nodes.
> - `group_secret`: The cornerstone of security. Must use a strong, unique secret, and all nodes must share the same secret definitions.
---
### 2. Configure Rule Chains
Rule chains determine how traffic is handled.
```yaml
# Define an inbound chain
[[acl.acl_v1.chains]]
name = "my_acl_policy" # Chain name
chain_type = 1 # 0: Unspecified, 1: Inbound chain (processes traffic sent to this machine), 2: Outbound (processes traffic sent from this machine), 3: Forwarding (subnet proxy)
description = "My security policy"
enabled = true # Enable this chain
default_action = 2 # Default action: 1(Allow) 2(Deny)
```
---
### 3. Configure Rules
Rules are the core of the policy and are defined within chains.
```yaml
# List of rules within the chain defined above
[[acl.acl_v1.chains.rules]]
name = "allow_admin_rdp"
description = "Allow administrators to RDP to this machine"
priority = 1000 # Priority, higher number means higher priority (0-65535)
action = 1 # Action: 0(No operation) 1(Allow) 2(Deny)
source_groups = ["admin"] # Rule match: source device must belong to the admin group
protocol = 1 # Protocol: 0(Unspecified) 1(TCP) 2(UDP) 3(ICMP) 4(ICMPv6) 5(Any)
ports = ["3389"] # Local allowed port: 3389 (RDP)
enabled = true # Enable this rule
[[acl.acl_v1.chains.rules]]
name = "deny_guest_to_db"
description = "Deny guests access to the database"
priority = 900 # Lower priority
action = 2 # Action: 0(No operation) 1(Allow) 2(Deny)
source_groups = ["guest"] # Rule match: source device must belong to the guest group
destination_groups = ["database"] # Match when the target device belongs to the database group
enabled = true # Enable the rule
protocol = 1 # TCP protocol
ports = [] # If empty, matches all ports
source_ips = [] # If empty, matches all source IP ranges; format `10.144.144.2/32`
destination_ips = [] # If empty, matches all destination IP ranges
source_ports = [] # If empty, matches all source ports
rate_limit = 0 # Rate limit (bps), 0 = unlimited
burst_limit = 0 # Maximum burst bandwidth (bps)
stateful = true # Enable connection tracking
```
---
## 🧪 Common Use Case Examples
### Use Case 1: Minimal Security Group - "Same Secret Allows Access"
**Goal**: Implement a private network where devices with the same secret can communicate; devices without the secret cannot join.
**Configuration**:
```yaml
[acl.acl_v1.group]
members = ["my-net"] # All devices join the same group
[[acl.acl_v1.group.declares]]
group_name = "my-net"
group_secret = "my-net-secret-key" # All devices use the same secret
[[acl.acl_v1.chains]]
name = "default_inbound"
chain_type = 1
enabled = true
default_action = 2 # Deny by default
# Core rule: Allow all communication within the group
[[acl.acl_v1.chains.rules]]
name = "allow_whole_group"
description = "Allow all traffic within the group"
priority = 1000
action = 1
source_groups = ["my-net"] # Source is a group member
destination_groups = ["my-net"] # Destination is a group member
protocol = 1
enabled = true
```
---
### Use Case 2: Three-Tier Network Architecture
**Goal**: Simulate a classic Web-DB architecture, only allowing web servers to access specific ports on the database.
**Node Configuration**:
- Web Server: `members = ["web"]`
- Database Server: `members = ["db"]`
- Admin Machine: `members = ["admin"]`
**ACL Rules on the Database Server**:
```yaml
[[acl.acl_v1.chains]]
name = "db_server_policy"
chain_type = 1
enabled = true
default_action = 2 # Deny all connections by default
# Rule 1: Allow web servers to access the database port
[[acl.acl_v1.chains.rules]]
name = "allow_web_to_mysql"
description = "Allow the web group to access MySQL"
priority = 100
action = 1
source_groups = ["web"]
destination_groups = ["db"] # Target is this machine (db group)
protocol = 1
ports = ["3306"] # Only open MySQL port
enabled = true
# Rule 2: Allow admins access to all ports (e.g., for management)
[[acl.acl_v1.chains.rules]]
name = "allow_admin_to_all"
description = "Allow administrators access to all services"
priority = 110 # Higher priority than the previous rule
action = 1
source_groups = ["admin"]
destination_groups = ["db"] # Target is this machine (db group)
protocol = 1
enabled = true
```
---
## ✅ Best Practices and Notes
1. **Secret Management**:
- **Importance**: `group_secret` is the foundation of security. If leaked, attackers can freely join your network.
- **Recommendation**: Use a password generator to create long and complex secrets, and rotate them periodically.
- **Secure Storage**: Do not commit the configuration file to public code repositories.
2. **Configuration Consistency**:
- Ensure the `[[acl.acl_v1.group.declares]]` section is completely consistent (same group names and secrets) across all nodes in the network. Otherwise, group verification will fail, and the network will not function correctly.
3. **Debugging Tips**:
- Start with a relaxed policy (`default_action = 1`) and use logs to confirm network connectivity.
- Gradually add deny rules (`action = 2`) to restrict access.
- Finally, change the `default_action` to deny (`2`) to implement a "whitelist" model.
- Make full use of the `description` field to add clear comments for each rule, facilitating future maintenance.
- The `easytier-cli acl stats` command can be used to view ACL statistics.
4. **Operation Order**:
- After modifying ACL configuration, the Easytier process usually needs to be restarted to take effect.
- Commands like `easytier-core -d --tcp-whitelist port number` can automatically generate simple port whitelist rules, which can serve as a starting point for learning.
