Skip to content

Repository files navigation

SKeen

SKeen

Lightweight transparent proxy for Keenetic/Netcraze routers, powered by sing-box.

Build SKeen License sing-box-latest Ask DeepWiki

🇺🇸 English | 🇷🇺 На русском

SKeen configures transparent proxying on Keenetic and Netcraze routers using sing-box. It manages firewall rules, service lifecycle and configuration synchronization.

Why sing-box?

sing-box is an open-source universal proxy engine written in Go. It is focused on maximum performance, low resource consumption, and support for the most modern protocols

Comparison: Proxy Engines for Routers & Embedded

Feature sing-box Xray mihomo
Resource Usage (RAM/CPU) ✅ Minimal ⚠️ Moderate ❌ High
Protocol Support ✅ Advanced ⚠️ Limited ✅ Extensive
Multiplexing ✅ Superior ⚠️ Legacy ✅ Good
DNS Logic 🥇 Native (+Fake-IP) 🥉 Sniffing (+FakeDNS) 🥈 Fake-IP (+Real)
TUN efficiency ✅ High ⚠️ Basic ⚠️ Basic
L7 Sniffing (Protocols) ✅ Leader ⚠️ Mid-tier ❌ Domain-only
Routing ✅ Flexible ⚠️ Basic ✅ (but heavier)
Rule Management ✅ Rule-sets (bin) ⚠️ Geo-files (dat) ✅ Rule-providers
Independent Project ✅ Yes ❌ (V2Ray fork) ❌ (Clash fork)
Learning Curve 🔴 High 🟡 Moderate 🟢 Low

Notes:

sing-box excels due to its modularity and clean-slate architecture: its DNS stack enables complex configurations with minimal RAM overhead. In contrast, mihomo (Clash) prioritizes automation at the cost of high resource usage, while Xray is hindered by legacy networking code and heavy .dat geo-files.

Sniffing Differences: sing-box and Xray utilize full DPI (Deep Packet Inspection), which allows them to identify the protocol type (e.g., BitTorrent) based on packet content. In contrast, mihomo is limited to metadata extraction (domains) from TLS/HTTP headers, making protocol-based routing impossible.

The high learning curve of sing-box stems from its strict JSON schema and lack of "magic" defaults. This is a trade-off for granular control and peak performance on low-end hardware.

Web UI?

💡 For easy setup, a sync plugin is available, allowing you to import profiles via GUI.for.SingBox. For more flexible manual configuration, automation, and synchronization, use Sub-Store-Docker on a VPS or Sub-Store-GUI on a PC.

The project intentionally does not include a dedicated management panel. This approach offers several advantages for your router:

  • Resource Efficiency: Not having a separate management panel saves RAM and reduces CPU overhead, leaving more resources for traffic routing.
  • Integration: Management and monitoring are available through the sing-box API and router tools, without duplicating their functions in a separate panel.
  • Security and Stability: Fewer continuously running services and components mean fewer potential points of failure and conflicts within the system.
  • Full Control: Directly editing the configuration provides access to sing-box features without the limitations of simplified graphical interfaces. Implementing all these features as buttons requires developers to continually update and promptly maintain the panel.
  • No Constant Need: In general, a separate management panel is not required: a correctly configured setup is created for specific tasks and usually does not need regular changes.
  • Focus on the Main Task: SKeen is designed for transparent traffic forwarding and routing. For a network tool of this kind, a separate heavy management panel would generally be excessive.
Architecture?

The description is provided in the Architecture document.

ADGuard Home & DNS?

The complete FAQ is available in docs/FAQ.md.

Features

  • TProxy, Redirect, Hybrid, Tun and DNS modes
  • IPv4 and IPv6 support
  • Working sing-box DNS module
  • Working sing-box FakeIP
  • FakeIP proxying at iptables level
  • Configured Web UI via built-in API
  • Network settings optimization
  • Commands working via router's Web CLI
  • Switch between official and third-party sing-box
  • Sing-box config sync via HTTP(S) link
  • Sub-Store usage examples for synchronization
  • Ready-to-use sing-box config templates
  • Optional proxying for the router itself
  • No access token required for RCI requests

Requirements

  • Entware installed and configured.
  • Netfilter Subsystem Kernel Module installed.
  • curl installed via opkg install curl.
  • Recommended: at least 256 MB of RAM and an ARM processor to unlock full potential.

Installation

Make sure that Entware is installed. Otherwise, find the instructions for your model in the Support Center → User Guide → Management → OPKG → Installing the Entware repository on a USB drive / Installing OPKG Entware on internal router memory.

