Skip to main content

VPN Protocols We Support

Twelve protocols across all NexTunnel servers — pick the one that beats your network's restrictions or wins the speed test.

CensorshipStreamingClassic VPN apps

DPI bypass at a glance

How each protocol fares against the real DPI stacks deployed by these governments.

ProtocolChinaRussiaIranUAE
OpenVPN
WireGuard
VLESS Reality
Hysteria2

✓ works · ⚠ unstable · ✕ blocked. Based on field reports from our user base; results vary by ISP and time of day.

VLESS Reality

Our flagship protocol. Mimics a real TLS handshake with a target site so DPI cannot tell it apart from normal HTTPS traffic.

Censorship
Port
TCP/443
Censorship resistance
●●●●●

Best for: Heavy censorship (Russia, Iran, China). Most users should start here.

VLESS Reality (Restricted)

Same Reality cipher on alternate ports and SNI for networks that block port 443 or our default SNI fingerprint.

Censorship
Port
TCP/2087, 8443
Censorship resistance
●●●●●

Best for: Corporate firewalls and stricter ISPs that block the standard profile.

VLESS WS+TLS+CDN

VLESS over WebSocket fronted by Cloudflare. Traffic is indistinguishable from any other Cloudflare-hosted site.

Censorship
Port
TCP/443 (CDN)
Censorship resistance
●●●●●

Best for: Networks that block direct TLS but allow Cloudflare. Maximum censorship resistance.

Hysteria2

QUIC-based UDP transport with BBR congestion control. The fastest option when UDP is allowed.

Streaming
Port
UDP/8443
Censorship resistance
●●●●○

Best for: Streaming, gaming, and any high-bandwidth workload over good networks.

Trojan

Pure TLS 1.3 with a password-only authentication layer. Indistinguishable from a regular HTTPS website.

Censorship
Port
TCP/443
Censorship resistance
●●●●○

Best for: Networks where Reality is detected but plain TLS is allowed.

TUIC v5

Modern QUIC-based protocol with multiplexing and 0-RTT handshakes. Fast even on lossy or high-latency networks.

Streaming
Port
UDP/varies
Censorship resistance
●●●●○

Best for: Mobile networks, satellite links, and unstable Wi-Fi.

ShadowTLS + Mieru

ShadowTLS wraps Mieru in a real TLS 1.3 handshake. Strong against active probing and TLS fingerprinting.

Censorship
Port
TCP/varies
Censorship resistance
●●●●●

Best for: Active-probe DPI environments where Reality is detected.

Shadowsocks 2022

Battle-tested SOCKS5-style proxy with the new 2022-blake3-aes-256-gcm cipher and randomized ports.

Censorship
Port
TCP/UDP 10000-20000
Censorship resistance
●●●●○

Best for: China (GFW) and as a reliable fallback when newer protocols fail.

WireGuard

Modern kernel-grade VPN with Curve25519 + ChaCha20-Poly1305. The fastest classic VPN protocol.

Classic VPN appsStreaming
Port
UDP/51820
Censorship resistance
●●○○○

Best for: Open networks where pure speed and battery life matter most.

AmneziaWG

WireGuard fork that injects junk packets to defeat DPI fingerprinting. Works where vanilla WireGuard is blocked.

CensorshipClassic VPN apps
Port
UDP/51821
Censorship resistance
●●●●●

Best for: Russia (TSPU), Iran, and any network that DPI-blocks vanilla WireGuard.

OpenVPN

Industry-standard VPN with broad client support across every platform and router.

Classic VPN apps
Port
UDP/1194
Censorship resistance
●●○○○

Best for: Legacy clients, routers, and corporate compatibility requirements.

IKEv2 / IPsec

Native VPN built into iOS, macOS, and Windows. Survives network changes (Wi-Fi to LTE) without dropping.

Classic VPN apps
Port
UDP/500, 4500
Censorship resistance
●●○○○

Best for: Mobile devices that want zero-app-install native VPN integration.

Ready to pick yours?

Every plan includes every protocol. Switch any time from your dashboard.

View pricing