XTLS-Iran-Reality

XTLS-Iran-Reality

基于Xray-core的高性能加密代理服务器

XTLS-Iran-Reality是基于Xray-core的服务器实现,采用Reality协议和TLS加密。该项目提供详细的安装配置指南,包括内核优化和客户端设置,以实现高性能安全的代理服务。此外,项目还包含特殊路由规则,允许在使用VPN时直接访问伊朗网站。

Reality协议Xray-core网络审查TLS加密VPN配置Github开源项目

XTLS-Iran-Reality

Xray-core (V2ray) Server with Reality Protocol for bypassing internet censorship in Iran with TLS encryption.


  • The main goal of this guide is to spread awereness on how to make one correctly.
  • The configuration file (config.json) is the main key here that includes a correct CIDR-IP block so the server does not initiate a connection back to Iran as this is not "normal" behaviour for a (web)server.

Notes

  • This is a noob-friendly guide but if you are an experienced linux user you should make a new user without sudo-access to run xray and give right permissions to files.
  • I wanted to make it easy for anyone non-technical to make a server without changing/creating users or editing permissions of files.
  • I will also teach on how to use your Iranian IP for direct communication to Iranian websites/services without disconnecting the "VPN" using routing rules.
  • <ins>This will not work with CDNs such as Cloudflare.</ins>
  • This will only work with clients that use xray-core 1.8.0 or above. See Clients for links to updated apps/programs.
  • V2rayNG version 1.8.2+ or above for Android.
  • FoXray for Iphone.

This guide is written for Ubuntu 22.04 LTS but any Debian based distro should also work.

What you need before starting this guide. Prerequisites

  • VPS or any other computer / Virtual-Machine running Ubuntu 22.04 LTS or a Debian based distro.
  • SSH or terminal/console access to your server.
  • You need to know your username (the username when you log into Ubuntu)
  • Port 443 open in your router or/and firewall.
  • Optional (But not required)

  • A Domain name, You can get a free domain name from https://freedns.afraid.org/ or https://www.noip.com/
  • Domain name must be pointed to your IP hosting the server.

First we need to do some kernel settings for performance and raise ulimits.

sudo nano /etc/sysctl.conf

Copy this at end of then file and save and close.

net.ipv4.tcp_keepalive_time = 90 net.ipv4.ip_local_port_range = 1024 65535 net.ipv4.tcp_fastopen = 3 net.core.default_qdisc=fq net.ipv4.tcp_congestion_control=bbr fs.file-max = 65535000

Then run this command to edit limits.conf

sudo nano /etc/security/limits.conf

Copy this at end of the file and save and close.

* soft nproc 655350 * hard nproc 655350 * soft nofile 655350 * hard nofile 655350 root soft nproc 655350 root hard nproc 655350 root soft nofile 655350 root hard nofile 655350

Run this to apply settings.

sudo sysctl -p

Install Xray (XTLS)

Create a folder called xray in your username home folder. You should be in this folder when you log in.

mkdir xray

Update Ubuntu package list and install unzip.

sudo apt-get update
sudo apt-get install unzip

Change directory to the newly created xray folder.

cd xray/

Download the latest geoasset file for blocking Iranian websites.

wget https://github.com/bootmortis/iran-hosted-domains/releases/latest/download/iran.dat

Download the latest version of XTLS-Xray-Core.

Link to release page.

https://github.com/XTLS/Xray-core/releases

To download the Xray-linux-64.zip file, we can use the wget command. Then we will unzip the file.

wget https://github.com/XTLS/Xray-core/releases/download/v1.8.3/Xray-linux-64.zip
unzip Xray-linux-64.zip

Remove the Xray-linux-64.zip for easier future updates. See updates

rm Xray-linux-64.zip

Generate UUID for config.json save this for later. Replace Secret with any random text/string

./xray uuid -i Secret

It should look something like this.

92c96807-e627-5328-8d85-XXXXXXXXX

Generate Private and Public keys and save it for later

./xray x25519

It should look something like this.

Private key: qBvFzkSMcgrXXXXXJu2VSt3-0dCy-XX8IXXXXXXXXXX Public key: rhrL9r_VGMWtwXXXXHO_eAi5e4CIn_XXXXXXXXXXXXX
  • The Private key is only for the server.
  • The Public key is for your apps/clients.

Run this command to generate short IDs, You can have multiple short IDs or just one. Save it for later.

openssl rand -hex 8

It should look something like this.

d82fb387XXXXXXXX

Install xray to boot at startup (Systemd-Service) create file or copy paste xray.service file from this repository

Create service file.

sudo nano /etc/systemd/system/xray.service
[Unit] Description=XTLS Xray-Core a VMESS/VLESS Server After=network.target nss-lookup.target [Service] # Change to your username <--- User=USERNAME Group=USERNAME CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE NoNewPrivileges=true # ---> Change to your username <--- ExecStart=/home/USERNAME/xray/xray run -config /home/USERNAME/xray/config.json Restart=on-failure RestartPreventExitStatus=23 StandardOutput=journal LimitNPROC=100000 LimitNOFILE=1000000 [Install] WantedBy=multi-user.target

Remember to edit this file to your own USERNAME! The parts to edit are.

