Step-by-step setup walkthroughs, one per transport. Each page is a complete session — every question the wizard asks, in the order it asks it, with the answer to give and the reason for it. Pick the transport you want and follow that page top to bottom.
New here? Read Before you start once. It covers the two roles, the token, the ports and the firewall — the four things that account for nearly every "the tunnel is up but nothing works" report. Every other page assumes it.
Every page below sets up a reverse tunnel: kharej dials Iran. If that will not come up — the provider filters inbound connections, or the tunnel port is blocked one way — turn it round.
| Tutorial | Use it when | Needs |
|---|---|---|
| Direct tunnel | the reverse tunnel will not connect; Iran dials out instead | Linux, root, a port open on kharej |
| Direct, stream transports | you already run a [direct] tunnel — the wizard no longer builds these |
a port open on kharej |
| Tutorial | Use it when | Needs |
|---|---|---|
| TCP | you are not sure — this is the starting point | — |
| TCP Mux | the service opens many short connections (panels, web) | — |
| TCP + Stealth | the link is DPI-filtered and plain TCP dies | — |
| TCP + PCK | TCP connects then stalls, resets or is throttled | Linux, root |
| UDP | you are forwarding one UDP service and want no layer on top | UDP open |
| UDP + KCP + FEC | gaming, or a lossy route where TCP keeps backing off | UDP open |
| UDP + QUIC | you want to test an encrypted, self-tuning UDP carrier | UDP open |
| WS / WS Mux | only HTTP gets through, or you want a CDN in front | — |
| WSS / WSS Mux | you want the tunnel to look like an ordinary HTTPS site | domain (for a real cert) |
| xDi (ICMP) | TCP and UDP are both filtered but ping works | Linux, root |
| IP Spoofing | the path blocks or counts by source address | Linux, root |
- Adding UDP to a tunnel — Xray/3x-ui UDP, WireGuard, DNS and games need one switch turned on. This is the page for "TCP works, UDP does not".
- Behind a panel (X-UI / 3x-ui / Marzban) — the port mapping, the real client IP, and what to set inside the panel.
Reference material — what each setting is, rather than how to set one up —
lives in docs/. The CLI menu reference
documents every option in every menu, including the advanced ones these
tutorials leave at their defaults.
این پوشه آموزشهای قدمبهقدم راهاندازی است — برای هر ترنسپورت یک صفحه، و در هر صفحه دقیقاً همان سؤالهایی که ویزارد میپرسد، به همان ترتیب، با جوابی که باید بدهی و دلیلش.
اگر تازه شروع کردهای، اول Before you start را بخوان. دو نقش (سرور ایران / کلاینت خارج)، توکن، پورتها و فایروال آنجا توضیح داده شده — همان چهار چیزی که تقریباً همهٔ «تونل بالاست ولی کار نمیکند»ها از آنها میآید.
اگر نمیدانی کدام ترنسپورت را بگیری، از TCP شروع کن؛ برای فیلترینگ سنگین TCP + Stealth و برای بازی و مسیر پرافت UDP + KCP + FEC.
اگر TCP کار میکند ولی UDP رد نمیشود (Xray/3x-ui، وایرگارد، DNS، بازی) صفحهٔ Adding UDP to a tunnel را ببین — فقط یک گزینه باید روشن شود.
توضیح تکتک تنظیمات (نه آموزش راهاندازی) در پوشهٔ docs/ است.