---
We hope this document helps you better understand and use Easytier's ACL features! If you have any questions, welcome to discuss them in the community. 🎉
+5 -5
View File
@@ -1,6 +1,6 @@
# Contact
- Ask questions or report problems: [GitHub Issues](https://github.com/KKRainbow/EasyTier/issues)
- Discussion and exchange: [GitHub Discussions](https://github.com/KKRainbow/EasyTier/discussions)
# Contact Information
- Ask questions or report issues: [GitHub Issues](https://github.com/EasyTier/EasyTier/issues)
- Discussion and communication: [GitHub Discussions](https://github.com/EasyTier/EasyTier/discussions)
- QQ Group: [949700262](https://qm.qq.com/q/LDxBN5L3kA)
- Telegram: https://t.me/easytier
- Telegram: https://t.me/easytier
+79
View File
@@ -0,0 +1,79 @@
# Frequently Asked Questions {#faq}
---
**Q: Windows 7 cannot create a network, the program crashes or reports an error saying it cannot create a virtual network?**
**A:** Windows 7 requires SP1 or later versions, and the following patches must be installed:
- [KB3063858](https://www.microsoft.com/en-us/download/details.aspx?id=47409)
- [KB4474419](https://www.catalog.update.microsoft.com/search.aspx?q=KB4474419)
---
**Q: The Linux command-line help is in English, how can I switch to Chinese?**
**A:** Set the environment variable `LANG=zh_CN`. Use the following command:
```bash
export LANG=zh_CN
```
---
**Q: What should I do if TunError is displayed after startup?**
**A:** Please ensure that the TUN driver is correctly loaded and the `/dev/net/tun` file exists. If running in Docker, ensure privileged mode is enabled. The command to load the TUN driver on Linux is as follows:
```bash
modprobe tun
mkdir -p /dev/net
sudo mknod /dev/net/tun c 10 200
```
---
**Q: What should I do if the error `Address already in use` is reported after startup?**
**A:** This may be due to port conflicts. Please check whether port 11010 or the port specified by the startup parameter (e.g., `-l tcp:12345`) is occupied by other programs.
---
**Q: Is a WEB console absolutely necessary?**
**A:** EasyTier is **decentralized**, so it **does not have** and **does not need** a centralized control panel like ZeroTier or Tailscale to manage all devices.
---
**Q: What is the purpose of the WEB console?**
**A:** The purpose of the WEB console is to remotely manage/distribute configurations. If you start with the `-w <web console username>` parameter, the machine will attempt to connect to the specified server and identify itself with the given username.
At this point, in the panel, you can log in with this username and manage machines that are identified with that user.
In other words, you don't need to worry about someone impersonating your username to start the core, because as long as you don't distribute the same configuration to that machine as your other machines, your network information will not be leaked.
On the contrary, this would expose all internal network services of that machine to you.
---
**Q: Is the WEB console username the same as the network name?**
**A:** **No, they are not the same**.
Network name + network password must be completely identical to successfully establish a network and transmit valid information.
---
**Q: What should I do if I cannot see other networked machines in the WEB console?**
**A:** If these machines were started using other methods, their configuration files are managed by the machines themselves, so naturally they **cannot** be seen in the web panel.
If you need to check whether they are successfully connected, you can enter `easytier-cli node` or `easytier-cli peers` on the machine to view.
Alternatively, you can open any managed machine in the web panel (which uses the same network name as the machine you want to check), and see if the machine you want to check appears in its connected directory.
---
**Q: How to start multiple instances?**
**A:** A single machine may need to provide forwarding services for multiple networks simultaneously, but this may cause port conflict errors.
As long as the listener port is set without conflicting with other already started instances, it will work.
If RPC is configured, you also need to ensure that the port does not conflict.
---
+29
View File
@@ -0,0 +1,29 @@
# AstralGame - Game Networking Tool
[![GitHub](https://img.shields.io/badge/GitHub-AstralET-blue)](https://github.com/ldoubil/astral)
[![AstralGame](https://img.shields.io/badge/wiki-AstralGame-blue)](https://astral.fan/)
## Preview
![manage-step1](/assets/AstralET1.png)
![manage-step1](/assets/AstralET2.png)
![manage-step1](/assets/AstralET3.png)
![manage-step1](/assets/AstralET4.png)
![manage-step1](/assets/AstralET5.png)
## Usage Tutorial
- https://astral.fan/quick-start/what-is-astral/
## Introduction
AstralGame is a lightweight game networking tool developed based on **Flutter** and **EasyTier**, designed to provide players with a simple and efficient online gaming experience.
## Features
- **Built-in EasyTier**: Directly integrates EasyTier into AstralGame, eliminating the need for additional installations and leaving no background processes.
- **Plug-and-Play**: Launch the app when connecting, close it when done—simple and convenient.
- **Actively Maintained**: Regular updates ensure quick issue resolution and continuous feature optimization (a productivity boost during work breaks).
## Contact & Support
- **QQ Group**: [Join Our QQ Community](https://qm.qq.com/q/r4VsExDDt6)
- **GitHub Issues**: [Report Bugs or Suggest Features](https://github.com/ldoubil/astral/issues)
+42
View File
@@ -0,0 +1,42 @@
# [EasyTier Game Launcher](https://github.com/EasyTier/EasytierGame)
## Introduction
EasyTier Game Launcher is developed with `nuxt3`, `typescript`, `rust`, and `tauri`. It has a simple interface and comes with the latest EasyTier core. When playing multiplayer games, it provides the most comfortable experience both psychologically and practically. It also supports custom configuration file startup to meet various needs.
## Download
GitHub Releases: [https://github.com/EasyTier/EasytierGame/releases](https://github.com/EasyTier/EasytierGame/releases)
- Only green zip packages are available. Personally, I don't like installers that write to the registry. Just extract and use, keeping the directory clean and tidy.
![game-step1](/assets/game-step1.png)
## Tutorial
- For the first use, enter a "hostname" and click to start the connection. Later, you can create your own server or use servers provided by kind community members.
![game-step2](/assets/game-step2.png)
![game-step3](/assets/game-step3.png)
- There are some special configurations in the advanced options that you can choose from.
![game-step4](/assets/game-step4.png)
- If your needs are still not met, you can use a configuration file to start. For details on how to configure, refer to the documentation [Configuration File](/guide/network/config-file.html).
![game-step5](/assets/game-step5.png)
- After upgrading the EasyTier core, you can click the update plugin button to update. However, you need to use a VPN. If you cannot update, you can get the update from the community.
![game-step6](/assets/game-step6.png)
## Features
- Developed based on the EasyTier networking tool with a clear and simple interface.
- Built-in "Update" button. When the EasyTier networking tool releases a new version, just click update (requires VPN).
- For the first use, enter a "hostname" and click to start the connection. Later, you can create your own server or use community servers.
- Simple configuration with advanced features, also supports custom configuration file startup.
- **WinIPBroadcast** is enabled by default, no longer afraid of not finding rooms when connecting (e.g., Borderlands 3).
- Tested with **Elden Ring learning version**, **Borderlands 3**, **Deep Rock Galactic**, **Monster Hunter World**, etc., all can be played stably.
