Replies: 4 comments 6 replies
|
I didnt read it (in my TODO), but there is an official guide: |
|
Blocking is more severe on mobile networks. Try establishing a VLESS connection from your home router to a foreign node. Many ISPs allow such connections. VLESS/Reality setups are more easily detected. In that case, try configuring VLESS-Nginx with real certificates and a simple website. This approach should work from home internet. |
|
I already have all this and have tested it. and even more. What I have done at the moment is that I have a cloak connection established from a foreign VPS to a Russian VPS, and inside this cloak there is a VLESS from the Russian to the foreign one so that proxied data can flow. |
|
Ok, so basically you want to initiate tunnel connection from foreign VPS but establish connections from home to the free Internet thru foreign VPS. Did you try to establish SSH tunnel (tun interface, not proxy)? If Russian TSPUs block direct SSH, you can connect SSH inside VLESS: foreign VPS connects VLESS to Russian VPS and then SSH tunnel inside VLESS from foreign VPS to russian VPS. You will get tun interfaces on server and client and you can route all the traffic in both directions. If you use VLESS as outer layer, inner SSH can be replaced by anything that fully supports L3, e.g. Wireguard or OpenVPN. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
In Russia, blocking of foreign internet connections has become increasingly strict and brutal. They block not only by SNI or protocol, but also by the number of connections to an address or their intensity. This forces the use of cascading proxies, using VPSs in Russia as intermediate ones, because blocking on VPS communication channels is more lenient.
But over time, blocking on VPS communication channels is also becoming more severe.
And here's an interesting point: the blocking is targeted at traffic going OUTSIDE.
Therefore, the following option would be interesting:
create a scheme in which the connection between a domestic VPS and a foreign VPS is initiated by an foreign VPS, but the traffic goes from the domestic to the foreign one.
xray-client --xhttp--> domestic VPS <--xhttp-- foreign VPS --> INTERNET
All reactions