Keenetic / Netcraze
Preparing the router, Entware, installation and specifics of Keenetic.
Requirements
Section titled “Requirements”- KeeneticOS 4.x or newer.
- Architectures:
aarch64(arm64),mipselandmips(softfloat). - Entware on a USB drive or the internal storage and about 70 MB free on it: the Mihomo core is about 40 MB, yq about 15 MB.
- XKeen stopped and removed from autostart: both intercept the same traffic, see migrating from XKeen.
Preparation
Section titled “Preparation”-
KeeneticOS components. General settings → Change component set, the router reboots.
Component Why Open Package support (OPKG) required, Entware runs on it Kernel modules for Netfilter required: TPROXY (UDP, and TCP in the TPROXY mode) and the DSCP marks IPv6 protocol for IPv6 through the proxy, always on in KeeneticOS 5 USB and the Ext file system when Entware is on a USB drive DNS-over-TLS DoT DNS-over-HTTPS DoH -
Management → Users and access → Management services → set HTTPS management port to anything other than 443.
-
Entware. Install it by the official Keenetic guide or by the guide from XKeen (in Russian, with partitioning of the drive and swap).
-
SSH console of Entware. User
root, passwordkeenetic(change it withpasswd). Port 222 when the SSH server component is installed on the router, 22 otherwise.
Install & update
Section titled “Install & update”In the SSH console of Entware:
opkg update && opkg install curlcurl -fsSL https://raw.githubusercontent.com/prettyleaf/openwrt-exodus/keenetic/install.sh | shThe installer installs Entware packages, checks access to GitHub, asks for the core and the password of the web UI, downloads Mihomo and yq into /opt/libexec/exodus. At the end it prints the address of the web UI, http://192.168.1.1:9099/ by default.
To update, run the same command or use the Updates page of the web UI. Installer options (core, password, gh-proxy) are on the Installer options page.
If opkg fails inside the installer, install the packages beforehand:
opkg updateopkg install curl ca-bundle jq ipset iptables ip-full lighttpd lighttpd-mod-cgi| Package | Why |
|---|---|
curl, ca-bundle | downloads over HTTPS: the installer, subscriptions, updates |
jq | settings and the API of the web UI |
ipset, iptables | interception rules and sets of devices, ip6tables is a part of iptables |
ip-full | the route and the rule of TPROXY |
lighttpd, lighttpd-mod-cgi | the web UI |
Specifics
Section titled “Specifics”- TCP goes through Redirect and UDP through TPROXY by default. TPROXY for TCP needs port 443 of the router free: move the web interface of the router to another port on the Users and access page. TUN is not supported, TUN of the profile is turned off.
- Traffic that bypasses the proxy (DSCP mark 62, excluded devices) keeps hardware acceleration and QoS of the router. Speed limits and priorities of IntelliQoS do not apply to proxied traffic: the router itself sends it out.
Uninstall
Section titled “Uninstall”curl -fsSL https://raw.githubusercontent.com/prettyleaf/openwrt-exodus/keenetic/uninstall.sh | shWith KEEP_CONFIG=1 before sh the settings, profiles and subscriptions in /opt/etc/exodus are kept. Entware packages are not removed: other applications may use them.