## System Support
Supports Windows 11, Windows 10, and Windows 7.
+73
View File
@@ -0,0 +1,73 @@
# [EasyTier Manager](https://github.com/xlc520/easytier-manager)
## Download
GitHub Releases: [https://github.com/xlc520/easytier-manager/releases](https://github.com/xlc520/easytier-manager/releases)
#### Package Descriptions
- `exe`: Installer, must be installed before use
- `zip`: Portable, extract and use directly
- `easytier-manager-win_2.0.0.exe`: Universal installer for 64-bit and 32-bit Windows systems
- `easytier-manager-win-x64_2.0.0.exe`: 64-bit Windows system installer
- `easytier-manager-win-ia32_2.0.0.exe`: 32-bit Windows system installer
- `easytier-manager-win7-x64_2.0.0.exe`: 64-bit Windows 7 system installer
- `tar.gz` `deb` `rpm` `AppImage`: For Linux systems (not yet tested)
## Tutorial
- **1. [Important] Settings page: Check if the kernel exists, if not, download the kernel, then install it, and check again if the kernel exists** (only needed for first use, subsequent confirmations can run directly)
![manage-step1](/assets/manage-step1.png)
![manage-step2](/assets/manage-step2.png)
- 2. Configuration page: Create new network configurations, providing both direct code editing and form filling methods
![manage-step3](/assets/manage-step3.png)
![manage-step4](/assets/manage-step4.png)
![manage-step5](/assets/manage-step5.png)
![manage-step6](/assets/manage-step6.png)
- 3. Workspace (home page): Run specified configurations
![manage-step7](/assets/manage-step7.png)
- 4. [Optional] After successful networking, if the connection is fine, you can exit the manager. The core program will run in the background (right-click the tray icon to "Exit")
- 5. [Optional] On the configuration page, install specified configurations as system services
![manage-step8](/assets/manage-step8.png)
![manage-step9](/assets/manage-step9.png)
## Introduction
EasyTier Manager integrates Vue3 + Vite5 + Electron33 + Element-Plus. It is a free and open-source network manager based on `element-plus`. It is developed using the latest mainstream technologies such as `vue3`, `vite5`, `TypeScript`, etc.
## Features
- **Memory Usage**: After successful networking, you can directly exit the manager without affecting the network, so it won't occupy memory or cause memory leaks due to various issues
- **Multi-Configuration Startup**: Supports running and managing multiple network configurations
- **System Service Installation**: One-click installation as a system service with visual interface, auto-start on boot
- **Visual Configuration Addition**: Provides form-based visual addition of network configurations, simple and convenient
- **Visual Log Viewing**: View logs of current network configurations on the home page
- **One-Click Download and Install**: One-click download and installation of the kernel with built-in accelerated sources, no manual download required
- **Latest Tech Stack**: Developed using cutting-edge frontend technologies like Electron33/Vue3/vite5
- **TypeScript**: Application-level JavaScript language
- **Internationalization**: Built-in comprehensive internationalization solution
## Bug Reports & Suggestions
> Tending towards stability, may not develop new features, only fix vulnerabilities and such
You can check [TODO](https://github.com/xlc520/easytier-manager/blob/master/TODO.md) to see if it's already recorded to avoid duplication
[Submit Bug | Feature Request](https://github.com/xlc520/easytier-manager/issues/new/choose)
## System Support
Theoretically supports Windows 11, Windows 10, and Windows 7.
+9
View File
@@ -0,0 +1,9 @@
# Graphical User Interface (GUI) Networking
The graphical interface program can also be downloaded from the GitHub Release page, with the prefix easytier-gui.
Note that after installation on MacOS, you need to execute the following command in the terminal, otherwise, it will mistakenly report that the file is damaged.
```bash
xattr -c /Applications/easytier-gui.app
```
+7
View File
@@ -0,0 +1,7 @@
# Manual Networking
EasyTier does not distinguish between client and server, and is completely decentralized. New nodes only need to establish a connection with any node in the virtual network to join the network. The configuration method is shown in the figure below.
![Manual Networking](/assets/cn/manual.png)
Note: After entering the node IP, you need to click on the list item to confirm. After confirmation, the node address will be displayed in card format.
+66
View File
@@ -0,0 +1,66 @@
# QtEasyTier
## Project Introduction
QtEasyTier is a cross-region networking tool developed based on the Qt framework, designed for creating and managing virtual network connections.
It provides an intuitive graphical interface, helping users easily configure and manage virtual networks to achieve secure communication across network devices.
Project Address: https://gitee.com/viagrahuang/qt-easy-tier
![QtEasyTier](/assets/qteasytier1.png)
## Features
- **Fast:** The program is developed using pure Qt C++, features system-native rendering, does not rely on Chromium or Webview, daily frontend memory usage stays under 50MB, ensuring efficient and fast operation.
- **Beautiful:** The UI style utilizes the Breeze style ported from KDE, providing a clean, aesthetically pleasing, and modern user interface. The program's UI layout is simple, logical, and intuitive, making it easy to learn, especially suitable for scenarios running multiple networks simultaneously.
## Platform Support
- Windows 10/11
- Linux support is planned for the future
- Mac currently has no support plan (primarily because the author doesn't have a Macbook), but contributions from experts are welcome
## Quick Start
For details, please visit the [Help Documentation](https://gitee.com/viagrahuang/qt-easy-tier/blob/master/assets/help.md)
- Double-click `QtEasyTier.exe` to launch the application
- Click the plus sign in the bottom right corner to create a network configuration
- Enter basic information such as network name, username, password, or click 'Import Configuration' below
- Configure advanced options (optional)
- Click the "Run Network" button to initiate the network connection
## Related Projects This Program Depends On or Uses
### EasyTier
A simple, secure, decentralized cross-region networking solution powered by Rust and Tokio.
- Official Website: [https://easytier.cn/](https://easytier.cn/)
### Qt Framework
Qt is a cross-platform C++ application development framework used for creating graphical user interfaces (GUIs) and other applications.
- Official Website: [https://www.qt.io/](https://www.qt.io/)
### Breeze
Breeze is the default theme for the KDE Plasma desktop environment. This program incorporates its style library adapted for the Qt framework to provide users with a beautiful interface.
