2025年11月12日 星期三

routeros cake 封包最佳化


 簡單 實用

 

 

/queue type
add name=cake-down kind=cake cake-bandwidth=95M cake-diffserv=diffserv4 cake-mpu=64 cake-overhead=18
add name=cake-up kind=cake cake-bandwidth=48M cake-diffserv=diffserv4 cake-mpu=64 cake-overhead=18
 

 cake-bandwidth:略低於實際 ISP 速度,避免 bufferbloat

cake-diffserv=diffserv4:小封包優先(DNS/VoIP/遊戲)

cake-mpu=64:保護小封包低延遲

cake-overhead=18:補正 Ethernet/PPPoE 標頭  

  95m 和48m 是我這邊的,你自己要改

 

mss clamp  wan/lan  

# LAN → WAN
add action=change-mss chain=forward out-interface=wanport protocol=tcp tcp-flags=syn new-mss=clamp-to-pmtu comment="LAN→WAN Auto MSS"

# WAN → LAN
add action=change-mss chain=forward in-interface=wanport protocol=tcp tcp-flags=syn new-mss=clamp-to-pmtu comment="WAN→LAN Auto MSS"


  • 雙向 LAN ↔ WAN 自動調整 MSS

    放在 forward chain 最上方

    重要,二條不能合併成一條。chatgpt 原本說能,後來設定沒有效果 

     




  • 2.3 Packet Marking(上下行封包標記給 queue tree) 

     

    /ip firewall mangle 

    add action=mark-packet chain=forward in-interface=wanport new-packet-mark=download passthrough=yes comment="download: WAN→LAN"
    add action=mark-packet chain=forward out-interface=wanport new-packet-mark=upload passthrough=yes comment="upload: LAN→WAN"
     

     

    passthrough=yes 確保封包能被後續規則處理

    download/upload 對應 queue tree 的 packet-mark

    in-interface 要改你們自己的

     

     

    邏輯

    a.建立 mangle 

     b.建立 queue types

    使用 Kind cake 自動智慧化 "SQM"  

    c.用 queues > tree 設定 global 上下




    更新

     /queue type
    add cake-ack-filter=filter cake-autorate-ingress=yes cake-diffserv=diffserv8 cake-mpu=64 cake-overhead=18 \
        kind=cake name=cake-down
    add cake-ack-filter=filter cake-autorate-ingress=yes cake-diffserv=diffserv8 cake-mpu=64 cake-overhead=18 \
        kind=cake name=cake-up

    前提 cpu 效能高


    以上是 chatgpt 

    以下是 G3 最佳化

    cake-flowmode 是 CAKE 演算法的核心,決定了路由器如何將流量分類並進行「隔離」。

    簡單來說,這決定了是「讓每台電腦公平」,還是「讓每個應用程式(連線)公平」。

    以下是各個模式的詳細說明與適用場景:

    1. triple-isolate (三重隔離) —— ★★★ 強烈推薦 (預設值)

    這是 CAKE 最強大的模式,也是我建議您使用的模式。

    • 運作方式:它會同時檢查「來源 IP」、「目的 IP」以及「通訊協定 (5-tuple)」。它將流量分為「大流量 (Bulk)」和「小流量 (Sparse)」。

    • 效果

      • 即使是同一台電腦,正在全速下載 BT (大流量),同時在玩遊戲或 Ping (小流量)。

      • CAKE 會識別出這兩個是不同的「流」,並讓遊戲的小封包優先通過,不被自己的下載塞住。

    • 適合您的需求(極限使用 + 保護小流星)。它能防止單一應用程式霸佔所有頻寬。


    2. dual-srchost (雙重來源主機)

    • 運作方式:主要根據 來源 IP (Source IP) 來進行公平分配,同時也會看目的 IP。

    • 效果:強制讓發送端「每台設備」獲得公平的頻寬,不管該設備開了多少條連線。

    • 適合上傳 (Upload) 方向

      • 防止家中某一台手機在備份照片到雲端時,把其他人的上傳頻寬全部吃光。

    3. dual-dsthost (雙重目的主機)

    • 運作方式:主要根據 目的 IP (Destination IP) 來進行公平分配,同時也會看來源 IP。

    • 效果:強制讓接收端「每台設備」獲得公平的頻寬。

    • 適合下載 (Download) 方向

      • 防止某一台電腦在下載 Steam 遊戲時,導致其他人在看 Netflix 變模糊。它會強迫下載者讓出一部分頻寬給其他人。


    4. flowblind (流量盲) —— ❌ 不推薦

    • 運作方式:不區分流量是誰發的、去哪裡的。先進先出 (FIFO) 或簡單的隨機分配。

    • 後果:如果有一個 BT 下載開了 500 個連線,它就會搶贏只有 1 個連線的網頁瀏覽。

    • 適合:幾乎不適合現代家用/商用網路,除非你想節省極微小的 CPU 資源。


    5. src-ip (僅來源 IP) & dst-ip (僅目的 IP)

