- tlsmimic: wrap QUIC packets in TLS 1.3 record headers - multi: auto-detect Salamander/TLS-mimic/plain on the same port - multi: random padding and jitter support for DPI evasion - reconnect: periodic session recreation via MaxSessionDuration - client/server: wire tlsmimic/auto/plain obfs types and config - NEW_FEATURES: translated to English
4 KiB
New Features (vs upstream)
1. L3 VPN Tunnel (Network)
Full IP tunnel over QUIC. A TUN interface is created on the server, clients get an IP from a pool, and all L3 traffic is routed through the encrypted QUIC connection.
Server config (config.json)
{
"network": {
"enabled": true,
"listen": ":5199",
"token": "mysecret",
"tun": {
"name": "hynt0",
"mtu": 1400
},
"pool": "10.10.0.0/24"
}
}
Parameters:
enabled— enable the tunnellisten— QUIC listener address (default:5199)token— shared secret for client authenticationtun.name— TUN interface name on the servertun.mtu— TUN interface MTUpool— CIDR subnet for assigning IPs to clients
Client config (client.json)
{
"network": {
"server": "your.server.com:5199",
"token": "mysecret",
"tun": {
"name": "hynt0_c",
"mtu": 1400
}
}
}
Parameters:
server— server address (required)token— shared secret (must match the server)tun.name— TUN interface name on the clienttun.mtu— TUN interface MTU
2. FileMask Noise
New obfuscation layer that masks traffic as downloading encrypted files. It works on top of the existing obfuscation (Salamander/Gecko). The server sends the client random chunks of real files from disk, simulating an active download.
Server config
{
"noise": {
"type": "filemask",
"filemask": {
"dir": "/path/to/files",
"maxRate": "512 kbps",
"minPacketSize": 512,
"maxPacketSize": 1400,
"idleThreshold": "3s"
}
}
}
Parameters:
type—"filemask"to enable;"none"or empty to disablefilemask.dir— required, directory containing files used to mask trafficfilemask.maxRate— max noise rate (default"512 kbps")filemask.minPacketSize— minimum noise packet sizefilemask.maxPacketSize— maximum noise packet sizefilemask.idleThreshold— client idle timeout before noise generation starts
Files from the specified directory are encrypted with AES-GCM on the fly and sent to the client.
3. Hysteria Outbound
Ability to use another Hysteria server as an upstream/outbound node. Allows building chains: client -> server A -> server B (via hysteria outbound).
Server config
{
"outbounds": [
{
"name": "upstream-hy2",
"type": "hysteria",
"hysteria": {
"server": "upstream.example.com:443",
"auth": "mypassword",
"tls": {
"sni": "upstream.example.com",
"insecure": false,
"pinSHA256": "abc123...",
"ca": "/path/to/ca.pem"
},
"quic": {
"initStreamReceiveWindow": 8388608,
"maxStreamReceiveWindow": 8388608,
"initConnReceiveWindow": 20971520,
"maxConnReceiveWindow": 20971520,
"maxIdleTimeout": "30s",
"disablePathMTUDiscovery": false
},
"bandwidth": {
"up": "100 mbps",
"down": "200 mbps"
},
"congestion": {
"type": "bbr",
"bbrProfile": "auto"
},
"obfs": {
"type": "salamander",
"salamander": {
"password": "obfspass"
}
},
"transport": {
"type": "udp",
"udp": {
"hopInterval": "5s"
}
},
"fastOpen": true
}
}
]
}
Supported parameters inside hysteria:
server— target Hysteria server address (required)auth— authentication password (required)tls— TLS settings (SNI, insecure, pinSHA256, CA)quic— QUIC settings (receive windows, timeouts)bandwidth— bandwidth limitscongestion— congestion control algorithm (bbr/cubic/brutal)obfs— obfuscation for the upstream connection (salamander/gecko)transport— transport (udp, with optional port hopping)fastOpen— enable fast open
Used in the outbounds section alongside direct, socks5, http.