hysteria/NEW_FEATURES.md
Niko Marmeladkov 1e77bbe7b7
Some checks are pending
Build master branch / build (push) Waiting to run
Tests / Test (push) Waiting to run
feat: TLS 1.3 mimicry obfuscation, multi-mode (auto + plain), session recreation
- tlsmimic: wrap QUIC packets in TLS 1.3 record headers
- multi: auto-detect Salamander/TLS-mimic/plain on the same port
- multi: random padding and jitter support for DPI evasion
- reconnect: periodic session recreation via MaxSessionDuration
- client/server: wire tlsmimic/auto/plain obfs types and config
- NEW_FEATURES: translated to English
2026-06-17 16:36:29 +03:00

4 KiB

New Features (vs upstream)

1. L3 VPN Tunnel (Network)

Full IP tunnel over QUIC. A TUN interface is created on the server, clients get an IP from a pool, and all L3 traffic is routed through the encrypted QUIC connection.

Server config (config.json)

{
  "network": {
    "enabled": true,
    "listen": ":5199",
    "token": "mysecret",
    "tun": {
      "name": "hynt0",
      "mtu": 1400
    },
    "pool": "10.10.0.0/24"
  }
}

Parameters:

  • enabled — enable the tunnel
  • listen — QUIC listener address (default :5199)
  • token — shared secret for client authentication
  • tun.name — TUN interface name on the server
  • tun.mtu — TUN interface MTU
  • pool — CIDR subnet for assigning IPs to clients

Client config (client.json)

{
  "network": {
    "server": "your.server.com:5199",
    "token": "mysecret",
    "tun": {
      "name": "hynt0_c",
      "mtu": 1400
    }
  }
}

Parameters:

  • server — server address (required)
  • token — shared secret (must match the server)
  • tun.name — TUN interface name on the client
  • tun.mtu — TUN interface MTU

2. FileMask Noise

New obfuscation layer that masks traffic as downloading encrypted files. It works on top of the existing obfuscation (Salamander/Gecko). The server sends the client random chunks of real files from disk, simulating an active download.

Server config

{
  "noise": {
    "type": "filemask",
    "filemask": {
      "dir": "/path/to/files",
      "maxRate": "512 kbps",
      "minPacketSize": 512,
      "maxPacketSize": 1400,
      "idleThreshold": "3s"
    }
  }
}

Parameters:

  • type"filemask" to enable; "none" or empty to disable
  • filemask.dirrequired, directory containing files used to mask traffic
  • filemask.maxRate — max noise rate (default "512 kbps")
  • filemask.minPacketSize — minimum noise packet size
  • filemask.maxPacketSize — maximum noise packet size
  • filemask.idleThreshold — client idle timeout before noise generation starts

Files from the specified directory are encrypted with AES-GCM on the fly and sent to the client.


3. Hysteria Outbound

Ability to use another Hysteria server as an upstream/outbound node. Allows building chains: client -> server A -> server B (via hysteria outbound).

Server config

{
  "outbounds": [
    {
      "name": "upstream-hy2",
      "type": "hysteria",
      "hysteria": {
        "server": "upstream.example.com:443",
        "auth": "mypassword",
        "tls": {
          "sni": "upstream.example.com",
          "insecure": false,
          "pinSHA256": "abc123...",
          "ca": "/path/to/ca.pem"
        },
        "quic": {
          "initStreamReceiveWindow": 8388608,
          "maxStreamReceiveWindow": 8388608,
          "initConnReceiveWindow": 20971520,
          "maxConnReceiveWindow": 20971520,
          "maxIdleTimeout": "30s",
          "disablePathMTUDiscovery": false
        },
        "bandwidth": {
          "up": "100 mbps",
          "down": "200 mbps"
        },
        "congestion": {
          "type": "bbr",
          "bbrProfile": "auto"
        },
        "obfs": {
          "type": "salamander",
          "salamander": {
            "password": "obfspass"
          }
        },
        "transport": {
          "type": "udp",
          "udp": {
            "hopInterval": "5s"
          }
        },
        "fastOpen": true
      }
    }
  ]
}

Supported parameters inside hysteria:

  • server — target Hysteria server address (required)
  • auth — authentication password (required)
  • tls — TLS settings (SNI, insecure, pinSHA256, CA)
  • quic — QUIC settings (receive windows, timeouts)
  • bandwidth — bandwidth limits
  • congestion — congestion control algorithm (bbr/cubic/brutal)
  • obfs — obfuscation for the upstream connection (salamander/gecko)
  • transport — transport (udp, with optional port hopping)
  • fastOpen — enable fast open

Used in the outbounds section alongside direct, socks5, http.