Surok

VLESS, Reality and XHTTP in plain words: why they work where WireGuard goes silent

What VLESS, Reality and XHTTP are without jargon, how they differ from OpenVPN and WireGuard, and what to check when "VLESS doesn't work" on your carrier.

·3 min read·133 viewsBasicsBlocking

VPN descriptions mention VLESS, Reality, XHTTP, and it's hard to tell what they are and why they matter. Here is the plain-language version, and at the end what to do when "VLESS doesn't work".

Why the old protocols became visible

OpenVPN, IKEv2 and WireGuard were designed to protect data, not to hide. Their traffic is encrypted, but the packet shapes and the handshake order show it is a VPN. Equipment at the ISP border recognises the shape and drops the connection. The encryption isn't broken; the mere fact "this is a VPN" is enough to block.

VLESS: transport without extras

VLESS is a way to pack your traffic into a tunnel with minimal overhead. By itself it neither hides nor encrypts, so it always works together with something "on top". Think of it as a container: what matters is the wrapping around it.

Reality: pretend to be someone else's site

Reality is a wrapping that makes the connection indistinguishable from an ordinary visit to a well-known site. When your phone connects to our server, from outside it looks like an HTTPS session with, say, a major search engine: same certificates, same handshake steps. The difference is one hidden key that only our client knows. If someone without the key connects, for example a probing robot from the ISP, the server honestly passes them on to the real site. The robot sees the real site and leaves. That is why Reality is so hard to kill: to block it you would have to block the site it hides behind.

XHTTP: when everything but websites is cut

Some carriers, mobile ones especially, run whitelists: only what looks like loading ordinary pages and images passes. XHTTP splits the tunnel into a series of ordinary HTTP requests, each looking like a file download from a website. It can even go through a CDN, and then the carrier sees a connection not to our server but to a large content delivery network that is too costly to block. At Surok this is the "Europe · auto" profile.

Which one to pick

You don't have to: the subscription has all three, and the app cycles through them itself. For understanding: Reality is faster and lighter, XHTTP via CDN passes where Reality is blocked. If everything works, leave it alone.

"VLESS doesn't work": what to check

  1. Refresh the subscription. Reality keys and addresses change; an old config stops matching.
  2. Switch the profile. Reality on 443 fails, try XHTTP or the CDN profile. Fails on mobile but works on Wi-Fi: that's whitelisting, use the CDN profile.
  3. Turn off the other VPN. A second tunnel won't start on a phone.
  4. Check the device clock. Reality compares time with the server; a few minutes' difference breaks the handshake. Enable automatic time.
  5. Update the app. Old clients don't know XHTTP. Recent Happ, v2RayTun, Streisand and Hiddify support everything.
  6. Look at the server itself. If the service gives one address and one port, you have nothing to switch to, and that is the service's problem, not the protocol's.

In short

VLESS packs, Reality hides behind someone else's site, XHTTP pretends to be ordinary requests and passes through CDNs. Together they close almost every blocking method currently in use. What they don't close, the ability to switch profiles does, and for that there must be several profiles.

Try Surok
3 days free, no card needed. Apps for everything.

More to read