Transport: Clarify Direct Outbounds and TLS/REALITY Compatibility

This commit is contained in:
Meow
2026-05-09 19:23:15 +08:00
parent a3acb5937d
commit 3258153a21
12 changed files with 30 additions and 12 deletions
+5 -3
View File
@@ -1,18 +1,18 @@
# Transport Configuration
Transport configuration controls how the current Xray instance communicates with its peer. That peer may be another Xray node, or it may simply be a public network target.
Transport configuration controls how the current Xray instance communicates with its peer. That peer may be another Xray node, or it may simply be any ordinary public network target.
It covers the part below the proxy protocol itself, including transport methods, transport security, and additional low-level behavior.
These three categories belong to different layers and can usually be combined:
- Transport methods specify how the data stream is carried, such as RAW, WebSocket, gRPC, or Hysteria.
- Transport methods specify how the data stream is carried, such as RAW, WebSocket, gRPC, Hysteria, and others.
- Transport security specifies the protection mechanism used during transport, such as TLS or REALITY.
- Additional configuration supplements low-level network behavior and final traffic obfuscation.
Some transport settings directly affect how a connection is established with the remote side. For settings that require negotiation, both sides usually need compatible configurations. For example, if one side uses WebSocket, the other side must also use WebSocket, otherwise the connection cannot be established.
For direct outbounds such as [Freedom](./outbounds/freedom.md), the peer is not necessarily another Xray node and may simply be a public network target. In that case transport configuration is not used to negotiate with another Xray instance, but to control how the local connection is sent. In that scenario, only `sockopt` is available.
For direct outbounds such as [Freedom](./outbounds/freedom.md), the peer is usually any ordinary public network target, such as Amazon's website or WeChat's servers. In that case, transport configuration does not need to negotiate with the other side, and generally cannot do so either. Instead, it is used to control how the local connection is sent. In that scenario, only `sockopt` is available.
## StreamSettingsObject
@@ -95,6 +95,7 @@ Whether to enable transport security. Supported options are:
REALITY configuration. REALITY is a modified form of TLS that uses the appearance and handshake characteristics of a target site as camouflage.
Only valid when `security` is `reality`.
It can only be used together with the `RAW`, `XHTTP`, and `gRPC` transport methods.
::: tip
REALITY is currently one of the most secure transport-security schemes, and from the outside its traffic looks consistent with ordinary web traffic. Enabling REALITY together with a suitable XTLS Vision flow-control mode can also deliver performance gains of several times or even more than ten times.
@@ -105,6 +106,7 @@ REALITY is currently one of the most secure transport-security schemes, and from
TLS configuration. TLS is provided by Go. In normal cases the negotiation result is TLS 1.3. DTLS is not supported.
Only valid when `security` is `tls`.
It supports use with the `RAW`, `XHTTP`, `mKCP`, `gRPC`, `WebSocket`, `HTTPUpgrade`, and `Hysteria` transport methods.
---
+1 -1
View File
@@ -1,6 +1,6 @@
# Xray Transport Configuration
Xray supports the following transport configuration categories:
Xray supports the following transport configuration categories
## Transport Methods
+2
View File
@@ -2,6 +2,8 @@
REALITY is a modified form of TLS that uses the appearance and handshake characteristics of a target site as camouflage.
REALITY can only be used together with the `RAW`, `XHTTP`, and `gRPC` transport methods.
:::: tip
REALITY is currently one of the most secure transport-security schemes, and from the outside its traffic shape is consistent with ordinary web browsing.<br>
Enabling REALITY together with a suitable XTLS Vision flow-control mode can improve performance by several times or even more than ten times.
+2
View File
@@ -4,6 +4,8 @@ TLS is a common transport-security mechanism.
It can be used to configure transport-layer encryption, certificate verification, client fingerprints, and related certificate settings.
It supports use with the `RAW`, `XHTTP`, `mKCP`, `gRPC`, `WebSocket`, `HTTPUpgrade`, and `Hysteria` transport methods.
## TLSObject
`TLSObject` corresponds to the `tlsSettings` item in [`StreamSettingsObject`](../transport.md#streamsettingsobject).