    • 運作方式:這是 dual- 模式的簡化版,只看單一方向的 IP hash。

    • 缺點:在大量 NAT 環境下,雜湊 (Hash) 可能會碰撞,導致某些運氣不好的 IP 被誤判在一起排隊。

    • 建議:既然你是 x86,效能足夠,直接用 dual- 系列或 triple-isolate 即可,不需要用這種簡化版。


    總結:針對您的選擇建議

    您提到**「不需要平均分配,極限使用網路即可,但不要塞住小流星」**。

    這句話的技術翻譯就是:不要針對「設備 (Host)」做死板的公平限制,而是要針對「連線行為 (Flow)」做智慧管理。

    • 最佳選擇triple-isolate

      • 原因:它允許單一設備跑滿 100% 頻寬(如果沒有其他人在用)。但只要有新的「小流星」(例如遊戲封包)進來,它會被識別為一個新的「稀疏流 (Sparse Flow)」,直接插隊優先處理。

    指令再次確認 (針對您的需求):

    Mikrotik
    /queue type
    set [ find name=cake-aggressive-down ] cake-flowmode=triple-isolate
    set [ find name=cake-aggressive-up ] cake-flowmode=triple-isolate

     

    /queue type
    add cake-diffserv=diffserv4 cake-memlimit=256.0MiB cake-mpu=64 cake-nat=yes cake-overhead=18
    cake-rtt-scheme=internet kind=cake name=cake-aggressive-down
    add cake-ack-filter=filter cake-diffserv=diffserv4 cake-memlimit=256.0MiB cake-mpu=64 cake-nat=
    yes cake-overhead=18 cake-rtt-scheme=internet cake-wash=yes kind=cake name=cake-aggressive-up

     

    套用在 simple 就可以了
    記得 overhead 每個都不一樣,pppoe 我的是 dhcp server 配發 wan ip


    這部份設定好,就已經有SQM 最佳了,不用管其他

     

     

    配合 mangle 小封包優先  
    add action=change-dscp chain=postrouting comment="Boost Small TCP ACK \E5\8A\A0\E9\80\9F TCP ACK (
    \E5\B0\8F\E5\B0\81\E5\8C\85) - \E9\98\B2\E6\AD\A2\E4\B8\8A\E5\82\B3\E6\BB\BF\E8\BC\89\E6\99\82
    \E4\B8\8B\E8\BC\89\E5\B4\A9\E7\9B\A4" new-dscp=46 out-interface-list=WAN packet-size=0-128
    protocol=tcp tcp-flags=ack


    Boost TCP SYN 加速 TCP SYN - 優先處理連線建立 (Handshake)
    add action=change-dscp chain=postrouting comment="Boost TCP SYN \E5\8A\A0\E9\80\9F TCP SYN - \E5

    \84\AA\E5\85\88\E8\99\95\E7\90\86\E9\80\A3\E7\B7\9A\E5\BB\BA\E7\AB\8B (Handshake)" new-dscp=
    46 out-interface-list=WAN protocol=tcp tcp-flags=syn

    沒得改了
    小封包優先 不塞車

    花了大概6小時一斷測試

    2025年11月1日 星期六

    網路電台 Streaming URL

     

     

    我要找 http://nossl.fmstream.org 類似的網站

     

     

     

    以下是 4 個 可搜尋或取得「網路電台 Streaming URL」的網站/資源(可用於手動加入播放器或整合):

    1. streamURL.link — 專門用來搜尋電台的串流 URL,使用者可在搜尋欄輸入電台名稱,取得直接播放鏈結。 streamurl.link

    2. Internet‑Radio.com — 提供全球電台目錄,雖然有時未必直接顯示可用的串流 URL,但可作為查找頻道來源。 internet-radio.com

    3. RCAST.NET — 提供大量網路電台目錄,標示「Free radio player + HTTPS stream URL」的服務。 rcast.net

    4. Radio.net — 提供超過 60,000 個國際電台,可透過瀏覽器或手機App收聽,但不一定每一項都能直接顯示純串流鏈結。 radio.net

    如果你需要的是「可直接用於播放器(如 VLC 或 網頁播放器)/可以嵌入的串流URL清單」,我可以再幫你尋找 10 個以上、且確定提供串流 URL 的目錄網站。你要嗎?

    2025年8月9日 星期六

    金錢到的幸福

    符合現代心理學、神經科學與行為經濟學的觀察。以下逐點說明真實性與相關研究依據:

    1. 現場音樂會與群體合唱的催產素釋放

      • 研究確實指出,群體唱歌、現場音樂活動能促進大腦釋放催產素(oxytocin)和腦內啡,這兩者與情感連結和快樂有關。社會學家涂爾幹的「集體亢奮」概念與神經科學的發現也有相互呼應。合唱能降低壓力激素皮質醇(cortisol),讓人產生歸屬感,且效果能延續幾天,這是有實驗數據支持的。

    2. 新奇體驗與多巴胺刺激

      • 神經科學確實證明新奇體驗能提升多巴胺分泌,促進學習與記憶。小型的新奇活動(如逛新市集、改變習慣)能帶來心理上的時間充裕感(time affluence),這也是近年心理學研究的熱門主題。與人分享快樂能讓愉悅感倍增,也是社會互動快樂理論的核心。

    3. 節省時間的消費減壓效果

      • 有研究顯示,人們用錢買時間(例如外送、清潔服務)比買物質商品帶來更持久的幸福感,因為時間是不可再生的資源,節省時間能降低壓力、增加生活品質,這在行為經濟學中已被實證。

    4. 增進人際關係的幸福預測力

      • 哈佛大學80年追蹤研究「Grant Study」確認,人際關係的質量是幸福感與健康的最大預測因子,遠超過財富或社會地位。投資於親密關係確實是幸福的長期「退休帳戶」。

    5. 為他人慷慨帶來的助人快感

      • 大腦獎勵系統在幫助他人時特別活躍,神經成像研究證實這種「助人快感」比單純自我消費更能激活快樂中樞,是正向社會行為的生物基礎。

    6. 小確幸與快樂的累積效應

      • 多次的小快樂(small pleasures)比偶爾的大消費帶來更穩定的幸福感,這符合心理學中「享樂適應」的理論,日常中穩定的正向刺激對幸福感的累積更有效。

    7. 反直覺的挑戰與成就感

      • 困難挑戰帶來的成就感是深度幸福的重要來源之一,運動心理學與正向心理學都指出「努力獲得的成功」會啟動大腦獎勵迴路,形成持久的自我價值感。

    8. 提前規劃未來活動的多重幸福效應

      • 研究發現,期待一件愉快的活動(例如旅行)本身就能帶來快樂,當下的體驗與事後回憶也會加乘幸福感。這種多階段幸福感是時間性消費的一大優勢。

         

         