User=USERNAME Group=USERNAME ExecStart=/home/USERNAME/xray/xray run -config /home/USERNAME/xray/config.json

Example

User=SasukeFreestyle Group=SasukeFreestyle ExecStart=/home/SasukeFreestyle/xray/xray run -config /home/SasukeFreestyle/xray/config.json

Reload services and enable auto-start.

sudo systemctl daemon-reload && sudo systemctl enable xray

Xray Configuration

Create a new file called config.json inside xray folder. Copy contents of config.json from this repository to the file.

nano /home/USERNAME/xray/config.json
  • Enter your UUID inside "YOUR UUID HERE"
  • Enter your Private Key inside "PRIVATE KEY HERE"
  • Enter your Short ID inside "shortIds":

  • Enter a destination ( "dest": ) and serverNames ("serverNames":).
  • This must be a website outside of Iran that you can access with a regular internet connection.
  • Destination website must have/support HTTPS/TLSv1.3 and H2.
  • This config is preconfigured with www.google-analytics.com website but here is a list of other websites that I think works.

The parts to edit are.

{ "listen":"0.0.0.0", "port":443, "protocol":"vless", "settings":{ "clients":[ { "id":"UUID HERE", // Your generated UUID here. "flow":"xtls-rprx-vision" } ], "decryption":"none" }, "streamSettings":{ "network":"tcp", "security":"reality", "realitySettings":{ "show":false, "dest":"www.google-analytics.com:443", // Edit to a website/server that works without VPN outside of Iran "xver":0, "serverNames":[ "www.google-analytics.com" // (SNI) Same as "dest" but without portnumber. ], "privateKey":"PRIVATE KEY HERE", // Private key you generated earlier. "minClientVer":"1.8.0", "maxClientVer":"", "maxTimeDiff":0, "shortIds":["SHORT ID HERE" // Short ID ] } },

Example

"id":"92c96807-e627-5328-8d85-XXXXXXXXX", "privateKey":"qBvFzkSMcgrXXXXXJu2VSt3-0dCy-XX8IXXXXXXXXXX", "shortIds":["d82fb387XXXXXXXX"]

Now start xray and check if xray is running it should now say Active: active (running).

sudo systemctl start xray && sudo systemctl status xray
● xray.service - XTLS Xray-Core a VMESS/VLESS Server Loaded: loaded (/etc/systemd/system/xray.service; enabled; vendor preset: enabled) Active: active (running) since Tue 2023-02-14 18:31:07 CET; 22min ago Main PID: 338362 (xray) Tasks: 16 (limit: 9365) Memory: 279.6M CPU: 5min 28.315s

Done! Now test the server with your clients.

Client/Apps (Settings)

V2rayNG (Android)

In V2rayNG press + then pick "Type manually[VLESS]"

Settings also apply to V2rayN (Windows).

Remember to set (uTLS) Fingerprint to Chrome.

  • Remarks/Alias
    • Name of the server, choose whatever name you want.
  • Address
    • IP or domain name of your server.
  • Port: 443
  • id:
    • Your UUID in config.json
  • Flow: xtls-rprx-vision
  • Encryption: None
  • Network: TCP
  • TLS: Reality
  • SNI: www.google-analytics.com (serverNames)
  • uTLS/Fingerprint: randomized or Chrome (I prefer randomized).
  • PublicKey: rhrL9r_VGMWtwXXXXHO_eAi5e4CIn_XXXXXXXXXXXXX, The public (not private) key you generated earlier.
  • ShortId: d82fb387XXXXXXXX , The short ID you generated earlier.

photo_2023-04-14_16-33-50

If you want to be able to visit Iranians websites without disconnecting the VPN follow the instructions in the video below.

This will also make it harder for government to see that you are using a VPN.

  • Connect to your server then go to Settings -> Geo asset files -> press download cloud to download new Geo asset files.

  • Go to Settings -> Custom Rules -> Direct URL or IP.

Enter

geoip:private,
geosite:private,
geoip:ir,
geosite:category-ir
  • Then save and reconnect to your server. Try browsing to youtube and tci.ir both will now work at the same time.

Video Instructions:

https://user-images.githubusercontent.com/2391403/235455406-96746fe5-fa45-43de-9c2a-9e9cca51f10d.mp4


V2rayN (Windows)

V2rayN 6.21+

v2rayN


Nekoray (Windows/Linux)

Nekoray 2.25+

Change core to sing-box in "Basic Settings".

nekoraysing

nekosettings


Iphone/Mac

FoXray

Pictures/Screenshots comming soon.


Routing rules

For routing rules for each client see bootmortis excellent guides. https://github.com/bootmortis/iran-hosted-domains

Link to some other routing rules for V2rayNG and FoXray


How to update to latest version

If a new version of Xray is published and you want to update to the latest version do this easy steps.

  • Log into your machine with SSH.

