# zfl9/ss-tproxy

ss/v2ray/xray/trojan/hysteria/naive/socks5 透明代理

Repository: https://github.com/zfl9/ss-tproxy
Canonical: https://ross.abutalabs.com/products/ss-tproxy
Language: Shell
License: AGPL-3.0
License Family: copyleft
Topics: ss, ssr, v2ray, socks5, transparent-proxy, gfwlist, chnroute, tproxy, proxy, shadowsocks, trojan, xray, clash, hysteria, naive, iptables, nftables, ss-tproxy
Last push: 2026-01-15T01:44:48+00:00

## Health v2 (maintenance only)
Score: 51/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 62, release rhythm 8, longevity 100
- inputs: {"age_days": 3216, "days_push": 231, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2394, forks 440 (observed 2026-08-28T04:06:43.490690+00:00)

## What it is
A shell script that sets up transparent proxying on Linux using iptables/nftables TPROXY and REDIRECT rules, working with clients like ss-libev, v2ray, xray, trojan, hysteria, and naive. It provides split-routing modes (global, gfwlist, chnroute, return-to-China) with clean DNS resolution via chinadns-ng.

## Use cases
- set up a transparent proxy on a Linux router
- proxy all LAN traffic through a gateway without configuring each app
- route only GFW-blocked sites through the proxy
- bypass proxy for Chinese IPs with chnroute split routing
- get pollution-free DNS resolution alongside a transparent proxy
- run a bypass gateway (旁路由) for the home network
- transparently proxy UDP as well as TCP traffic
- convert a socks5-only proxy client into a transparent proxy

## When to choose
- you run Linux (router, gateway, or desktop) and want system-wide transparent proxying
- you use ss/v2ray/xray/trojan/hysteria clients that support transparent proxy input, or socks5 with ipt2socks
- you need split-tunneling modes like gfwlist or chnroute with clean DNS
- you want a scriptable, dependency-light solution instead of a full proxy platform

## When to avoid
- you need a GUI or one-click client on Windows/macOS/Android/iOS
- you prefer an all-in-one proxy platform like Clash with rule management UI
- your environment lacks root access or iptables/nftables TPROXY support
- you only need a simple local socks5/http forward proxy without transparent interception

## Facets
- artifact type: cli-tool
- maturity: active
- function: proxy, networking, security
- domain: networking, privacy, censorship-circumvention, self-hosted
- platform: cli, self-hosted
- tags: transparent-proxy, iptables, nftables, tproxy, shadowsocks, v2ray, xray, trojan, hysteria, gfwlist, chnroute, shell-script, router, split-tunneling, command-line, linux

## Member repositories
- zfl9/ss-tproxy (main) score 51

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:43.490690+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:34:24.656733+00:00, confidence not recorded.
  - readme: https://github.com/zfl9/ss-tproxy (fetched 2026-08-28T04:06:43.490690+00:00, sha 005fa72b6603)
- Data as of 2026-08-30T08:39:29.467469+00:00.
