Skip to content
Usage

Settings

Every option of the Settings page of the web UI on Keenetic and Asus.

The Settings page holds only what makes sense to change on the router. Everything else (DNS servers, hosts, sniffer, rule providers) goes to the profile or to the mixin file. On changes a bar appears at the bottom: Save only saves, Save & Apply also restarts the service. On OpenWrt the similar options are on the Advanced page of LuCI.

OptionDefaultWhat it does
Enableonintercept the traffic of the devices chosen on the Status page. When off, only the core runs: its proxy port and the dashboard
TCPRedirectRedirect works everywhere and is recommended. TPROXY for TCP needs port 443 of the router free on Keenetic, the TPROXY module of the firmware on Asus (without it TCP is redirected)
UDPTPROXYfor QUIC, games and calls. Needs the Kernel modules for Netfilter component on Keenetic or the TPROXY module on Asus, without it UDP goes directly. Empty — UDP is not proxied
DNS through the coreonDNS queries of the proxied devices go to the core, whatever DNS the router uses. Required for Fake-IP and domain rules
Traffic of the routeroffproxy the connections of the router itself, for example of Entware applications. DNS of the router is not intercepted
Respect parental controlondevices blocked in the router and schedules apply to the proxied traffic too, otherwise blocked devices would get internet through the core
OptionDefaultWhat it does
TCP ports to proxyall (0-65535)ports and ranges separated by spaces, the other ports go directly. Presets: Web only (80 443 8080 8443), Common ports
UDP ports to proxyall (0-65535)the same for UDP. Preset QUIC only (443 8443)
Direct IPv4 networkslocal and special networksdestinations that never go through the proxy
Direct IPv6 networkslocal and special networksthe same for IPv6, used when IPv6 is on in the profile and the router has an IPv6 address

A device can mark its traffic with DSCP to choose the route per application. The marks are the same as in XKeen.

OptionDefaultWhat it does
Direct62traffic with these marks goes directly
Proxy63traffic with these marks goes through the proxy even from excluded devices and on any port
Mark of the chosen proxy61traffic with this mark goes to one proxy, past the rules of the profile
Chosen proxy—a group or a proxy of the running profile for the mark above. Exodus adds a separate listener for it to the profile itself. The list fills after the first start

How to mark traffic on Windows: gpedit.msc → Computer Configuration → Windows Settings → Policy-based QoS → Create new policy: choose the DSCP value and the application. Outside of a domain set this in the registry first and reboot:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\QoS]
"Do not use NLA"="1"

Options merged over the profile. Mode, DNS mode and IPv6 always come from the profile.

OptionDefaultWhat it does
Log levelfrom profilesilent, error, warning, info, debug
Outbound interfaceautomaticLinux name of the interface for the connections of the core: ppp0, eth3, nwg0 and so on
Memory limithalf of RAMGOMEMLIMIT, e.g. 128MiB; off removes the limit. Without a limit the router may kill the core when memory runs out
Proxy portfrom profile, otherwise 7890HTTP and SOCKS5 on one port, for devices and applications set up by hand
Authenticationon, user exodususername and password on the proxy port
PanelZashboardZashboard, MetaCubeXD or YACD. Update downloads it again
API port9090port of the API of the core, the dashboard works through it
API secret—the dashboard and other applications connect to the core with it

The open files limit of the core is 40000 on arm64 and 10000 on other models.

Rules of Exodus are checked from top to bottom before the rules of the profile, the first matching rule wins. Put REJECT rules first, then DIRECT, then the proxy groups: a block or a direct exception is then not caught by a wider proxy rule.

Target: DIRECT goes directly, REJECT blocks (REJECT-DROP silently), or a group of the profile (hidden groups are not offered). A rule without a type, a target or a value is skipped.

TypeMatchesExample
DOMAINdomainexample.com
DOMAIN-SUFFIXdomain and subdomainsexample.com
DOMAIN-KEYWORDdomain keywordgoogle
DOMAIN-WILDCARDdomain by a pattern with * and ?*.example.com
DOMAIN-REGEXdomain by a regular expression^ads?\.
GEOSITEgeosite categoryyoutube
IP-CIDR, IP-CIDR6destination IPv4 / IPv6 network1.1.1.0/24
IP-ASNdestination autonomous system13335
GEOIPgeoip countryru
SRC-IP-CIDRsource network, a device of the local network192.168.1.10/32
DST-PORT, SRC-PORTdestination / source port443
NETWORKtcp or udpudp
RULE-SETrule provider of the profilemy-rules
MATCHeverything else—

No resolve is for rules by IP (IP-CIDR, IP-ASN, GEOIP): the domain is not resolved to check the rule, it matches only connections to an IP address. More — rules in the Mihomo documentation.

OptionDefaultWhat it does
Start delay, seconds0wait after the router boots, for example until the USB drive or the internet is ready
Scheduled restartoffrestart the service on a cron schedule: minute hour day month weekday. 0 3 * * * is every day at 3:00
Device ID (HWID)automaticmade from the hardware of the router, it stays the same after a reinstall. The x-device-os, x-ver-os, x-device-model headers are shown next to it, see HWID
Log size limit, MB1logs are kept in RAM, a log over the limit is cleared. Empty — no limit
Clear logs at stopon
Web UI: port9099the web UI moves to the new port after saving
Web UI: password—change the password, at least 4 characters. It can also be reset with exodus passwd over SSH