- Official Website: [https://kde.org/](https://kde.org/)
## Contact the Author
- Project Address: [https://gitee.com/viagrahuang/qt-easy-tier](https://gitee.com/viagrahuang/qt-easy-tier)
- Issue Reporting: Welcome to submit Issues and PRs
- Contact Methods:
- The author is active in the EasyTier Support Group 3, feel free to join for discussion: 957189589
- Bilibili Space: [space.bilibili.com/558600071](https://space.bilibili.com/558600071)
## License
This project is licensed under the GNU General Public License v3.0 (GPLv3). For details, please see the LICENSE file.
## Sponsorship and Support
Software development is not easy. Your sponsorship and support are vital motivation for the continuous development and maintenance of this project, and they also recognize the author's ongoing efforts.
If you find this project helpful, please consider supporting it through the following methods.
1. Contribute a public server: Contact via email viagrahuang@88.com
2. Help fix bugs, add features, port to other platforms, etc.: [Project Address](https://gitee.com/viagrahuang/qt-easy-tier)
+13
View File
@@ -0,0 +1,13 @@
# Subnet Proxy
By setting up a subnet proxy, you can connect the local area network and the virtual local area network.
Assuming the devices at home are in the 192.168.1.0/24 subnet, and you want to access any device at home from the company, you can start an EasyTier node at home and add a subnet proxy for 192.168.1.0/24. No additional configuration is needed on the company's devices; simply connect to the home node successfully, and you can access any device at home.
![Subnet Proxy Configuration](/assets/cn/subnet.png)
Note: After entering the subnet, you need to click on the list item to confirm. After successful confirmation, the subnet will be displayed in card format.
Subnet proxy can perform subnet mapping.
![Subnet Proxy Configuration](/assets/cn/subnet-mapping.png)
+11
View File
@@ -0,0 +1,11 @@
# WireGuard Access
Each node in EasyTier can act as a WireGuard server, allowing mobile devices such as Android and iOS to easily access devices in the virtual LAN.
Configuration method as shown in the figure.
![Wireguard Portal Config](/assets/cn/portal.png)
Click the "Show WireGuard Portal Configuration" button on the network success page to view the client configuration file. Import this configuration file into a third-party client on your phone to allow the phone to access the virtual LAN.
![Client Config](/assets/cn/portal_config.png)
+98 -11
View File
@@ -1,19 +1,106 @@
# Installation {#installation}
# Installation (Command Line Program) {#installation}
1. **Download the precompiled binary file**
Visit the [GitHub Release page](https://github.com/KKRainbow/EasyTier/releases) to download the binary file suitable for your operating system. Release includes both command-line programs and GUI programs in the compressed package.
This section only introduces installation methods.
2. **Install via crates.io**
## Installation Methods
1. **Manual Download of Command Line Program**
::: code-group
```sh [cargo]
cargo install easytier
```bash [Linux / MacOS / FreeBSD]
./easytier-core --version
```
```powershell [Windows]
.\easytier-core.exe --version
```
:::
3. **Install from source code**
::: code-group
```sh [cargo]
cargo install --git https://github.com/KKRainbow/EasyTier.git
***
2. **DockerHub**
[DockerHub Image Address](https://hub.docker.com/r/easytier/easytier)
```sh [docker]
# docker.io image
docker pull easytier/easytier:latest
docker run -d --privileged --network host easytier/easytier:latest
# Domestic users can use DaoCloud image
docker pull m.daocloud.io/docker.io/easytier/easytier:latest
docker run -d --privileged --network host m.daocloud.io/docker.io/easytier/easytier:latest
```
:::
***
3. **Install via Docker Compose**
::: details docker-compose.yml
```yaml [docker-compose.yml]
services:
watchtower: # Used to automatically update easytier image, delete this part if not needed
image: containrrr/watchtower
container_name: watchtower
restart: unless-stopped
environment:
- TZ=Asia/Shanghai
- WATCHTOWER_NO_STARTUP_MESSAGE
volumes:
- /var/run/docker.sock:/var/run/docker.sock
command: --interval 3600 --cleanup --label-enable
easytier:
image: easytier/easytier:latest # Domestic users can use m.daocloud.io/docker.io/easytier/easytier:latest
hostname: easytier
container_name: easytier
labels:
com.centurylinklabs.watchtower.enable: 'true'
restart: unless-stopped
network_mode: host
cap_add:
- NET_ADMIN
- NET_RAW
environment:
- TZ=Asia/Shanghai
devices:
- /dev/net/tun:/dev/net/tun
volumes:
- /etc/easytier:/root
- /etc/machine-id:/etc/machine-id:ro # Map host machine code
command: -d --network-name <user> --network-secret <password> -p tcp://<your-public-ip>:11010
```
:::
***
4. **One-Click Installation Script (Linux Only)**
Note: The one-click script depends on `unzip`, please download and install it in advance.
```bash
wget -O /tmp/easytier.sh "https://raw.githubusercontent.com/EasyTier/EasyTier/main/script/install.sh" && sudo bash /tmp/easytier.sh install --gh-proxy https://ghfast.top/
```
After the script executes successfully, EasyTier's binary programs will be installed in the `/opt/easytier` directory, and the configuration file is located at `/opt/easytier/config/default.conf`.
The configuration file can be generated through the [Configuration File Generator](https://easytier.cn/web/index.html#/config_generator).
EasyTier will be registered as a system service and can be managed with the following commands:
```bash
systemctl start easytier@default
```
***
5. **Install from Source**
```sh [cargo]
cargo install --git https://github.com/EasyTier/EasyTier.git easytier
```
Source installation requires Rust environment and LLVM installation.
+79
View File
@@ -0,0 +1,79 @@
# Installation (Graphical Interface) {#installation_gui}
## EasyTier GUI
Please note that EasyTier GUI relies on WebView, and the following common issues may occur:
1. On lower versions of Windows, WebView download may fail due to domestic network environment issues, making it impossible to download WebView components. Please manually install [WebView2](https://developer.microsoft.com/en-US/microsoft-edge/webview2/) or [Edge](https://www.microsoft.com/en-us/edge) browser.
2. On lower versions of Android, styles may be lost, and display may be chaotic. Please manually update the WebView component in the app store.
## Third-party Graphical Interfaces
### [EasyTier Game (Windows)](/guide/gui/easytier-game)
EasyTierGame is a game networking launcher developed using nuxt3, typescript, rust, and tauri. It features a simple interface and includes the latest version of the EasyTier core. When playing games, it provides the most comfortable experience both psychologically and in usage, while supporting custom configuration file launches to meet various needs.