Change directory to your xray folder.

cd xray/

wget the latest release.

wget https://github.com/XTLS/Xray-core/releases/download/v1.8.3/Xray-linux-64.zip

This command will stop the xray service and remove old files and start xray service again.

sudo systemctl stop xray && rm geo* && rm LICENSE && rm README.md && rm xray && unzip Xray-linux-64.zip && sudo systemctl start xray

Make sure xray is running by entering this command.

sudo systemctl status xray

Remove the zipfile.

rm Xray-linux-64.zip

Done!

Credits

XTLS-core Team / v2fly

@bootmortis for Iranian domain list and routing rules.

And many

编辑推荐精选

酷表ChatExcel

酷表ChatExcel

大模型驱动的Excel数据处理工具

基于大模型交互的表格处理系统,允许用户通过对话方式完成数据整理和可视化分析。系统采用机器学习算法解析用户指令,自动执行排序、公式计算和数据透视等操作,支持多种文件格式导入导出。数据处理响应速度保持在0.8秒以内,支持超过100万行数据的即时分析。

AI工具酷表ChatExcelAI智能客服AI营销产品使用教程
DeepEP

DeepEP

DeepSeek开源的专家并行通信优化框架

DeepEP是一个专为大规模分布式计算设计的通信库,重点解决专家并行模式中的通信瓶颈问题。其核心架构采用分层拓扑感知技术,能够自动识别节点间物理连接关系,优化数据传输路径。通过实现动态路由选择与负载均衡机制,系统在千卡级计算集群中维持稳定的低延迟特性,同时兼容主流深度学习框架的通信接口。

DeepSeek

DeepSeek

全球领先开源大模型,高效智能助手

DeepSeek是一家幻方量化创办的专注于通用人工智能的中国科技公司,主攻大模型研发与应用。DeepSeek-R1是开源的推理模型,擅长处理复杂任务且可免费商用。

问小白

问小白

DeepSeek R1 满血模型上线

问小白是一个基于 DeepSeek R1 模型的智能对话平台,专为用户提供高效、贴心的对话体验。实时在线,支持深度思考和联网搜索。免费不限次数,帮用户写作、创作、分析和规划,各种任务随时完成!

AI主流办公工具有哪些办公热门AI 助手
KnowS

KnowS

AI医学搜索引擎 整合4000万+实时更新的全球医学文献

医学领域专用搜索引擎整合4000万+实时更新的全球医学文献,通过自主研发AI模型实现精准知识检索。系统每日更新指南、中英文文献及会议资料,搜索准确率较传统工具提升80%,同时将大模型幻觉率控制在8%以下。支持临床建议生成、文献深度解析、学术报告制作等全流程科研辅助,典型用户反馈显示每周可节省医疗工作者70%时间。

Windsurf Wave 3

Windsurf Wave 3

Windsurf Editor推出第三次重大更新Wave 3

新增模型上下文协议支持与智能编辑功能。本次更新包含五项核心改进:支持接入MCP协议扩展工具生态,Tab键智能跳转提升编码效率,Turbo模式实现自动化终端操作,图片拖拽功能优化多模态交互,以及面向付费用户的个性化图标定制。系统同步集成DeepSeek、Gemini等新模型,并通过信用点数机制实现差异化的资源调配。

AI IDE
腾讯元宝

腾讯元宝

腾讯自研的混元大模型AI助手

腾讯元宝是腾讯基于自研的混元大模型推出的一款多功能AI应用,旨在通过人工智能技术提升用户在写作、绘画、翻译、编程、搜索、阅读总结等多个领域的工作与生活效率。

AI助手AI对话AI工具腾讯元宝智能体热门 AI 办公助手
Grok3

Grok3

埃隆·马斯克旗下的人工智能公司 xAI 推出的第三代大规模语言模型

Grok3 是由埃隆·马斯克旗下的人工智能公司 xAI 推出的第三代大规模语言模型,常被马斯克称为“地球上最聪明的 AI”。它不仅是在前代产品 Grok 1 和 Grok 2 基础上的一次飞跃,还在多个关键技术上实现了创新突破。

OmniParser

OmniParser

帮助AI理解电脑屏幕 纯视觉GUI元素的自动化解析方案

开源工具通过计算机视觉技术实现图形界面元素的智能识别与结构化处理,支持自动化测试脚本生成和辅助功能开发。项目采用模块化设计,提供API接口与多种输出格式,适用于跨平台应用场景。核心算法优化了元素定位精度,在动态界面和复杂布局场景下保持稳定解析能力。

OmniParser界面解析交互区域检测Github开源项目
流畅阅读

流畅阅读

AI网页翻译插件 双语阅读工具,还原母语级体验

流畅阅读是一款浏览器翻译插件,通过上下文智能分析提升翻译准确性,支持中英双语对照显示。集成多翻译引擎接口,允许用户自定义翻译规则和快捷键配置,操作数据全部存储在本地设备保障隐私安全。兼容Chrome、Edge、Firefox等主流浏览器,基于GPL-3.0开源协议开发,提供持续的功能迭代和社区支持。

AI翻译AI翻译引擎AI翻译工具
下拉加载更多