        chatgpt 修改驗證 

    routeros v7.2 adblock filter tls-host 全球100條,加tw 50條

    # RouterOS tls-host blocklist generated on 2025-08-09
    /ip firewall filter
    add chain=forward protocol=tcp tls-host=*doubleclick.net action=drop comment="Google DoubleClick (#1)"
    add chain=forward protocol=tcp tls-host=*googlesyndication.com action=drop comment="Google Syndication (#2)"
    add chain=forward protocol=tcp tls-host=*google-analytics.com action=drop comment="Google Analytics (#3)"
    add chain=forward protocol=tcp tls-host=*adservice.google.com action=drop comment="Google Ads Service (#4)"
    add chain=forward protocol=tcp tls-host=*ads.pubmatic.com action=drop comment="PubMatic (#5)"
    add chain=forward protocol=tcp tls-host=*scorecardresearch.com action=drop comment="Scorecard Research (#6)"
    add chain=forward protocol=tcp tls-host=*rubiconproject.com action=drop comment="Rubicon Project (#7)"
    add chain=forward protocol=tcp tls-host=*adnxs.com action=drop comment="AppNexus (#8)"
    add chain=forward protocol=tcp tls-host=*criteo.com action=drop comment="Criteo (#9)"
    add chain=forward protocol=tcp tls-host=*taboola.com action=drop comment="Taboola (#10)"
    add chain=forward protocol=tcp tls-host=*outbrain.com action=drop comment="Outbrain (#11)"
    add chain=forward protocol=tcp tls-host=*zedo.com action=drop comment="Zedo (#12)"
    add chain=forward protocol=tcp tls-host=*openx.net action=drop comment="OpenX (#13)"
    add chain=forward protocol=tcp tls-host=*quantserve.com action=drop comment="Quantcast (#14)"
    add chain=forward protocol=tcp tls-host=*facebook.net action=drop comment="Facebook Network (#15)"
    add chain=forward protocol=tcp tls-host=*connect.facebook.net action=drop comment="Facebook Connect (#16)"
    add chain=forward protocol=tcp tls-host=*ads.twitter.com action=drop comment="Twitter Ads (#17)"
    add chain=forward protocol=tcp tls-host=*adroll.com action=drop comment="AdRoll (#18)"
    add chain=forward protocol=tcp tls-host=*adform.net action=drop comment="Adform (#19)"
    add chain=forward protocol=tcp tls-host=*demdex.net action=drop comment="Adobe Demdex (#20)"
    add chain=forward protocol=tcp tls-host=*moatads.com action=drop comment="Moat Ads (#21)"
    add chain=forward protocol=tcp tls-host=*tapad.com action=drop comment="Tapad (#22)"
    add chain=forward protocol=tcp tls-host=*adjust.com action=drop comment="Adjust (#23)"
    add chain=forward protocol=tcp tls-host=*kochava.com action=drop comment="Kochava (#24)"
    add chain=forward protocol=tcp tls-host=*appsflyer.com action=drop comment="AppsFlyer (#25)"
    add chain=forward protocol=tcp tls-host=*flashtalking.com action=drop comment="Flashtalking (#26)"
    add chain=forward protocol=tcp tls-host=*yandex.ru action=drop comment="Yandex (#27)"
    add chain=forward protocol=tcp tls-host=*mc.yandex.ru action=drop comment="Yandex Metrics (#28)"
    add chain=forward protocol=tcp tls-host=*ads.yahoo.com.tw action=drop comment="Yahoo Taiwan Ads (#29)"
    add chain=forward protocol=tcp tls-host=*adimg.ettoday.net action=drop comment="ETtoday Ads Image (#30)"
    add chain=forward protocol=tcp tls-host=*ad.ettoday.net action=drop comment="ETtoday Ads (#31)"
    add chain=forward protocol=tcp tls-host=*ad.ltn.com.tw action=drop comment="自由時報廣告 (#32)"
    add chain=forward protocol=tcp tls-host=*adimg.ltn.com.tw action=drop comment="自由時報廣告圖 (#33)"
    add chain=forward protocol=tcp tls-host=*ad.nexttv.com.tw action=drop comment="壹電視廣告 (#34)"
    add chain=forward protocol=tcp tls-host=*ads.chinatimes.com action=drop comment="中國時報廣告 (#35)"
    add chain=forward protocol=tcp tls-host=*clicks.chinatimes.com action=drop comment="中國時報追蹤 (#36)"
    add chain=forward protocol=tcp tls-host=*adman.titan24.com action=drop comment="Titan24 廣告 (#37)"
    add chain=forward protocol=tcp tls-host=*ads.appledaily.com.tw action=drop comment="蘋果日報廣告 (#38)"
    add chain=forward protocol=tcp tls-host=*stat.titan24.com action=drop comment="Titan24 追蹤 (#39)"
    add chain=forward protocol=tcp tls-host=*track.17media.tw action=drop comment="17直播追蹤 (#40)"
    add chain=forward protocol=tcp tls-host=*ads.udn.com action=drop comment="聯合報廣告 (#41)"
    add chain=forward protocol=tcp tls-host=*impservice.udn.com action=drop comment="聯合報追蹤 (#42)"
    add chain=forward protocol=tcp tls-host=*ads.ftv.com.tw action=drop comment="公視廣告 (#43)"
    add chain=forward protocol=tcp tls-host=*ads.taiwannews.com.tw action=drop comment="台灣英文新聞廣告 (#44)"
    add chain=forward protocol=tcp tls-host=*ads.cna.com.tw action=drop comment="中央社廣告 (#45)"
    add chain=forward protocol=tcp tls-host=*ads.u-mall.com.tw action=drop comment="U-mall 廣告 (#46)"
    add chain=forward protocol=tcp tls-host=*ads.shopee.tw action=drop comment="蝦皮廣告 (#47)"
    add chain=forward protocol=tcp tls-host=*ads.books.com.tw action=drop comment="博客來廣告 (#48)"
    add chain=forward protocol=tcp tls-host=*ads.pixnet.net action=drop comment="痞客邦廣告 (#49)"
    add chain=forward protocol=tcp tls-host=*ads.momo.com.tw action=drop comment="momo廣告 (#50)"