---
### [EasyTier Manager (Windows)](/guide/gui/easytier-manager)
EasyTier Manager is a desktop application used to manage the EasyTier core. It provides visualized operations for adding, modifying, and deleting EasyTier configuration files.
- Supports one-click start and stop of group networks through the interface.
- Supports modification of all existing core parameters, with all new and modified operations supporting both interface-based forms and text editor operations.
- Supports viewing current running logs through the interface.
- Supports one-click download of any version of the core (Note: Many parameters and features of older versions are not supported).
---
### [Astral Game (Windows / Android / Linux)](/guide/gui/astral-game)
AstralGame is a cross-platform network application based on EasyTier, providing simple and easy-to-use P2P network connections and VPN services. Built with Flutter, its modern interface allows users to easily create and manage virtual networks.
---
### [luci-app-easytier (OpenWrt)](https://github.com/EasyTier/luci-app-easytier)
EasyTier's OpenWrt plugin provides methods for installing and configuring the EasyTier core on OpenWrt routers. The plugin supports completing the installation, configuration, and management of the EasyTier core within OpenWrt's LuCI interface. Users can conveniently configure the core, view running logs, restart the core, and perform other operations through the LuCI interface.
---
### [EasyTier HarmonyOS Edition (HarmonyOS 5 – Latest)](https://appgallery.huawei.com/app/detail?id=top.frankhan.easytier&channelId=SHARE&source=appshare)
EasyTier HarmonyOS Edition is a native HarmonyOS app developed as a secondary project based on EasyTier. It uses ArkTS to implement a modern UI, provides VPN services and configuration management, allows quick importing of community-shared nodes, and supports new HarmonyOS features such as Tap-to-Share.
Note that in the future, compatibility with HarmonyOS 5 (API18-) may be dropped in order to reduce compatibility code and keep the best possible compatibility with HarmonyOS 6 (API20+) and above.
<div align="left">
<a href="https://appgallery.huawei.com/app/detail?id=top.frankhan.easytier&channelId=SHARE&source=appshare" target="_blank">
<img src="/assets/HomoTier_AppGallery.png" width="204" height="51" />
</a>
</div>
---
### [Terracotta | TaoWa Multiplayer (Windows / Android / Linux)](https://github.com/burningtnt/Terracotta)
Terracotta | TaoWa Multiplayer provides Minecraft players with an out-of-the-box multiplayer experience. TaoWa Multiplayer is developed based on EasyTier and includes extensive optimizations specifically for MC, aiming to lower the barrier to entry as much as possible.
It has now been integrated into the HMCL launcher—you can try the program features in the latest version, or download this program to experience it directly.
---
### [EasyTier iOS (iOS 16.0+)](https://github.com/EasyTier/EasyTier-iOS)
The iOS client for EasyTier, offering a user-friendly interface for connecting to the EasyTier network on iOS devices, and implementing system-level VPN integration using the Network Extension framework.
[TestFlight Invitation](https://testflight.apple.com/join/YWnDyJfM) (free, preview version, limited slots, periodically cleaned up)
---
### [QtEasyTier (Windows)](/guide/gui/qteasytier)
A powerful and user-friendly EasyTier frontend developed with Qt Widgets. Built with pure Qt C++ and native rendering, it is efficient and does not rely on WebView or Chromium.
QtEasyTier simplifies setup with one-click import/export of configurations and supports running multiple networks simultaneously. Its main interface provides a clear overview of all network statuses.
- Project: [https://gitee.com/viagrahuang/qt-easy-tier](https://gitee.com/viagrahuang/qt-easy-tier)
- Demo Video: [https://www.bilibili.com/video/BV1ST6nBzE1k](https://www.bilibili.com/video/BV1ST6nBzE1k)
+33 -16
View File
@@ -1,20 +1,37 @@
# Introduction
EasyTier is a simple, safe and decentralized VPN networking solution implemented with the Rust language and Tokio framework.
EasyTier is a simple, secure, decentralized tool for intranet penetration and remote networking, suitable for various scenarios such as remote work, remote access, and game acceleration. It requires no public IP and no complex configuration, enabling secure interconnection between devices in different locations with ease.
![alt text](/assets/image-5.png)
![alt text](/assets/image-4.png)
The software can be used via command line or graphical interface. It is ready to use after download, with no additional dependencies.
## Features
- **Decentralized**: No need to rely on centralized services, nodes are equal and independent.
- **Safe**: Use WireGuard protocol to encrypt data.
- **High Performance**: Full-link zero-copy, with performance comparable to mainstream networking software.
- **Cross-platform**: Supports MacOS/Linux/Windows, will support IOS and Android in the future. The executable file is statically linked, making deployment simple.
- **Networking without public IP**: Supports networking using shared public nodes, refer to [Configuration Guide](/guide/network/without-public-ip.md)
- **NAT traversal**: Supports UDP-based NAT traversal, able to establish stable connections even in complex network environments.
- **Subnet Proxy (Point-to-Network)**: Nodes can expose accessible network segments as proxies to the VPN subnet, allowing other nodes to access these subnets through the node.
- **Smart Routing**: Selects links based on traffic to reduce latency and increase throughput.
- **TCP Support**: Provides reliable data transmission through concurrent TCP links when UDP is limited, optimizing performance.
- **High Availability**: Supports multi-path and switches to healthy paths when high packet loss or network errors are detected.
- **IPv6 Support**: Supports networking using IPv6.
- [🛠️ CLI Installation Page](./installation) provides methods for installing the command-line tool.
- [🖥️ GUI Installation Page](./installation_gui) provides methods for installing the graphical interface tool.
## Applicable Scenarios
- **Remote Work**: Make computers at the company, home, and remote locations communicate as if they are on the same local network.
- **Remote Access**: Securely access home NAS, servers, or other devices anytime, anywhere.
- **Game Acceleration**: Build a virtual local area network to enjoy multiplayer games.
- **IoT Networking**: Securely interconnect devices distributed across different locations.
## Core Features
- **Decentralized**: No reliance on central servers; all nodes are equal and independent, capable of forwarding and networking.
- **Secure Encryption**: Supports WireGuard and AES-GCM encryption to ensure data security.
