sudo pacman -S ipset
sudo ipset create china hash:net
wget http://www.ipdeny.com/ipblocks/data/countries/cn.zone
for i in $(cat cn.zone); do sudo ipset add china $i; done
sudo ipset save | sudo tee /etc/ipset.conf
sudo systemctl enable ipset
sudo systemctl start ipset
sudo ipset test china 114.114.114.114
返回in
sudo ipset test china 8.8.8.8
返回not in
sudo vim /etc/iptables/redsocks.conf
添加一行
-A REDSOCKS -p tcp -m set --match-set china dst -j RETURN
sudo iptables-restore < /etc/iptables/redsocks.rules