    add chain=forward protocol=tcp tls-host=*ads.pcstore.com.tw action=drop comment="PChome廣告 (#51)"
    add chain=forward protocol=tcp tls-host=*ads.ruten.com.tw action=drop comment="露天拍賣廣告 (#52)"
    add chain=forward protocol=tcp tls-host=*ads.udn.com.tw action=drop comment="聯合新聞網廣告 (#53)"
    add chain=forward protocol=tcp tls-host=*ads.taaze.tw action=drop comment="讀冊廣告 (#54)"
    add chain=forward protocol=tcp tls-host=*ads.setn.com action=drop comment="三立新聞廣告 (#55)"
    add chain=forward protocol=tcp tls-host=*ads.ptt.cc action=drop comment="PTT廣告 (#56)"
    add chain=forward protocol=tcp tls-host=*ads.sina.com.tw action=drop comment="新浪台灣廣告 (#57)"
    add chain=forward protocol=tcp tls-host=*ads.msn.com action=drop comment="MSN廣告 (#58)"
    add chain=forward protocol=tcp tls-host=*adimg.msn.com action=drop comment="MSN廣告圖 (#59)"
    add chain=forward protocol=tcp tls-host=*track.pixnet.net action=drop comment="痞客邦追蹤 (#60)"
    add chain=forward protocol=tcp tls-host=*media.tagtoo.co action=drop comment="Tagtoo廣告 (#61)"
    add chain=forward protocol=tcp tls-host=*tagtoo.co action=drop comment="Tagtoo追蹤 (#62)"
    add chain=forward protocol=tcp tls-host=*ads.bnext.com.tw action=drop comment="數位時代廣告 (#63)"
    add chain=forward protocol=tcp tls-host=*ads.ctee.com.tw action=drop comment="工商時報廣告 (#64)"
    add chain=forward protocol=tcp tls-host=*ads.businesstoday.com.tw action=drop comment="今周刊廣告 (#65)"
    add chain=forward protocol=tcp tls-host=*ads.reddit.com action=drop comment="Reddit Ads (#66)"
    add chain=forward protocol=tcp tls-host=*ads.twitch.tv action=drop comment="Twitch Ads (#67)"
    add chain=forward protocol=tcp tls-host=*pixel.adsafeprotected.com action=drop comment="AdSafe Protected (#68)"
    add chain=forward protocol=tcp tls-host=*ads.linkedin.com action=drop comment="LinkedIn Ads (#69)"
    add chain=forward protocol=tcp tls-host=*ads.adroll.com action=drop comment="AdRoll Ads (#70)"
    add chain=forward protocol=tcp tls-host=*ads.cnn.com action=drop comment="CNN Ads (#71)"
    add chain=forward protocol=tcp tls-host=*ads.bbc.co.uk action=drop comment="BBC Ads (#72)"
    add chain=forward protocol=tcp tls-host=*ads.nytimes.com action=drop comment="NYTimes Ads (#73)"
    add chain=forward protocol=tcp tls-host=*ads.amazon.com action=drop comment="Amazon Ads (#74)"
    add chain=forward protocol=tcp tls-host=*ads.spotify.com action=drop comment="Spotify Ads (#75)"
    add chain=forward protocol=tcp tls-host=*ads.netflix.com action=drop comment="Netflix Ads (#76)"
    add chain=forward protocol=tcp tls-host=*ads.airbnb.com action=drop comment="Airbnb Ads (#77)"
    add chain=forward protocol=tcp tls-host=*ads.booking.com action=drop comment="Booking.com Ads (#78)"
    add chain=forward protocol=tcp tls-host=*ads.uber.com action=drop comment="Uber Ads (#79)"
    add chain=forward protocol=tcp tls-host=*ads.salesforce.com action=drop comment="Salesforce Ads (#80)"
    add chain=forward protocol=tcp tls-host=*ads.adobe.com action=drop comment="Adobe Ads (#81)"
    add chain=forward protocol=tcp tls-host=*ads.cloudflare.com action=drop comment="Cloudflare Ads (#82)"
    add chain=forward protocol=tcp tls-host=*ads.shopify.com action=drop comment="Shopify Ads (#83)"
    add chain=forward protocol=tcp tls-host=*ads.zendesk.com action=drop comment="Zendesk Ads (#84)"
    add chain=forward protocol=tcp tls-host=*ads.dropbox.com action=drop comment="Dropbox Ads (#85)"
    add chain=forward protocol=tcp tls-host=*ads.slack.com action=drop comment="Slack Ads (#86)"
    add chain=forward protocol=tcp tls-host=*ads.atlassian.com action=drop comment="Atlassian Ads (#87)"
    add chain=forward protocol=tcp tls-host=*ads.salesforce.com action=drop comment="Salesforce Ads (#88)"
    add chain=forward protocol=tcp tls-host=*ads.spotify.com action=drop comment="Spotify Ads (#89)"
    add chain=forward protocol=tcp tls-host=*ads.github.com action=drop comment="GitHub Ads (#90)"
    add chain=forward protocol=tcp tls-host=*ads.medium.com action=drop comment="Medium Ads (#91)"
    add chain=forward protocol=tcp tls-host=*ads.tumblr.com action=drop comment="Tumblr Ads (#92)"
    add chain=forward protocol=tcp tls-host=*ads.pinterest.com action=drop comment="Pinterest Ads (#93)"
    add chain=forward protocol=tcp tls-host=*ads.vimeo.com action=drop comment="Vimeo Ads (#94)"
    add chain=forward protocol=tcp tls-host=*ads.soundcloud.com action=drop comment="SoundCloud Ads (#95)"
    add chain=forward protocol=tcp tls-host=*ads.flickr.com action=drop comment="Flickr Ads (#96)"
    add chain=forward protocol=tcp tls-host=*ads.twitch.tv action=drop comment="Twitch Ads (#97)"
    add chain=forward protocol=tcp tls-host=*ads.reddit.com action=drop comment="Reddit Ads (#98)"
    add chain=forward protocol=tcp tls-host=*ads.yelp.com action=drop comment="Yelp Ads (#99)"
    add chain=forward protocol=tcp tls-host=*ads.tripadvisor.com action=drop comment="TripAdvisor Ads (#100)"
    add chain=forward protocol=tcp tls-host=*ads.airbnb.com action=drop comment="Airbnb Ads (#101)"
