This repository contains the optimal configurations for Xray and the Remnawave panel, providing you with a starting point for deploying various protocols securely and effectively.
In Remnawave, these configurations should be used to create Config Profiles. To use a configuration:
- Navigate to the Config Profiles section in your Remnawave panel.
- Create a new profile or edit an existing one.
- Paste the contents of the desired
.jsonfile from this repository into the configuration editor. - Important: Remember to replace any placeholder values (like
USE OWN VALUE!,private key,/path/to/cert.crt) with your actual environment variables or generated keys before saving. - Apply the profile to your nodes and assign users to the appropriate internal squads.
Demonstrates how to group multiple outbound connections into a load balancer using the Remnawave injectHosts directive and monitor health using burstObservatory.
Usage: Use this when you have multiple upstream servers and want the panel to automatically inject them into your routing strategy based on latency.
The Bridge Profile acts as the destination server in a multi-server routing setup. Usage: Deploy this profile on the target/backend server (e.g., DE-001) that will receive traffic forwarded from your entry server.
The Public Profile acts as the entry node. It routes traffic based on rules (e.g., direct for specific regions) and sends all other traffic over a Shadowsocks outbound to the bridge node.
Usage: Deploy this on the server users connect to directly (e.g., RU-001).
Note: You must replace ADDRESS OF DE-001, ПАРОЛЬ С ПРОШЛОГО ШАГА, USE OWN VALUE!, USE OWN KEY!, and REPLACE WITH OWN VALUES! with your actual values before deploying this configuration.
The optimal VLESS TCP REALITY configuration, incorporating specific routing and blocking rules. Usage: A robust, standard configuration utilizing REALITY to disguise traffic as connections to an allowed site (e.g., github.com). Excellent for bypassing deep packet inspection.
The optimal VLESS gRPC REALITY configuration, maintaining standard routing and blocking rules. Usage: Uses gRPC multiplexing. Suitable for situations where TCP traffic might be throttled or when placing Xray behind a proxy/CDN that supports gRPC.
The optimal VLESS XHTTP REALITY configuration. Usage: Utilizes the experimental xhttp transport for advanced obfuscation techniques.
The optimal VLESS WebSocket configuration utilizing standard TLS.
Usage: The classic choice for putting Xray behind a Content Delivery Network (CDN) like Cloudflare. The wsSettings.path should be customized for your setup.
The optimal Trojan WebSocket TLS configuration. Usage: Similar to VLESS WS, this is ideal for passing traffic through a CDN, utilizing the Trojan protocol. Ensure you point the certificates to valid paths on your server.
References:
The optimal Trojan TCP TLS configuration with a fallback mechanism. Usage: When someone (or a firewall probe) connects to your server on port 443 without the correct Trojan password, they are seamlessly forwarded to the fallback port (e.g., a fake web server or external site like 1.1.1.1). Extremely effective against active probing.
The optimal Shadowsocks-2022 configuration (2022-blake3-aes-128-gcm).
Usage: Shadowsocks-2022 offers significant performance and security improvements over legacy Shadowsocks. Excellent for bypassing restrictive networks where TLS obfuscation is heavily scrutinized or blocked entirely, as SS-2022 looks like pure random UDP/TCP noise.
Why is there no Hysteria 2.0 configuration? Xray-core (which Remnawave is built on top of) does not natively support Hysteria 2 as an inbound protocol. While Hysteria 2 is excellent, it requires a different core engine (like Sing-Box or the standalone Hysteria binaries) to run. Therefore, it is impossible to configure Hysteria 2 natively through Xray JSON in this panel.