- **Cross-Platform**: Supports MacOS, Linux, Windows, FreeBSD, Android, and will support iOS in the future.
- **Networking Without Public IP**: Enables networking using shared public nodes.
- **NAT Traversal**: Supports UDP NAT traversal for stable connections in complex network environments.
- **Intelligent Routing**: Automatically selects the best link to reduce latency and increase throughput.
- **High Availability**: Supports multipath and automatically switches to healthy links to improve stability.
## Advanced Features
- **KCP / QUIC Proxy**: Converts TCP traffic to KCP / QUIC protocol, improving transmission latency and stability in high UDP packet loss environments.
- **Non-Privileged Mode**: Supports running under non-privileged users, avoiding the need for root permissions (only as an accessed endpoint).
- **WireGuard Access**: Supports WireGuard client access to the EasyTier network.
## Graphical Interface (GUI)
EasyTier provides a simple and user-friendly graphical interface, suitable for beginners to get started quickly.
<img src="/assets/gui-screenshot.png" alt="EasyTier GUI Screenshot" width="400">
+2 -2
View File
@@ -1,3 +1,3 @@
# License
EasyTier is released under the [Apache License 2.0](https://github.com/KKRainbow/EasyTier/blob/main/LICENSE).
EasyTier is released under the [LGPL 3.0](https://github.com/EasyTier/EasyTier/blob/main/LICENSE).
+27
View File
@@ -0,0 +1,27 @@
# Configuration File
Supports using the -c parameter to specify the configuration file path.
```sh
easytier-core -c ./config.yaml
```
::: warning Note
Note: Parameters in the configuration file can be overridden by command line parameters. For example, if `--hostname abc` is specified in the configuration file, but `--hostname xyz` is used in the command line, then the hostname parameter `xyz` from the command line will be used.
:::
Running with parameters can generate a configuration file with the corresponding parameters. The configuration file will be printed in the command line, and you can manually copy and save it as a toml file.
Running `easytier-core` directly without parameters will generate the minimal configuration file.
## Multiple Configuration Files Startup
You can specify multiple configuration files through the `-c` parameter. EasyTier will load multiple configuration files in one process and start multiple virtual networks.
```sh
easytier-core -c ./config1.yaml -c ./config2.yaml
```
## Configuration File Generator
The official website provides a configuration file generator, which you can access via <a target="_blank" href="https://easytier.cn/web/index.html#config_generator">Configuration File Generator</a> to generate configuration files.
+120
View File
@@ -0,0 +1,120 @@
# Complete Configuration Options
You can use `easytier-core --help` to view all configuration options.
## Basic Settings
### Configuration Server
| Parameter | Description |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-w, --config-server` | Configuration server address. Allowed formats: |
| | - Full URL: `--config-server udp://127.0.0.1:22020/admin` |
| | - Username only: `--config-server admin`, will use the official server |
| | [env: ET_CONFIG_SERVER=] |
| `--machine-id` | Web configuration server identifies machines through machine id, used for configuration recovery after disconnection and reconnection, must be unique and fixed. Default obtained from system. [env: ET_MACHINE_ID=] |
| `-c, --config-file` | Configuration file path, note: options configured in command line will override options in configuration file [env: ET_CONFIG_FILE=] |
| `--config-dir` | Load all .toml files in the directory to start network instances, and store the received configurations in this directory. [env: ET_CONFIG_DIR=] |
| `--disable-env-parsing` | Disable environment variable parsing in config file [env: ET_DISABLE_ENV_PARSING=] |
### Network Settings
| Parameter | Description |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--network-name` | Network name used to identify this VPN network [env: ET_NETWORK_NAME=] |
| `--network-secret` | Network secret, used to verify that this node belongs to the VPN network [env: ET_NETWORK_SECRET=] |
| `-i, --ipv4` | IPv4 address of this VPN node. If empty, this node will only forward packets and will not create a TUN device [env: ET_IPV4=] |
| `--ipv6` | IPv6 address of this VPN node, can be used together with ipv4 for dual-stack operation [env: ET_IPV6=] |
| `-d, --dhcp` | Automatically determine and set IP address by Easytier, default starts from 10.0.0.1. Warning: When using DHCP, if IP conflicts occur in the network, IP will be automatically changed. [env: ET_DHCP=] |
| `-p, --peers` | Peer nodes to connect to initially [env: ET_PEERS=] |
| `-e, --external-node` | Use public shared nodes to discover peer nodes [env: ET_EXTERNAL_NODE=] |
| `-n, --proxy-networks` | Export local network to other peer nodes in VPN, e.g.: `10.0.0.0/24`. Supports mapping to other CIDR, e.g.: `10.0.0.0/24->192.168.0.0/24` [env: ET_PROXY_NETWORKS=] |
### RPC Settings
| Parameter | Description |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| `-r, --rpc-portal` | RPC portal address for management. Supports the following formats: |
| | - `0` means random port |
| | - `12345` means listen on localhost:12345 |
| | - `0.0.0.0:12345` means listen on all interfaces:12345 |
| | Default is `0`, first try `15888` |
| | [env: ET_RPC_PORTAL=] |
| `--rpc-portal-whitelist` | RPC portal whitelist, only allow these addresses to access RPC portal, e.g.: `127.0.0.1/32,127.0.0.0/8,::1/128` [env: ET_RPC_PORTAL_WHITELIST=] |
### Listener Settings
| Parameter | Description |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-l, --listeners` | Listeners for accepting connections, supports the following formats: |
| | - Port number: `<11010>`, means tcp/udp will listen on port 11010, ws/wss will listen on ports 11010 and 11011, wg will listen on port 11011. |
| | - URL: `<protocol://0.0.0.0:11010>`, where protocol can be tcp, udp, ring, wg, ws, wss, quic, faketcp protocols. |
| | - Protocol and port pair: `<proto:port>`, e.g. wg:11011, means use WireGuard protocol to listen on port 11011. |
| | [env: ET_LISTENERS=] |
| `--mapped-listeners` | Manually specify the public address of the listener, other nodes can use this address to connect to this node. E.g.: `tcp://123.123.123.123:11223`, can specify multiple. [env: ET_MAPPED_LISTENERS=] |
| `--no-listener` | Don't listen on any port, only connect to peer nodes [env: ET_NO_LISTENER=] |
### Other Settings
| Parameter | Description |
| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--hostname` | Hostname used to identify this device [env: ET_HOSTNAME=] |
| `-m, --instance-name` | Instance name, used to identify this VPN node on the same machine [env: ET_INSTANCE_NAME=] |
| `--vpn-portal` | Define the URL of the VPN portal, allowing other VPN clients to connect. E.g.: `wg://0.0.0.0:11010/10.14.14.0/24` [env: ET_VPN_PORTAL=] |
| `--default-protocol` | Default protocol used when connecting to peer nodes [env: ET_DEFAULT_PROTOCOL=] |
| `-u, --disable-encryption` | Disable encryption for peer node communication, default is false, must be the same as peer nodes [env: ET_DISABLE_ENCRYPTION=] |
| `--encryption-algorithm` | Encryption algorithm to use, supported: '', 'xor', 'chacha20', 'aes-gcm', 'aes-gcm-256', 'openssl-aes128-gcm', 'openssl-aes256-gcm', 'openssl-chacha20' [env: ET_ENCRYPTION_ALGORITHM=] |
| `--multi-thread` | Use multi-threaded runtime, default is single-threaded [env: ET_MULTI_THREAD=] |
| `--multi-thread-count` | The number of threads to use, default is 2, only effective when multi-thread is enabled, must be greater than 2 [env: ET_MULTI_THREAD_COUNT=] |
| `--disable-ipv6` | Don't use IPv6 [env: ET_DISABLE_IPV6=] |
| `--dev-name` | Optional TUN interface name [env: ET_DEV_NAME=] |
| `--mtu` | MTU of TUN device, default is 1380 when not encrypted, 1360 when encrypted [env: ET_MTU=] |
| `--latency-first` | Latency priority mode, will try to use the lowest latency path to forward traffic, default uses shortest path [env: ET_LATENCY_FIRST=] |
| `--exit-nodes` | Exit nodes for forwarding all traffic, virtual IPv4 addresses, priority determined by list order [env: ET_EXIT_NODES=] |
| `--enable-exit-node` | Allow this node to become an exit node [env: ET_ENABLE_EXIT_NODE=] |
| `--proxy-forward-by-system` | Forward subnet proxy packets through system kernel, disable built-in NAT [env: ET_PROXY_FORWARD_BY_SYSTEM=] |
| `--no-tun` | Don't create TUN device, can use subnet proxy to access nodes [env: ET_NO_TUN=] |
| `--use-smoltcp` | Enable smoltcp stack for subnet proxy and KCP proxy [env: ET_USE_SMOLTCP=] |
| `--manual-routes` | Manually assign route CIDR, will disable subnet proxy and wireguard routes propagated from peer nodes. E.g.: `192.168.0.0/16` [env: ET_MANUAL_ROUTES=] |
| `--relay-network-whitelist` | Only forward traffic from whitelisted networks, supports wildcard strings. Multiple network names can be separated by English spaces. [env: ET_RELAY_NETWORK_WHITELIST=] |
| `--disable-p2p` | Disable P2P communication, only forward packets through nodes specified by `--peers` [env: ET_DISABLE_P2P=] |
| `--p2p-only` | Only communicate with peers that already establish p2p connection [env: ET_P2P_ONLY=] |
| `--disable-tcp-hole-punching` | Disable TCP hole punching function [env: ET_DISABLE_TCP_HOLE_PUNCHING=] |
| `--disable-udp-hole-punching` | Disable UDP hole punching function [env: ET_DISABLE_UDP_HOLE_PUNCHING=] |
| `--disable-sym-hole-punching` | If true, disable UDP NAT hole punching for symmetric NAT (NAT4), which is based on birthday attack and may be blocked by ISP [env: ET_DISABLE_SYM_HOLE_PUNCHING=] |
| `--relay-all-peer-rpc` | Forward RPC packets from all peer nodes, even if peer nodes are not in the relay network whitelist. [env: ET_RELAY_ALL_PEER_RPC=] |
| `--socks5` | Enable socks5 server, allowing socks5 clients to access virtual network. Format: `<port>`, e.g.: `1080` [env: ET_SOCKS5=] |
| `--compression` | Compression algorithm to use, supports `none`, `zstd`. Default is `none` [env: ET_COMPRESSION=] |
| `--bind-device` | Bind the connector's socket to a physical device to avoid routing issues. [env: ET_BIND_DEVICE=] |
| `--enable-kcp-proxy` | Use KCP proxy for TCP streams, improving latency and throughput on UDP packet loss networks. [env: ET_ENABLE_KCP_PROXY=] |
| `--disable-kcp-input` | Don't allow other nodes to use KCP proxy TCP streams to this node. [env: ET_DISABLE_KCP_INPUT=] |
| `--enable-quic-proxy` | Use QUIC proxy for TCP streams, improving latency and throughput on UDP packet loss networks. [env: ET_ENABLE_QUIC_PROXY=] |
| `--disable-quic-input` | Don't allow other nodes to use QUIC proxy TCP streams to this node. [env: ET_DISABLE_QUIC_INPUT=] |
| `--quic-listen-port` | The port to listen for QUIC connections, default is 0 (random port) [env: ET_QUIC_LISTEN_PORT=] |
| `--port-forward` | Forward local ports to remote ports in virtual network. E.g.: `udp://0.0.0.0:12345/10.126.126.1:23456` [env: ET_PORT_FORWARD=] |
| `--accept-dns` | If true, enable Magic DNS. With Magic DNS, you can use domain names to access other nodes, e.g.: `<hostname>.et.net` [env: ET_ACCEPT_DNS=] |
| `--tld-dns-zone` | Specify the top-level DNS zone for Magic DNS. If not provided, use the dns_server module default (et.net.). Used only when accept_dns is true. [env: ET_TLD_DNS_ZONE=] |
| `--private-mode` | If true, don't allow nodes using different network names and passwords from this network to handshake or relay through this node [env: ET_PRIVATE_MODE=] |
| `--foreign-relay-bps-limit` | Limit bandwidth for relayed traffic [env: ET_FOREIGN_RELAY_BPS_LIMIT=] |
| `--tcp-whitelist` | TCP port whitelist. Supports single ports (80) and ranges (8000-9000) [env: ET_TCP_WHITELIST=] |
| `--udp-whitelist` | UDP port whitelist. Supports single ports (53) and ranges (5000-6000) [env: ET_UDP_WHITELIST=] |
| `--disable-relay-kcp` | If true, disable relay KCP packets. Avoid consuming too many bandwidth. Default is false [env: ET_DISABLE_RELAY_KCP=] |
| `--enable-relay-foreign-network-kcp` | If true, allow relay KCP packets from foreign network. Default is false [env: ET_ENABLE_RELAY_FOREIGN_NETWORK_KCP=] |
| `--stun-servers` | Override default STUN servers; If configured but empty, STUN servers are not used [env: ET_STUN_SERVERS=] |
| `--stun-servers-v6` | Override default STUN servers, IPv6; If configured but empty, IPv6 STUN servers are not used [env: ET_STUN_SERVERS_V6=] |
### Logging Settings
| Parameter | Description |
| --------------------- | ------------------------------------------------------------------ |
| `--console-log-level` | Console log level [env: ET_CONSOLE_LOG_LEVEL=] |
| `--file-log-level` | File log level [env: ET_FILE_LOG_LEVEL=] |
| `--file-log-dir` | Directory to store log files [env: ET_FILE_LOG_DIR=] |
| `--file-log-size` | Per file log size in MB, default is 100MB [env: ET_FILE_LOG_SIZE=] |
| `--file-log-count` | Max file log count, default is 10 [env: ET_FILE_LOG_COUNT=] |
---
For more configuration options, please refer to the output of `easytier-core --help`.
