VPN INFRASTRUCTURE

Deployment Guide — Entry + Chain Architecture

Entry Server (RU)
Chain Servers
Protocols
Bridges
AmneziaWG 2.0 + CPS (TLS 1.3 Mimicry)
Clients
AWG 2.0
UDP, CPS I1-I5
tun2socks
tun0 → SOCKS5
SOCKS5
127.0.0.1:10808
Xray
entry server
Routing
domain → chain
Chain
VLESS+Reality+XHTTP
VLESS + Reality + XHTTP (Direct Client)
Clients
VLESS+Reality+XHTTP
TCP, TLS fingerprint
——→
Xray
entry server
Routing
domain → chain
Chain
VLESS+Reality+XHTTP
MTProxy for Telegram (mtg)
Telegram
mtg
FakeTLS, port 3128
SOCKS5
127.0.0.1:10808
Xray
entry server
Routing
domain → chain
Chain
VLESS+Reality+XHTTP
Routing Decision (Xray on Entry)
Incoming Traffic
domainStrategy:
IPIfNonMatch
RU domains/IPs → direct
Foreign → balancer (leastPing)
entry — RU server  |  chain — exit VPS  |  SOCKS5 bridges AWG & mtg into Xray routing
Guide