mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-10-02 20:08:18 +03:00
Add udp mask
EN Add udp mask RU Add udp mask Prettified Code!
This commit is contained in:
@@ -20,6 +20,9 @@ Transport specifies a stable method for data transmission. Generally, both ends
|
||||
"grpcSettings": {},
|
||||
"wsSettings": {},
|
||||
"httpupgradeSettings": {},
|
||||
"finalmask": {
|
||||
"udp": []
|
||||
},
|
||||
"sockopt": {
|
||||
"mark": 0,
|
||||
"tcpMaxSeg": 1440,
|
||||
@@ -101,6 +104,10 @@ Hysteria configuration for the current connection. Only valid when this connecti
|
||||
|
||||
Specific configurations related to transparent proxying.
|
||||
|
||||
> `finalmask`: [FinalMaskObject](#finalmaskobject)
|
||||
|
||||
FinalMask configuration, used for general traffic obfuscation.
|
||||
|
||||
### TLSObject
|
||||
|
||||
```json
|
||||
@@ -888,3 +895,100 @@ E.g., waiting IP queue sorted as 46464646 (set to 1), 44664466 (set to 2).
|
||||
> `maxConcurrentTry`: number
|
||||
|
||||
Max concurrent attempts. Prevents core from making massive connections if many IPs resolve but fail. Default 4. Set to 0 to disable happyEyeballs.
|
||||
|
||||
### FinalMaskObject
|
||||
|
||||
FinalMask applies a final layer of obfuscation to the traffic after the core has processed transport layer encryption, including TLS/REALITY. Currently, only UDP is supported.
|
||||
|
||||
```json
|
||||
{
|
||||
"udp": [
|
||||
{
|
||||
"type": "header-dns",
|
||||
"settings": {
|
||||
"domain": "[www.baidu.com](https://www.baidu.com)"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
> `udp`: \[ list \]
|
||||
|
||||
An array representing the list of obfuscations applied to UDP traffic. Multiple obfuscations will be applied sequentially, layer by layer. The `settings` vary depending on the obfuscation type; see below.
|
||||
|
||||
> `mkcp-original`
|
||||
|
||||
The simple obfuscation that was previously applied by default in mKCP. You may need to configure this to connect to legacy mKCP servers. No additional configuration required.
|
||||
|
||||
> `mkcp-aes128gcm`
|
||||
|
||||
Corresponds to the original mKCP `seed` feature. Uses AES-128-GCM for obfuscation.
|
||||
|
||||
- `settings`:
|
||||
```json
|
||||
{
|
||||
"password": "your-password"
|
||||
}
|
||||
```
|
||||
|
||||
`password` is the encryption password; it must be consistent between the server and the client.
|
||||
|
||||
> `header-dns`
|
||||
|
||||
Corresponds to the original mKCP DNS obfuscation.
|
||||
|
||||
- `settings`:
|
||||
```json
|
||||
{
|
||||
"domain": "[www.example.com](https://www.example.com)"
|
||||
}
|
||||
```
|
||||
|
||||
`domain` is the domain name used for obfuscation.
|
||||
|
||||
> `header-dtls`
|
||||
|
||||
Corresponds to the original mKCP DTLS obfuscation. No additional configuration required.
|
||||
|
||||
> `header-srtp`
|
||||
|
||||
Corresponds to the original mKCP SRTP obfuscation. No additional configuration required.
|
||||
|
||||
> `header-utp`
|
||||
|
||||
Corresponds to the original mKCP uTP obfuscation. No additional configuration required.
|
||||
|
||||
> `header-wechat`
|
||||
|
||||
Corresponds to the original mKCP WeChat Video obfuscation. No additional configuration required.
|
||||
|
||||
> `header-wireguard`
|
||||
|
||||
Corresponds to the original mKCP WireGuard obfuscation. No additional configuration required.
|
||||
|
||||
> `xdns`
|
||||
|
||||
Experimental feature. Utilizes DNS queries to transport data (similar to DNSTT). It performs standard DNS TXT queries to transport the payload. Due to technical limitations, the resulting MTU is very small, making it incompatible with QUIC; it is recommended to use it with mKCP. Recommended MTU values: Client 130, Server 900.