---
@@ -0,0 +1,93 @@
# Decentralized Networking
Most networking software is centralized, where all devices must connect to a central server to form a network.
EasyTier is decentralized, with no distinction between server and client. As long as one device can communicate with any node in the virtual network, it can join the virtual network.
## Two-Node Networking {#two-nodes}
Assume the network topology of two nodes is as follows:
```mermaid
flowchart LR
subgraph Node A [Physical NIC IP: 22.1.1.1]
nodeA[EasyTier<br/>Virtual IP: 10.144.144.1]
end
subgraph Node B [Physical NIC IP: 33.1.1.1]
nodeB[EasyTier<br/>Virtual IP: 10.144.144.2]
end
nodeA <-----> nodeB
```
### Steps
1. Run the following command on Node A:
```sh
sudo easytier-core -i 10.144.144.1
```
- `-i` specifies the virtual network IP address.
After startup, this node will listen on the following ports by default:
| Protocol | Default Port |
| ------------- | ------------ |
| TCP | 11010 (TCP) |
| UDP | 11010 (UDP) |
| WebSocket | 11011 (TCP) |
| WebSocket SSL | 11012 (TCP) |
| WireGuard | 11011 (UDP) |
| QUIC | 11012 (UDP) |
| FakeTCP | 11013 |
You can specify listening ports through the `-l` parameter, for example:
| Parameter Example | Description |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-l 12345` | Change the base port to 12345, then listening ports are: TCP: 12345, UDP: 12345, WebSocket: 12346, WebSocket SSL: 12347, WireGuard: 12348 |
| `-l tcp:11010 -l udp:11011` | Change TCP port to 11010, UDP port to 11011, only listen on these two ports. Supported protocols are `tcp`, `udp`, `ws`, `wss`, `wg`, `quic`, `faketcp` |
| `--no-listener` | Disable port listening, which will affect the establishment of non-hole-punching connections. |
2. Run the following command on Node B:
```sh
sudo easytier-core -d -p udp://22.1.1.1:11010
```
- `-d` represents DHCP mode, automatically assign virtual IP.
- `-p` specifies the public address and port of Node A.
## Three-Node Networking
Based on two-node networking, the third node C can join the virtual network by connecting to Node A or Node B.
Assume networking by connecting to Node A, the network topology is as follows:
```mermaid
flowchart LR
subgraph Node A [Physical NIC IP: 22.1.1.1]
nodeA[EasyTier<br/>Virtual IP: 10.144.144.1]
end
subgraph Node C [Newly Added]
nodeC[EasyTier<br/>Virtual IP: 10.144.144.3]
end
subgraph Node B [Physical NIC IP: 33.1.1.1]
nodeB[EasyTier<br/>Virtual IP: 10.144.144.2]
end
nodeA <-----> nodeB
nodeC <-----> nodeA
```
### Steps
1. Run the following command on Node C:
```sh
sudo easytier-core -d -p udp://22.1.1.1:11010
```
- `-d` represents DHCP mode, automatically assign virtual IP.
- `-p` specifies the public address and port of Node A.
Subsequently, Node C can communicate with Node A and Node B through the virtual network.
+33
View File
@@ -0,0 +1,33 @@
# Setting Up a Shared Node
Users can use their own public nodes to set up a public shared node for networking without a public IP, making it easier for other users without a public IP to network. Simply start EasyTier without any parameters, and the node can be used as a public server (no root privileges required):
```
easytier-core
```
Additionally, EasyTier supports shared node clusters. Each virtual network (created with the same network name and key) can act as a shared node cluster, and nodes from other networks can connect to any node in the shared node cluster, discovering each other without a public IP. Running a self-built public server cluster is the same as running a virtual network, but you can skip configuring the IPv4 address.
If you wish to contribute a public server to the EasyTier community, you can contact the administrator, and we will inform you how to add your node to the community shared node list. Of course, this requires your node to have a certain level of bandwidth and stability.
## Disable Forwarding
By default, each EasyTier node allows forwarding services for other virtual networks, even if the node has specified a network name (`--network-name`) and network key (`--network-secret`), and has joined a virtual network.
To change this behavior, you can use the `--relay-network-whitelist` parameter to specify a whitelist of network names that can be forwarded (a space-separated list of wildcards, such as `"ab* abc"`). When this parameter's list is empty, it will not provide forwarding services for any other networks.
EasyTier can avoid forwarding network packets for other virtual networks and only help them establish P2P links by setting the whitelist to empty and configuring it to only forward RPC traffic. The reference command is:
```
easytier-core --relay-network-whitelist --relay-all-peer-rpc
```
## Private Mode
If you want EasyTier to only provide services in your virtual network and don't want nodes from other virtual networks to connect to your node, you can start EasyTier with the `--private-mode true` parameter.
```
sudo easytier-core --private-mode true --network-name my-network --network-secret my-secret
```
This will only allow nodes with network name `my-network` and key `my-secret` to connect to this EasyTier node.

Some files were not shown because too many files have changed in this diff Show More