fix(xray): allow private-IP destinations via freedom finalRules

Xray-core v26.4.17 added a default policy that blocks private IPs in the
freedom outbound for vless/vmess/trojan/hysteria/wireguard inbounds,
even when the panel's routing rules send traffic to direct (#4420). The
legacy ipsBlocked override was deprecated in the same release.

Default template now seeds the direct outbound with a finalRules entry
that explicitly allows geoip:private, so users who intentionally remove
the geoip:private->blocked routing rule actually regain LAN access.
Defense in depth is preserved: the routing rule still blocks private
IPs by default, so unmodified configs keep the same behavior.

OutboundFormModal exposes a Final Rules editor under the Freedom
section: per-rule action (allow/block), network, port, IP/CIDR/geoip
tags, and an optional blockDelay for block actions.
This commit is contained in:
MHSanaei
2026-05-19 15:42:16 +02:00
parent fd3770c8c9
commit d7f47d8b6a
2 changed files with 45 additions and 1 deletions
+4 -1
View File
@@ -30,7 +30,10 @@
"outbounds": [{
"protocol": "freedom",
"settings": {
"domainStrategy": "AsIs"
"domainStrategy": "AsIs",
"finalRules": [
{ "action": "allow", "ip": ["geoip:private"] }
]
},
"tag": "direct"
},