What it is
A modern way to disguise a VPN connection as ordinary HTTPS traffic to a well-known site, so it cannot be told apart and blocked. A protocol of the Xray core.
How we use it
On the studio's VPN routes the entry node accepts VLESS with Reality or WebSocket+TLS and the exit node is abroad. The client picks a live entry point itself.
Where it helps a business
- Ordinary VPN protocols get blocked, and you need a connection indistinguishable from visiting a normal website.
- You would rather not give the exit node a domain and certificate that could be blocked.
How we use it
- A standalone node. On the VPN route a separate node in the Netherlands with its own Marzban panel runs VLESS Reality: the connection is disguised as TLS to someone else's website, and no domain or certificate is needed.
- Keys from a bot. The subscription-sales bot creates a Marzban user with the xtls-rprx-vision flow and issues a VLESS key; the subscriptions are built on VLESS and Reality.
- The client. In OshaVPN a Reality entry point connects in the Xray engine from the same subscription as the other entry points.
Common problems
- Not every client and system. The Windows 7 client runs sing-box with a WS+TLS entry point, so a subscription needs more than Reality.
- One entry point is one point of failure. That is why a subscription carries several entry points of different types, and the client picks a live one itself.
When you do not need it
If the VPN is for reaching your own servers and nobody blocks it, WireGuard is enough. Reality pays off where blocking happens.