Skip to content

Protocols ​

This section is about choosing what your users connect with. Each protocol is an Inbound you create once in the shared pool and put on a Template; the nodes on that template serve it, and every user of the template gets an entry for it in their Subscription. How to create one is on Inbounds; the pages here explain each protocol's fields and limits.

The inbounds page: a list of inbounds with their protocol, port and TLS modeThe inbounds page: a list of inbounds with their protocol, port and TLS mode

Every inbound at a glance ​

Runs over is what the node listens on, which is what your firewall has to let in. TLS lists the modes the form offers: a certificate (the node's own, one from the panel's store, or your own PEM pair), REALITY, or none. Behind a CDN says whether a domain front can carry it.

ProtocolRuns overTLSBehind a CDNPage
VLESSTCP (UDP with the quic or mkcp transport)TLS, REALITY, noneyes, with an HTTP-shaped transport and no REALITYVLESS with REALITY
VMessas VLESSTLS, REALITY, noneas VLESSVMess
Trojanas VLESSTLS, REALITY, noneas VLESSTrojan
ShadowsocksTCP and UDPnone (its own encryption)noShadowsocks
Hysteria2, Hysteria (v1)UDP (QUIC)TLS, requirednoHysteria2 and port hopping
TUICUDP (QUIC)TLS, requirednoTUIC
NaiveProxyTCP (HTTP/2), optionally UDP (HTTP/3)TLS, requirednoNaiveProxy
AnyTLSTCPTLS or REALITY, requirednoMore protocols
ShadowTLSTCPborrowed from a real sitenoMore protocols
MieruTCP or UDPnone (its own encryption)noMore protocols
SnellTCPnone (its own encryption)noMore protocols
MTProxyTCPnone (its own encryption)noMore protocols
SSHTCPSSH's ownnoMore protocols
TrustTunnelTCP or UDPTLS, requirednoMore protocols
SudokuTCPnone (its own encryption)noMore protocols
SOCKS, mixedTCPnonenoMore protocols
HTTPTCPTLS, REALITY, nonenoMore protocols
IngressTCPTLS or nonethrough its childrenOne port for many inbounds
WireGuard (endpoint)UDPWireGuard's ownnoWireGuard
OpenVPN (endpoint)UDP or TCPTLS (certificate)noOpenVPN and OpenConnect
OpenConnect (endpoint)TCP and UDPTLS (certificate)noOpenVPN and OpenConnect

VLESS, VMess and Trojan take a transport: tcp (none), ws, grpc, http (HTTP/2), httpupgrade, quic, xhttp or mkcp. No other protocol has a transport. A CDN can carry the HTTP-shaped ones: ws, grpc, http, httpupgrade and xhttp.

WireGuard, OpenVPN and OpenConnect are endpoints, made on Endpoints. They reach users the same way inbounds do. The local types the form also lists (tun, redirect, tproxy, direct) are not for customers; see More protocols.

Which apps read what ​

A subscription answers in the format the app asks for. Four formats matter:

  • Share links (vless://, trojan://, hysteria2://…), read by almost every app, including the Xray-based apps (v2rayNG, v2rayN, Streisand, Happ).
  • Clash, read by Clash Meta and other mihomo apps.
  • sing-box, read by sing-box apps (SFA, SFI, Karing, NekoBox).
  • Xray JSON, read by Xray-based apps.

An entry an app cannot use is left out of that app's file, so the same user can see a different list in two apps.

ProtocolShare linkClashsing-boxXray JSON
VLESSyesyesyes, except with VLESS Encryptionyes, except without TLS, REALITY or VLESS Encryption
VMess, Trojanyesyesyesyes
Shadowsocksyesyesyesyes
Hysteria2yesyesyesyes
Hysteria, TUIC, AnyTLSyesyesyesno
NaiveProxyyesnoyesno
SOCKS, mixedyesyesyesyes
HTTPnoyesyesyes
SSHnoyesyesno
Mierunoyesnono
Snellnonoyesno
ShadowTLS, MTProxy, TrustTunnel, Sudokunononono
WireGuard.conf fileyesyesyes
OpenVPN.ovpn filenoyesno
OpenConnectserver and sign-in detailsnoyesno

For VLESS, VMess and Trojan the transport decides as well:

TransportClashsing-boxXray JSONBehind a CDN
tcp (none)yesyesyesno
ws (WebSocket)yesyesyesyes
grpcyesyesyesyes
http (HTTP/2)yesyesnoyes
httpupgradeyesyesyesyes
quicnoyesnono
xhttpnonoyesyes
mkcpnonoyesno

Share links carry every transport; whether a given app can dial it is the app's business.

Tell users to turn Mux off

Xray-based apps have a Mux switch. Turned on, the connection fails with nothing in the app to explain it. The subscription page warns about it; repeat it in your own setup instructions. See Subscriptions and the subscription page.

How to choose ​

  • Start with VLESS + REALITY. It needs no domain and no certificate, works in nearly every app, and is the first preset on Inbounds → From a preset.
  • Add a WebSocket, gRPC or XHTTP inbound with TLS when you want to put a CDN in front. REALITY cannot be fronted. See Domain fronting.
  • Add Hysteria2 for users on lossy mobile or long-distance links, where a UDP protocol holds up better than TCP. It needs UDP to reach the node, and port hopping helps where single UDP ports are blocked.
  • Offer two or three shapes. Different networks block different things. A subscription with a TCP protocol, a CDN-fronted one and a UDP one gives a user something that works when one of them stops.
  • Use an ingress when you have only port 443 to spare and want several TCP inbounds on it.
  • Use WireGuard or OpenVPN / OpenConnect for users who need a standard VPN app, a router, or a work laptop that can only run one of those.

Every protocol carries the same accounting, quotas, speed and address limits per user; nothing about the choice changes how you sell an account.

Text and images under CC BY 4.0.