Skip to main content

VPN and proxy tunnel protocols

Full-device VPNs and proxy/tunnel protocols solve different routing problems. Every live row must pass a protocol-specific full tunnel, HTTPS request and changed exit-IP check; port reachability is never counted as a working VPN.

Full-device VPNs

OpenVPN

UDP or TCP VPN tunnel

4081 visible rows3890 verified online4085 stored configurations178 metrics pending13 failing/staleIndexing gate passed

Mature full-device VPN with broad client and router support; current catalog rows include downloadable .ovpn profiles.

WireGuard

UDP VPN tunnel

0 verified configurations0 stored configurationsIndexing paused

A relay hostname and port are not a usable WireGuard profile. A publishable client key, peer key and allowed-IP configuration are required.

Gate: 0/14 qualifying days · zero usable rows seven days

IKEv2

IKEv2/IPsec

0 verified configurations0 stored configurationsIndexing paused

IKEv2 requires credentials or certificates and a separate strongSwan checker; an open UDP port is not proof of a working VPN.

Gate: 0/14 qualifying days · zero usable rows seven days

Proxy and tunnel protocols

VLESS

TCP, WebSocket, gRPC or XHTTP with TLS/REALITY

37 verified configurations37 stored configurationsIndexing gate passed

Proxy tunnel protocol whose transport and TLS/REALITY settings must be preserved by a compatible client.

Gate: 9/14 qualifying days · indexable

Trojan

TCP with TLS

21 verified configurations8382 stored configurationsIndexing paused

Use a current client that supports Trojan over TLS and verify the SNI before importing any public configuration.

Gate: 6/14 qualifying days · insufficient qualified history

VMess

TCP, WebSocket or gRPC

128 verified configurations4795 stored configurationsIndexing gate passed

VMess connection details are transport-specific; the client must preserve TLS, host, path and transport settings.

Gate: 9/14 qualifying days · indexable

Shadowsocks

Encrypted TCP/UDP proxy

229 verified configurations6190 stored configurationsIndexing gate passed

Outline access keys use the Shadowsocks protocol family, so Outline is covered here instead of being counted as a separate tunnel protocol.

Gate: 9/14 qualifying days · indexable

Hysteria2

UDP/QUIC

61 verified configurations1428 stored configurationsIndexing gate passed

Hysteria2 requires UDP reachability and valid TLS parameters; a TCP port probe cannot verify it.

Gate: 9/14 qualifying days · indexable

TUIC

UDP/QUIC

0 verified configurations122 stored configurationsIndexing paused

TUIC requires a complete UUID/password pair and UDP-capable checking; incomplete metadata is never listed as working.

Gate: 0/14 qualifying days · zero usable rows seven days

Data gate and measurement units

A protocol catalog can be indexed only after it has at least 10 unique verified endpoints from 3 independent sources on 7 days within the last 14. Seven consecutive zero-result days force noindex,follow and sitemap removal; a documented outage can retain eligibility for at most 72 hours.

Endpoint counts, configuration counts and stored quarantine records are shown separately. Handshake and HTTPS first-byte values are milliseconds measured by checker infrastructure. Survival is a percentage over the stated window and is not shown until enough history exists.