Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    X-ray VPN implementation in future releases of pfSense+

    Scheduled Pinned Locked Moved Development
    15 Posts 7 Posters 3.1k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • w0wW Offline
      w0w @patient0
      last edited by

      @patient0
      https://github.com/XTLS/Xray-core

      patient0P 1 Reply Last reply Reply Quote 1
      • patient0P Offline
        patient0 @w0w
        last edited by

        @w0w I found that too, yes. But that's not X-ray VPN, right?

        w0wW 1 Reply Last reply Reply Quote 0
        • w0wW Offline
          w0w @patient0
          last edited by w0w

          @patient0 said in X-ray VPN implementation in future releases of pfSense+:

          But that's not X-ray VPN

          Some kind of analog, not as a paid service, but as functional client-service software.
          I think it's about this one, not the one you've mentioned.

          1 Reply Last reply Reply Quote 1
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            Hmm, it does seem kinda shady!

            There's no FreeBSD port as far as I can see, though there is one for v2ray which this was forked from.

            You are asking about adding it as a client to connect to the xrayvpn service only?

            I'm not really seeing any advantages over existing VPN options TBH.

            1 Reply Last reply Reply Quote 3
            • С Offline
              Сергей 3
              last edited by

              In some countries, this package is absolutely necessary in pfsense.
              I found these instructions
              But the topic has stalled there. Is there any way to adapt these instructions for pfsense?
              Or could someone explain to the newbies where all these IP addresses come from?

              stephenw10S 1 Reply Last reply Reply Quote 0
              • E Offline
                elvisimprsntr
                last edited by elvisimprsntr

                I stay away from any of the so called "privacy" VPNs, especially those promoted by YouTube shills.

                "If you are not paying for the product, you are the product."

                Youtube Video

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator @Сергей 3
                  last edited by

                  @Сергей-3 said in X-ray VPN implementation in future releases of pfSense+:

                  In some countries, this package is absolutely necessary in pfsense.

                  I still don't see how this is any better than any other existing VPN provider?

                  С 1 Reply Last reply Reply Quote 3
                  • С Offline
                    Сергей 3 @stephenw10
                    last edited by

                    @stephenw10
                    You're lucky you don't live in such a country.
                    Other VPN providers (protocols) are blocked.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      Hmm, so the novel protocol used here bypasses state-level filtering?

                      С 1 Reply Last reply Reply Quote 0
                      • С Offline
                        Сергей 3 @stephenw10
                        last edited by

                        @stephenw10
                        Xray is a Chinese development that bypasses the Great Firewall of China.
                        I'm not very knowledgeable about networking and would like some tips for setting up Xray in pfSense.
                        It would be better if pfSense had its own xray package.
                        Could anyone get the pfSense developers involved in this?

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG Offline
                          Gertjan @Сергей 3
                          last edited by Gertjan

                          @Сергей-3 said in X-ray VPN implementation in future releases of pfSense+:

                          Could anyone get the pfSense developers involved in this?

                          Wouldn't that be a temporary solution ?

                          I you were working for this company (?) that was mandated by gouvernement of the country you mentioned above, what would be your mission ?
                          With simple words : Blocking outgoing traffic.
                          You wouldn't want this government's big boss X... calling you and telling you you did a bad job as he just found out how to bypass your "Great Firewall" - he knows, as he could find it on the Internet ... we're talking about it right now.
                          The issue with open source is : it is visible to everyone. So, get it integrated, and it will work for a while. And then suddenly, the Great Firewall maintainers block whatever X-Ray is. After all, it's a protocol, so it can be blocked, the usefulness is gone. It becomes yet another type of VPN, like OpenVPN, Wireguard, IPSEC, etc etc. that needs to be supported by the authors of pfSense, Netgate.

                          And as always, I hope to be wrong 😊

                          Btw : the oSense already has it ... did you give it a try ? ( it's probably just for some short time anyway )

                          edit : I'm just a forum poster like you - this is what I think, based of what I've read, and what think I know.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          С 1 Reply Last reply Reply Quote 0
                          • С Offline
                            Сергей 3 @Gertjan
                            last edited by

                            @Gertjan, Xray disguises traffic as regular HTTPS connections, making it difficult to block.
                            I provided a link to an implementation of Xray in oSense, but the thread stopped responding to questions. I'm asking knowledgeable people to adapt that instruction for pfSense.

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S Offline
                              stephenw10 Netgate Administrator
                              last edited by

                              I would first try to make it work in FreeBSD where the package exists.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.