Bypassing Russian GFW #4035
Replies: 4 comments
|
What we saw: a working VLESS+REALITY node suddenly died on several LTE carriers,
So on those LTE segments a ClientHello with a Two related things that held up well on RU mobile:
YMMV by region/carrier, but the fingerprint swap is the cheapest first thing to test. |
|
A data point from running production REALITY nodes for RU mobile (LTE) users over the past months, in case it helps others chasing the same symptom. TSPU on mobile appears to filter REALITY by the TLS fingerprint, not just by SNI/IP. What we saw: a working VLESS+REALITY node suddenly died on several LTE carriers, while the exact same node kept working fine on home broadband. First guess was an IP block or the SNI getting flagged — both turned out wrong:
So on those LTE segments a ClientHello with a Two related things that held up well on RU mobile:
YMMV by region/carrier, but the fingerprint swap is the cheapest first thing to test. |
|
I ran into the same problem while operating a small Xray setup for real users in Russia. My experience was similar: switching the uTLS fingerprint from I ended up adding transport profiles to my ovpn project instead of relying on one REALITY configuration. The current setup supports:
With the self-SNI profile, Xray still owns port 443. Valid VLESS clients enter the tunnel, while an ordinary HTTPS probe receives a normal website instead of a VPN-specific response. Ansible handles certificate issuance and renewal, firewall rules and the fallback site. I do not claim that this makes the server unblockable. The goal is more practical: remove obvious probe behavior and avoid making one transport the only point of failure. Project: Transport details: Optional camouflage: |
|
I have added an experimental XHTTP + VLESS Encryption profile to my open-source OVPN project: The profile currently uses XHTTP The code, deployment templates, tests, and documentation are public. I would appreciate feedback on client compatibility, reconnect behavior, memory use, and longer soak tests. |
Uh oh!
There was an error while loading. Please reload this page.
Hello to everyone, so now I'm making VPN using Xray core and Vless + Reality protocol. I love the core and the protocol, but i don't think that will be enough, if my VPN gets some attention. I was thinking about implementing something like parcing packets, or just encrypt packet header, over Vless to confuse GFW and so it can't analyse my traffic and get anything, i'm talking like, they can't get the IP of my VPS server, and can't use any AI's to create some pattern's of my traffic. I know that to "hide" the IP of my VPS, I need to create my own site on my VPS and redirect traffic to my site's domain, and I already did it, but again, if some people near the government or smth like that will find out about my VPN, it just a matter of time to block my servers. Also talking about parcing, I really can't find something that can be pretty straightforward to implement in Xray core. Was thinking also about dynamic IP of my servers, but this idea is not ideal. Also using anything except TCP doesn't work for me. SplitHTTP doesn't match my requirnments, Quic is only accessible in older versions of 3ui-panel, and also it is too slow XD, I don't know why, but if we are talking about loading websites it is hella quick, but if downloading something, the speed is 5 times slower than when using regular TCP. Configuring it is not an option because I can't find anything usefull, only basic info. Also tried mKCP and it really didn't work, not only configuring it made it worse, the downloading speeds were worse than using quic. And websites after configuring were working poorly too. So that's pretty much all, it will be excellent if someone can help me find a parcing script which works with Xray, or maybe some sites where I can get a better knowledge of how I can create it myself. Any other ideas how to make a vpn connection more resistant to GFW will be excellent too. In advance thank you guys for reading this and spending your time on this disscussion!
All reactions