Skip to content
Installation

Keenetic / Netcraze

Preparing the router, Entware, installation and specifics of Keenetic.

  • KeeneticOS 4.x or newer.
  • Architectures: aarch64 (arm64), mipsel and mips (softfloat).
  • Entware on a USB drive or the internal storage and about 70 MB free on it: the Mihomo core is about 40 MB, yq about 15 MB.
  • XKeen stopped and removed from autostart: both intercept the same traffic, see migrating from XKeen.
  1. KeeneticOS components. General settings → Change component set, the router reboots.

    ComponentWhy
    Open Package support (OPKG)required, Entware runs on it
    Kernel modules for Netfilterrequired: TPROXY (UDP, and TCP in the TPROXY mode) and the DSCP marks
    IPv6 protocolfor IPv6 through the proxy, always on in KeeneticOS 5
    USB and the Ext file systemwhen Entware is on a USB drive
    DNS-over-TLSDoT
    DNS-over-HTTPSDoH
  2. Management → Users and access → Management services → set HTTPS management port to anything other than 443.

  3. Entware. Install it by the official Keenetic guide or by the guide from XKeen (in Russian, with partitioning of the drive and swap).

  4. SSH console of Entware. User root, password keenetic (change it with passwd). Port 222 when the SSH server component is installed on the router, 22 otherwise.

In the SSH console of Entware:

opkg update && opkg install curl
curl -fsSL https://raw.githubusercontent.com/prettyleaf/openwrt-exodus/keenetic/install.sh | sh

The installer installs Entware packages, checks access to GitHub, asks for the core and the password of the web UI, downloads Mihomo and yq into /opt/libexec/exodus. At the end it prints the address of the web UI, http://192.168.1.1:9099/ by default.

To update, run the same command or use the Updates page of the web UI. Installer options (core, password, gh-proxy) are on the Installer options page.

If opkg fails inside the installer, install the packages beforehand:

opkg update
opkg install curl ca-bundle jq ipset iptables ip-full lighttpd lighttpd-mod-cgi
PackageWhy
curl, ca-bundledownloads over HTTPS: the installer, subscriptions, updates
jqsettings and the API of the web UI
ipset, iptablesinterception rules and sets of devices, ip6tables is a part of iptables
ip-fullthe route and the rule of TPROXY
lighttpd, lighttpd-mod-cgithe web UI
  • TCP goes through Redirect and UDP through TPROXY by default. TPROXY for TCP needs port 443 of the router free: move the web interface of the router to another port on the Users and access page. TUN is not supported, TUN of the profile is turned off.
  • Traffic that bypasses the proxy (DSCP mark 62, excluded devices) keeps hardware acceleration and QoS of the router. Speed limits and priorities of IntelliQoS do not apply to proxied traffic: the router itself sends it out.
curl -fsSL https://raw.githubusercontent.com/prettyleaf/openwrt-exodus/keenetic/uninstall.sh | sh

With KEEP_CONFIG=1 before sh the settings, profiles and subscriptions in /opt/etc/exodus are kept. Entware packages are not removed: other applications may use them.