Files
layer4-proxy/README.md

80 lines
2.5 KiB
Markdown
Raw Permalink Normal View History

# l4p
2021-10-21 16:43:59 +08:00
> Hey, now we are on level 4!
2021-10-21 16:43:59 +08:00
![CI](https://drone-ci.kiers.eu/api/badges/jjkiers/layer4-proxy/status.svg)
2021-10-25 22:29:02 +08:00
`l4p` is a layer 4 proxy implemented by Rust to listen on specific ports and transfer TCP data to remote addresses (only TCP) according to the configuration.
2021-10-26 23:58:00 +08:00
## Features
2021-10-21 16:43:59 +08:00
- Listen on specific port and proxy to local or remote port
- SNI-based rule without terminating TLS connection
- DNS-based backend with periodic resolution
2021-10-21 16:43:59 +08:00
## Installation
2021-10-21 16:43:59 +08:00
To gain best performance on your computer's architecture, please consider build the source code. First, you may need [Rust tool chain](https://rustup.rs/).
2021-10-21 16:43:59 +08:00
```bash
$ cd l4p
2021-10-21 16:43:59 +08:00
$ cargo build --release
```
Binary file will be generated at `target/release/l4p`, or you can use `cargo install --path .` to install.
2021-10-21 16:43:59 +08:00
Or you can use Cargo to install `l4p`:
2021-10-26 21:40:40 +08:00
```bash
$ cargo install l4p
2021-10-26 21:40:40 +08:00
```
Or you can download binary file form the Release page.
2021-11-01 15:56:57 +08:00
2026-04-03 00:31:05 +02:00
## Features
- Listen on specific port and proxy to local or remote port
- SNI-based rule without terminating TLS connection
- Wildcard SNI matching with DNS-style longest-suffix-match
- DNS-based backend with periodic resolution
## Configuration
2021-10-21 16:43:59 +08:00
`l4p` will read yaml format configuration file from `/etc/l4p/l4p.yaml`, and you can set custom path to environment variable `L4P_CONFIG`, here is an minimal viable example:
2021-10-21 16:43:59 +08:00
```yaml
version: 1
log: info
servers:
2021-10-26 21:36:12 +08:00
proxy_server:
2021-10-21 16:43:59 +08:00
listen:
- "127.0.0.1:8081"
default: remote
upstream:
remote: "tcp://www.remote.example.com:8082" # proxy to remote address
2021-10-21 16:43:59 +08:00
```
There are two upstreams built in:
* Ban, which terminates the connection immediately
* Echo, which reflects back with the input
2021-10-21 16:43:59 +08:00
For detailed configuration, check [this example](./config.yaml.example).
2021-10-21 16:43:59 +08:00
2026-04-03 00:31:05 +02:00
### SNI Matching
The proxy supports both exact and wildcard SNI patterns in the `sni` config. Wildcards use DNS-style longest-suffix-match: more specific patterns take precedence. For example, with `*.example.com` and `*.api.example.com`, request `api.example.com` matches the first, while `v2.api.example.com` matches the second.
Wildcards are validated against the Public Suffix List (PSL). Known suffixes (`.com`, `.org`) require at least one label below the suffix (`*.example.com` OK, `*.com` rejected). Unknown suffixes (`.local`, `.lan`) are allowed without restriction.
Invalid wildcard patterns are rejected at config load time with clear error messages.
## Thanks
2021-10-26 23:02:05 +08:00
- [`fourth`](https://crates.io/crates/fourth), of which this is a heavily modified fork.
2021-10-26 23:02:05 +08:00
## License
2021-10-21 16:43:59 +08:00
`l4p` is available under terms of Apache-2.0.