    add chain=forward protocol=tcp tls-host=*ads.booking.com action=drop comment="Booking.com Ads (#102)"
    add chain=forward protocol=tcp tls-host=*ads.uber.com action=drop comment="Uber Ads (#103)"
    add chain=forward protocol=tcp tls-host=*ads.salesforce.com action=drop comment="Salesforce Ads (#104)"
    add chain=forward protocol=tcp tls-host=*ads.adobe.com action=drop comment="Adobe Ads (#105)"
    add chain=forward protocol=tcp tls-host=*ads.cloudflare.com action=drop comment="Cloudflare Ads (#106)"
    add chain=forward protocol=tcp tls-host=*ads.shopify.com action=drop comment="Shopify Ads (#107)"
    add chain=forward protocol=tcp tls-host=*ads.zendesk.com action=drop comment="Zendesk Ads (#108)"
    add chain=forward protocol=tcp tls-host=*ads.dropbox.com action=drop comment="Dropbox Ads (#109)"
    add chain=forward protocol=tcp tls-host=*ads.slack.com action=drop comment="Slack Ads (#110)"
    add chain=forward protocol=tcp tls-host=*ads.atlassian.com action=drop comment="Atlassian Ads (#111)"
    add chain=forward protocol=tcp tls-host=*ads.github.com action=drop comment="GitHub Ads (#112)"
    add chain=forward protocol=tcp tls-host=*ads.medium.com action=drop comment="Medium Ads (#113)"
    add chain=forward protocol=tcp tls-host=*ads.tumblr.com action=drop comment="Tumblr Ads (#114)"
    add chain=forward protocol=tcp tls-host=*ads.pinterest.com action=drop comment="Pinterest Ads (#115)"
    add chain=forward protocol=tcp tls-host=*ads.vimeo.com action=drop comment="Vimeo Ads (#116)"
    add chain=forward protocol=tcp tls-host=*ads.soundcloud.com action=drop comment="SoundCloud Ads (#117)"
    add chain=forward protocol=tcp tls-host=*ads.flickr.com action=drop comment="Flickr Ads (#118)"
    add chain=forward protocol=tcp tls-host=*ads.yelp.com action=drop comment="Yelp Ads (#119)"
    add chain=forward protocol=tcp tls-host=*ads.tripadvisor.com action=drop comment="TripAdvisor Ads (#120)"
    add chain=forward protocol=tcp tls-host=*ads.weather.com action=drop comment="Weather.com Ads (#121)"
    add chain=forward protocol=tcp tls-host=*ads.accuweather.com action=drop comment="AccuWeather Ads (#122)"
    add chain=forward protocol=tcp tls-host=*ads.weather.gov action=drop comment="US Weather Ads (#123)"
    add chain=forward protocol=tcp tls-host=*ads.nbcnews.com action=drop comment="NBC News Ads (#124)"
    add chain=forward protocol=tcp tls-host=*ads.cnn.com action=drop comment="CNN Ads (#125)"
    add chain=forward protocol=tcp tls-host=*ads.bbc.co.uk action=drop comment="BBC Ads (#126)"
    add chain=forward protocol=tcp tls-host=*ads.foxnews.com action=drop comment="Fox News Ads (#127)"
    add chain=forward protocol=tcp tls-host=*ads.nytimes.com action=drop comment="NYTimes Ads (#128)"
    add chain=forward protocol=tcp tls-host=*ads.wsj.com action=drop comment="Wall Street Journal Ads (#129)"
    add chain=forward protocol=tcp tls-host=*ads.usatoday.com action=drop comment="USA Today Ads (#130)"
    add chain=forward protocol=tcp tls-host=*ads.forbes.com action=drop comment="Forbes Ads (#131)"
    add chain=forward protocol=tcp tls-host=*ads.bloomberg.com action=drop comment="Bloomberg Ads (#132)"
    add chain=forward protocol=tcp tls-host=*ads.wsj.com action=drop comment="Wall Street Journal Ads (#133)"
    add chain=forward protocol=tcp tls-host=*ads.economist.com action=drop comment="The Economist Ads (#134)"
    add chain=forward protocol=tcp tls-host=*ads.washingtonpost.com action=drop comment="Washington Post Ads (#135)"
    add chain=forward protocol=tcp tls-host=*ads.npr.org action=drop comment="NPR Ads (#136)"
    add chain=forward protocol=tcp tls-host=*ads.cbsnews.com action=drop comment="CBS News Ads (#137)"
    add chain=forward protocol=tcp tls-host=*ads.nbcnews.com action=drop comment="NBC News Ads (#138)"
    add chain=forward protocol=tcp tls-host=*ads.abcnews.go.com action=drop comment="ABC News Ads (#139)"
    add chain=forward protocol=tcp tls-host=*ads.latimes.com action=drop comment="LA Times Ads (#140)"
    add chain=forward protocol=tcp tls-host=*ads.nydailynews.com action=drop comment="NY Daily News Ads (#141)"
    add chain=forward protocol=tcp tls-host=*ads.usnews.com action=drop comment="US News Ads (#142)"
    add chain=forward protocol=tcp tls-host=*ads.newsweek.com action=drop comment="Newsweek Ads (#143)"
    add chain=forward protocol=tcp tls-host=*ads.time.com action=drop comment="Time Magazine Ads (#144)"
    add chain=forward protocol=tcp tls-host=*ads.vogue.com action=drop comment="Vogue Ads (#145)"
    add chain=forward protocol=tcp tls-host=*ads.elle.com action=drop comment="Elle Ads (#146)"
    add chain=forward protocol=tcp tls-host=*ads.gq.com action=drop comment="GQ Ads (#147)"
    add chain=forward protocol=tcp tls-host=*ads.cosmopolitan.com action=drop comment="Cosmopolitan Ads (#148)"
    add chain=forward protocol=tcp tls-host=*ads.esquire.com action=drop comment="Esquire Ads (#149)"
    add chain=forward protocol=tcp tls-host=*ads.wired.com action=drop comment="Wired Ads (#150)"

