Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    X-ray VPN implementation in future releases of pfSense+

    Scheduled Pinned Locked Moved Development
    17 Posts 7 Posters 3.2k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • С Offline
      Сергей 3
      last edited by

      In some countries, this package is absolutely necessary in pfsense.
      I found these instructions
      But the topic has stalled there. Is there any way to adapt these instructions for pfsense?
      Or could someone explain to the newbies where all these IP addresses come from?

      stephenw10S 1 Reply Last reply Reply Quote 0
      • E Offline
        elvisimprsntr
        last edited by elvisimprsntr

        I stay away from any of the so called "privacy" VPNs, especially those promoted by YouTube shills.

        "If you are not paying for the product, you are the product."

        Youtube Video

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator @Сергей 3
          last edited by

          @Сергей-3 said in X-ray VPN implementation in future releases of pfSense+:

          In some countries, this package is absolutely necessary in pfsense.

          I still don't see how this is any better than any other existing VPN provider?

          С 1 Reply Last reply Reply Quote 3
          • С Offline
            Сергей 3 @stephenw10
            last edited by

            @stephenw10
            You're lucky you don't live in such a country.
            Other VPN providers (protocols) are blocked.

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Hmm, so the novel protocol used here bypasses state-level filtering?

              С 1 Reply Last reply Reply Quote 0
              • С Offline
                Сергей 3 @stephenw10
                last edited by

                @stephenw10
                Xray is a Chinese development that bypasses the Great Firewall of China.
                I'm not very knowledgeable about networking and would like some tips for setting up Xray in pfSense.
                It would be better if pfSense had its own xray package.
                Could anyone get the pfSense developers involved in this?

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG Offline
                  Gertjan @Сергей 3
                  last edited by Gertjan

                  @Сергей-3 said in X-ray VPN implementation in future releases of pfSense+:

                  Could anyone get the pfSense developers involved in this?

                  Wouldn't that be a temporary solution ?

                  I you were working for this company (?) that was mandated by gouvernement of the country you mentioned above, what would be your mission ?
                  With simple words : Blocking outgoing traffic.
                  You wouldn't want this government's big boss X... calling you and telling you you did a bad job as he just found out how to bypass your "Great Firewall" - he knows, as he could find it on the Internet ... we're talking about it right now.
                  The issue with open source is : it is visible to everyone. So, get it integrated, and it will work for a while. And then suddenly, the Great Firewall maintainers block whatever X-Ray is. After all, it's a protocol, so it can be blocked, the usefulness is gone. It becomes yet another type of VPN, like OpenVPN, Wireguard, IPSEC, etc etc. that needs to be supported by the authors of pfSense, Netgate.

                  And as always, I hope to be wrong 😊

                  Btw : the oSense already has it ... did you give it a try ? ( it's probably just for some short time anyway )

                  edit : I'm just a forum poster like you - this is what I think, based of what I've read, and what think I know.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  С 1 Reply Last reply Reply Quote 0
                  • С Offline
                    Сергей 3 @Gertjan
                    last edited by

                    @Gertjan, Xray disguises traffic as regular HTTPS connections, making it difficult to block.
                    I provided a link to an implementation of Xray in oSense, but the thread stopped responding to questions. I'm asking knowledgeable people to adapt that instruction for pfSense.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      I would first try to make it work in FreeBSD where the package exists.

                      С 1 Reply Last reply Reply Quote 0
                      • С Offline
                        Сергей 3 @stephenw10
                        last edited by

                        @stephenw10
                        Here are the packages that work on FreeBSD
                        Xray
                        Tun2socks
                        But I don't have the knowledge to configure it manually.
                        I wish there was a standard package for pfSence.

                        1 Reply Last reply Reply Quote 0
                        • E Offline
                          elvisimprsntr
                          last edited by elvisimprsntr

                          Is it just me, or does it seem like the KISS (Keep It Simple [redacted]) answer is to install X-Ray on an officially supported platform or a VPS and tunnel traffic through that?

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.