Larkin 我也在考虑这个做法,但好像实现起来也比较麻烦。 用nchnroutes非cnip来搭建bird服务 路由器配置ospf 让非cnip走Surge网关 Surge有fakeip,而且没有开dns监听端口,可能要在Surge所在Mac上开一个dns服务 dns服务对于国内域名返回真实ip,对于国外ip返回fakeip 内网使用这个dns服务
Hyejeongdd SurgeTeam 明白, AND,((SRC-IP,10.10.1.59), (RULE-SET,https://raw.githubusercontent.com/blackmatrix7/ios_rule_script/master/rule/Surge/GoogleFCM/GoogleFCM.list,extended-matching)),REJECT AND,((SRC-IP,10.10.1.60), (RULE-SET,https://raw.githubusercontent.com/blackmatrix7/ios_rule_script/master/rule/Surge/GoogleFCM/GoogleFCM.list,extended-matching)),REJECT AND,((SRC-IP,10.10.1.61), (RULE-SET,https://raw.githubusercontent.com/blackmatrix7/ios_rule_script/master/rule/Surge/GoogleFCM/GoogleFCM.list,extended-matching)),REJECT 我的需求是 10.10.1.70 - 10.10.1.100 需要拦截 FCM 服务,有什么更优雅的写法吗?
mieqq Hyejeongdd 目前应该只能用多个cidr来表示 10.10.1.70/31 10.10.1.72/29 10.10.1.80/28 10.10.1.96/30 10.10.1.100/32
mieqq Hyejeongdd AND,((OR,((SRC-IP,10.10.1.100/32), (SRC-IP,10.10.1.96/30), (SRC-IP,10.10.1.80/28), (SRC-IP,10.10.1.72/29), (SRC-IP,10.10.1.70/31))), (RULE-SET,https://raw.githubusercontent.com/blackmatrix7/ios_rule_script/master/rule/Surge/GoogleFCM/GoogleFCM.list,extended-matching)),REJECT 另外可以这样合并成一个逻辑规则