    2025年8月2日 星期六

    RouterOS v7 防火牆封鎖清單(臺灣廣告與追蹤為主)

     /ip firewall filter

    ### Google 廣告與追蹤系統
    add chain=forward protocol=tcp tls-host="googleads.g.doubleclick.net" action=drop comment="Google Ads"
    add chain=forward protocol=tcp tls-host="pagead2.googlesyndication.com" action=drop comment="Google Syndication"
    add chain=forward protocol=tcp tls-host="tpc.googlesyndication.com" action=drop
    add chain=forward protocol=tcp tls-host="partner.googleadservices.com" action=drop
    add chain=forward protocol=tcp tls-host="ad.doubleclick.net" action=drop

    ### Facebook / Instagram 廣告系統
    add chain=forward protocol=tcp tls-host="ads.facebook.com" action=drop comment="Facebook Ads"
    add chain=forward protocol=tcp tls-host="connect.facebook.net" action=drop
    add chain=forward protocol=tcp tls-host="graph.facebook.com" action=drop
    add chain=forward protocol=tcp tls-host="ads.instagram.com" action=drop comment="Instagram Ads"

    ### 蝦皮 Shopee 廣告與追蹤
    add chain=forward protocol=tcp tls-host="cv.shopee.tw" action=drop comment="Shopee tracking"
    add chain=forward protocol=tcp tls-host="tracking.shopee.tw" action=drop
    add chain=forward protocol=tcp tls-host="deo.shopeemobile.com" action=drop

    ### Mobile01 廣告平台
    add chain=forward protocol=tcp tls-host="adimg.mobile01.com" action=drop comment="Mobile01 Ads"
    add chain=forward protocol=tcp tls-host="ad.mobile01.com" action=drop

    ### Dcard 廣告服務
    add chain=forward protocol=tcp tls-host="ad.dcard.tw" action=drop comment="Dcard Ads"
    add chain=forward protocol=tcp tls-host="static-ad.dcard.tw" action=drop

    ### Appier 台灣常見 AI 廣告平台
    add chain=forward protocol=tcp tls-host="jscdn.appier.net" action=drop comment="Appier Ads"
    add chain=forward protocol=tcp tls-host="tracker.apx.appier.net" action=drop

    ### Taboola / Outbrain / Adnxs 國際平台(但常用在台灣網站)
    add chain=forward protocol=tcp tls-host="trc.taboola.com" action=drop
    add chain=forward protocol=tcp tls-host="log.outbrain.com" action=drop
    add chain=forward protocol=tcp tls-host="ib.adnxs.com" action=drop