|
||||
|
||||
- `settings`:
|
||||
```json
|
||||
{
|
||||
"domain": "[www.example.com](https://www.example.com)"
|
||||
}
|
||||
```
|
||||
|
||||
`domain` is the domain name used for queries. Since the queries performed are standard, they can be forwarded through any UDP DNS server, although efficiency may be very suboptimal. To use this feature, the server needs to listen on port 53, and the proxy protocol should direct the target to a DNS server (e.g., 8.8.8.8:53). Additionally, you must own the domain specified in `domain` and point its NS record to your server.
|
||||
|
||||
> `salamander`
|
||||
|
||||
Salamander obfuscation (from Hysteria2).
|
||||
|
||||
- `settings`:
|
||||
```json
|
||||
{
|
||||
"password": "your-password"
|
||||
}
|
||||
```
|
||||
|
||||
`password` is the obfuscation password; it must be consistent between the server and the client.
|
||||
|
||||
@@ -20,15 +20,16 @@ Please ensure that the firewall configuration on the host is correct.
|
||||
"downlinkCapacity": 20,
|
||||
"congestion": false,
|
||||
"readBufferSize": 1,
|
||||
"writeBufferSize": 1,
|
||||
"header": {
|
||||
"type": "none",
|
||||
"domain": "example.com"
|
||||
},
|
||||
"seed": "Password"
|
||||
"writeBufferSize": 1
|
||||
}
|
||||
```
|
||||
|
||||
::: TIP
|
||||
The `header` and `seed` fields have been removed. Please use [FinalMask](../transport.md#finalmaskobject) for configuration.
|
||||
|
||||
Additionally, the previously default mKCP obfuscation has also been removed. To connect to a legacy server, you need to configure `mkcp-original` in FinalMask.
|
||||
:::
|
||||
|
||||
> `mtu`: number
|
||||
|
||||
Maximum Transmission Unit.
|
||||
@@ -91,43 +92,6 @@ When high-speed transmission is required, specifying larger `readBufferSize` and
|
||||
When the network speed does not exceed 20MB/s, the default value of 1MB can meet the demand; beyond that, you can appropriately increase the values of `readBufferSize` and `writeBufferSize`, and then manually balance the relationship between speed and memory.
|
||||
:::
|
||||
|
||||
> `header`: [HeaderObject](#headerobject)
|
||||
|
||||
Packet header camouflage settings.
|
||||
|
||||
> `seed`: string
|
||||
|
||||
Optional obfuscation password. Uses the AES-128-GCM algorithm to obfuscate traffic data. Must be consistent between the client and the server.
|
||||
|
||||
This obfuscation mechanism cannot be used to guarantee the security of communication content, but it may help mitigate some forms of blocking.
|
||||
|
||||
> Currently, in test environments, no port blocking phenomena have been observed after enabling this setting compared to the original unobfuscated version.
|
||||
|
||||
### HeaderObject
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "none",
|
||||
"domain": "example.com"
|
||||
}
|
||||
```
|
||||
|
||||
> `type`: string
|
||||
|
||||
Camouflage type. Optional values are:
|
||||
|
||||
- `"none"`: Default value. No camouflage is performed; sent data is a packet without characteristics.
|
||||
- `"srtp"`: Disguised as SRTP packets, recognized as video call data (e.g., FaceTime).
|
||||
- `"utp"`: Disguised as uTP packets, recognized as BT download data.
|
||||
- `"wechat-video"`: Disguised as WeChat video call packets.
|
||||
- `"dtls"`: Disguised as DTLS 1.2 packets.
|
||||
- `"wireguard"`: Disguised as WireGuard packets. (Not the real WireGuard protocol).
|
||||
- `"dns"`: Some campus networks allow DNS queries without logging in. Adding a DNS header to KCP allows traffic to be disguised as DNS requests, potentially bypassing login requirements on some campus networks.
|
||||
|
||||
> `domain`: string
|
||||
|
||||
Used with the camouflage type `"dns"`. You can fill in any domain name.
|
||||
|
||||
## Credits
|
||||
|
||||
- [@skywind3000](https://github.com/skywind3000) Invented and implemented the KCP protocol.
|
||||
|
||||
Reference in New Issue
Block a user