Automation & VPN

What is Xray / VLESS

What it is

A protocol and tool for bypassing internet blocks — it disguises VPN traffic as ordinary encrypted web traffic (HTTPS), so it is much harder to block by its "fingerprint".

How we use it

For clients for whom a regular VPN is no longer enough — we build an "entry node in Russia → exit node in the EU" scheme with a permanent tunnel and route health monitoring.

Where Xray helps a business

  • An ordinary VPN has stopped working: connections are cut by their characteristic traffic pattern.
  • You sell a VPN by subscription, and customers must be able to connect from any internet provider.
  • A team needs a corporate gateway to work tools that cannot be told apart from ordinary HTTPS.

Entry point types

  • VLESS Reality disguises the connection as TLS to someone else's website and needs neither a domain nor a certificate. It runs on our node in the Netherlands.
  • WebSocket + TLS is a tunnel that looks like an ordinary website on your domain. It works through nginx and suits the Windows 7 client.
  • XHTTP is another way to wrap traffic in HTTP. On our test bench every entry point, Reality, XHTTP, QUIC and WS+TLS, connects in Xray from a single subscription.

Which entry point is alive depends on the provider and the day, so a subscription carries several and the client picks one itself.

How we use it

  • The client's engine. In OshaVPN Xray is the main engine and sing-box the second. The UI, subscription and routing talk to the engine through a narrow engine-api layer, so the engine is switched by a setting, with no reinstall. After a drop Xray switches the entry point through its routing API in a fraction of a second, without restarting the engine.
  • The route. On the VPN route the entry nginx proxies the VLESS WebSocket tunnel; a path without the Upgrade header answers 404, like a page that does not exist.
  • The gateway. In the corporate gateway Xray routes and encrypts employee traffic.
  • Issuing keys. The Tech Poly VPN bot issues VLESS keys through the Marzban panel.

Routes and gateways are under Infrastructure, clients under Apps.

Common problems

  • Windows 7. Xray built with a newer Go does not start there, so the Windows 7 client runs sing-box through the system proxy with a WS+TLS entry point.
  • One entry point is not enough. An entry point can die on a particular provider. The client tries every entry point from the subscription at once and takes the first that opens the internet; on the test bench the race takes 0.9 to 1.3 seconds.
  • A dead TLS looks alive. An entry point whose TLS handshake does not complete is not considered alive and is never picked automatically.
  • The traffic domain will be noticed. A continuous WebSocket becomes visible sooner or later, so the traffic and subscription domains are kept separate.

When you do not need it

If nobody cuts your connections and you just need to link staff with the office, WireGuard is simpler and faster. Xray pays off where ordinary VPNs are already being blocked.

← All terms

Need a website, a bot or automation?

Terms explained — now let's get to work: tell us about the task and we'll turn it into a clear work plan.