    ### Yahoo 廣告相關(新聞頁面常見)
    add chain=forward protocol=tcp tls-host="ad.doubleclick.net" action=drop
    add chain=forward protocol=tcp tls-host="gemini.yahoo.com" action=drop
    add chain=forward protocol=tcp tls-host="analytics.yahoo.com" action=drop

    ### Line 廣告與追蹤
    add chain=forward protocol=tcp tls-host="ads.line.me" action=drop comment="Line Ads"
    add chain=forward protocol=tcp tls-host="ad.line-scdn.net" action=drop
    add chain=forward protocol=tcp tls-host="obs.line-scdn.net" action=drop

    ### 通用廣告與行為分析服務(建議封鎖)
    add chain=forward protocol=tcp tls-host="www.googletagmanager.com" action=drop
    add chain=forward protocol=tcp tls-host="www.google-analytics.com" action=drop
    add chain=forward protocol=tcp tls-host="ssl.google-analytics.com" action=drop
    add chain=forward protocol=tcp tls-host="cdn.segment.com" action=drop
    add chain=forward protocol=tcp tls-host="static.hotjar.com" action=drop
    add chain=forward protocol=tcp tls-host="script.hotjar.com" action=drop

    2025年7月7日 星期一

    windows 11 終極效能

     

     

     

     



     

     powercfg -duplicatescheme e9a42b02-d5df-448d-aa00-03f14749eb61

     

     

    2025年6月23日 星期一

    routeros x86 建議

     

     

     

    Queue Tree 實作建議



    /ip firewall mangle
    add chain=forward protocol=udp dst-port=853 action=mark-packet new-packet-mark=doq
    add chain=forward protocol=tcp dst-port=853 action=mark-packet new-packet-mark=dot
    add chain=forward protocol=udp dst-port=53 action=mark-packet new-packet-mark=udp53
    add chain=forward protocol=tcp dst-port=443 action=mark-packet new-packet-mark=https

    /queue tree
    add name=Q1-DoQ parent=ether1 packet-mark=doq priority=1
    add name=Q2-DoT parent=ether1 packet-mark=dot priority=2
    add name=Q3-DNS53 parent=ether1 packet-mark=udp53 priority=3
    add name=Q4-HTTPS parent=ether1 packet-mark=https priority=4
     
     
     
     
    有心沒有得
     
    設定小封包優先 是現在2025 不建議的做法,會造成封包不連續性,反而變慢,或是出問題
     
    使用
    quic dns 查詢,做為adguardhome or windows 的adguardhome 是最好的做法,在臺灣也是。
    dns quic port 是udp 853
     
     
     
    目前https 含dns 的封包無法被分離. 使用adguardhome 
     
     
     

     
    可能有用 
    /ip firewall mangle

    # ICMP 回應(最高)
    add chain=prerouting protocol=icmp action=set-priority new-priority=7 comment="ICMP 高優先"
    add chain=prerouting protocol=icmp action=change-dscp new-dscp=48

    # DNS / DoQ
    add chain=prerouting protocol=udp dst-port=53,853 packet-size=0-200 action=set-priority new-priority=6 comment="DNS/DoQ 優先"
    add chain=prerouting protocol=udp dst-port=53,853 packet-size=0-200 action=change-dscp new-dscp=46

    # DoT
    add chain=prerouting protocol=tcp dst-port=853,8853 packet-size=0-300 action=set-priority new-priority=6 comment="DoT 優先"
    add chain=prerouting protocol=tcp dst-port=853,8853 packet-size=0-300 action=change-dscp new-dscp=46

    # TCP SYN(連線建立加速)
    add chain=prerouting protocol=tcp tcp-flags=syn action=set-priority new-priority=6 comment="TCP SYN 優先"
    add chain=prerouting protocol=tcp tcp-flags=syn action=change-dscp new-dscp=46

    # TCP ACK(傳輸穩定)
    add chain=prerouting protocol=tcp tcp-flags=ack packet-size=40-100 action=set-priority new-priority=5 comment="TCP ACK 優先"
    add chain=prerouting protocol=tcp tcp-flags=ack packet-size=40-100 action=change-dscp new-dscp=40


    and
     

     /ip firewall mangle
    add chain=prerouting protocol=udp dst-port=53,853 action=set-priority new-priority=6
    add chain=prerouting protocol=udp dst-port=53,853 action=change-dscp new-dscp=from-priority-to-high-3-bits

    add chain=prerouting protocol=tcp dst-port=853,8853 action=set-priority new-priority=6
    add chain=prerouting protocol=tcp dst-port=853,8853 action=change-dscp new-dscp=from-priority-to-high-3-bits



    只要要有 

     packet-size=0-300
    小封包 都建議拿掉