Run from Entware via SSH:

curl -Ls https://github.com/jinndi/SKeen/releases/latest/download/skeen --resolve release-assets.githubusercontent.com:443:185.199.108.133 | sh

Russian-localized version: See README-RU.md

Installation failed? (click to expand)

See the troubleshooting guide.

Note

You will be prompted to install sing-box from the official repository (either the stable or beta version). You can also skip the installation to configure a custom binary file later in skeen.json.

Configure the following:

  1. SKeen in /opt/etc/skeen/skeen.json.
  2. sing-box in /opt/etc/skeen/config.json.
  3. The web dashboard at http://192.168.1.1:9999. By default, it is available at the router's IP address (typically 192.168.1.1).

Important:

The /opt/etc/skeen directory is preserved when the program is uninstalled and is not overwritten during reinstallation if it already exists. Delete it manually if necessary.

Manage SKeen using the skeen command.

File and directory structure after successful installation:

/opt/
├── bin/
│   ├── skeen                  # Main SKeen management script
│   └── skeen-box              # sing-box binary (if installation selected)
├── etc/
│   ├── init.d/
│   │   └── S99SKeen           # System startup / autostart script
│   ├── ndm/netfilter.d/
│   │   └── skeen_firewall.sh  # Firewall rules (generated on startup)
│   └── skeen/
│       ├── skeen.json         # SKeen configuration
│       └── config.json        # sing-box configuration
└── tmp/                       # Temporary download files

/tmp/ (RAM Disk) - synced into memory:
├── skeen.sh                   # Script copy - updated after start/reboot
├── skeen.json                 # Config cache - synced on source changes
├── skeen_singbox_version      # sing-box version cache - updated on binary change
└── run/
    └── skeen.pid              # PID file of the sing-box process

Web Panels for Local Network

The following domains are pre-configured in the base config.json template for accessing the panels from the router's local network:

Dashboard URL Used API Panel Connection Address Brief Description
sing-box-dashboard.sagernet.org (in Chrome)
HTTP version (others)
Native sing-box API (9999) http://192.168.1.1:9999 Built-in sing-box web dashboard (files are stored locally on the router).
sdash.u1.pw (in Chrome)
HTTP version (others)
Native sing-box API (9999) http://192.168.1.1:9999 Very lightweight web interface for sing-box management.
board.zash.run.place (in Chrome)
HTTP version (others)
Clash API (9090) http://192.168.1.1:9090 Remote Zashboard frontend for managing proxy connections.
d.metacubex.one / metacubexd.pages.dev (Chrome only) Clash API (9090) http://192.168.1.1:9090 Alternative MetacubexD (Yacd-meta) web interface for Clash API.

Commands

Example Usage from SSH: start the daemon skeen start

When using the router’s Web CLI, add exec before the command. For example: exec skeen reload

The output in the Web CLI is limited to 8 lines and a certain execution time, but this does not affect the correct execution of commands.

skeen without parameters launches the management menu from SSH, use skeen help for help

Command Description Web CLI
start Start service ✓
stop Stop service ✓
restart Full restart ✓
reload Reload sing-box only ✓
kill Force stop ✓
status Show status ✓
version Show version ✓
help Help about any command -
iface Show network interface table -
update Check and install updates -
test Test firewall rules ✓
deps Check dependencies ✓
check Check configuration ✓
format Format sing-box configuration ✓
api sing-box API management commands -
backup Create archive of /opt/etc/skeen ✓
backups List created archives in /opt ✓
restore¹ Restore /opt/etc/skeen from archive in /opt ✓
reset Reset /opt/etc/skeen to default -
clean² Clear sing-box cache file ✓
sync³ Synchronize sing-box configuration ✓
headers Generate fake client headers for subscriptions -

1 - archive name can be passed as the second parameter with a .tar extension to immediately start the backup restore process

2 - clears the cache file. This is required when using the experimental.cache_file feature in sing-box, for example, to reset the cache of loaded rule_set and DNS query history.

3 - accepts the sing-box JSON configuration URL as the second parameter (HTTP or HTTPS); optional if the address is set in singbox.config.url

OpkgTun manager (KeeneticOS v5+, only from SSH)

Command Description
skeen tun create <ipv4> <name> Create interface with IP address and name
skeen tun delete <name> Delete interface by name
skeen tun list List all OpkgTun interfaces

Settings

The full configuration reference is available in docs/CONFIGURATION.md.

Useful links

Sync and GUI

Rulesets

Documentation and references

About

Lightweight transparent proxy for Keenetic/Netcraze routers, powered by sing-box. Supports TProxy, Redirect, TUN, DNS and Fake IP.

Topics

Resources

Stars

59 stars

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages