Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

🛡️ vpn-proxy-stack

📦 Overview

vpn-proxy-stack is a comprehensive Docker-based VPN and proxy solution integrating:

  • 🔒 OpenConnect VPN server (ocserv) with camouflage support
  • 🛠️ 3x-ui panel for proxy management (Reality proxy)
  • 🌐 Nginx acting as a TLS SNI multiplexer and reverse proxy
  • 🔐 acme.sh for automated Let's Encrypt certificate management

After setup, you get a fully functional VPN and proxy stack with ease of deployment, management UI, and automatic TLS certificate handling.


🚀 Getting Started

Clone the repository

git clone https://github.com/gifi71/vpn-proxy-stack.git /opt/vpn-proxy-stack
cd /opt/vpn-proxy-stack

Install Docker

If Docker is not installed yet, install it via the official script:

curl -sSL https://get.docker.com | sh

Configure environment variables

Edit the .env file with your settings. Below is a description of variables and an example:

VariableDescriptionExample
DEFAULT_HTTPSDefault path for HTTPS traffic fallbackdefault.example.com
DEFAULT_HTTPDefault path for HTTP traffic fallbackdefault.example.com
CAMOUFLAGE_SECRETSecret string used for ocserv camouflagesecret
OCERV_DOMAINDomain name used for OpenConnect VPNvpn.example.com
REALITY_DOMAINDomain name used for Reality proxyreality.example.com
PORTS🔧 (Optional) Firewall port mappings (<container_port>:<client_ip>:<client_port> ...)Not set
EXPORTER_ENABLED📊 (Optional) Enable ocserv-exporter (1 = enable, 0 = disable)0
EXPORTER_INTERVAL⏱️ (Optional) Interval for ocserv-exporter scrape requests30s
EXPORTER_BIND📡 (Optional) IP and port where ocserv-exporter listens0.0.0.0:8000

💡 Note: ocserv-exporter metrics by default are only available inside the ocserv container.


⚙️ Generate configuration files

./gen_conf.sh

🧾 (Optional) Customize OpenConnect server configuration

  • Main config: volumes/ocserv/ocserv.conf
  • Per-user configs: put files in volumes/ocserv/config-per-user/

Example per-user config:

# Assign static IP to userexplicit-ipv4 = 10.10.0.50
# Route all client traffic through VPNroute = default

Or:

explicit-ipv4 = 10.10.0.100
route = 10.0.1.0/24
# Optional - notify server that client handles this subnet# iroute = 10.0.1.0/24

🐳 Start the stack with Docker Compose

docker compose up -d

🔏 Generate SSL certificates

./get_cert.sh

🔥 Configure firewall (optional)

Example UFW rules:

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable

🚀 Optimize Host Networking (optional)

To improve TCP performance, especially when using TCP VPN connections, you can enable the following settings by editing /etc/sysctl.conf:

net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr

Apply the changes with:

sysctl -p

These settings optimize packet scheduling and enable the BBR TCP congestion control algorithm, which can significantly enhance TCP throughput and reduce latency. This optimization is particularly useful if your VPN clients mainly use TCP connections.


👥 Add OpenConnect VPN users

docker exec -it ocserv bash
/opt/ocserv/bin/ocpasswd -c /etc/ocserv/ocpasswd <user>

🌍 Connecting to OpenConnect VPN

  • Linux:
sudo openconnect "https://<OCERV_DOMAIN>/?<CAMOUFLAGE_SECRET>"
  • Windows & Android: Use Cisco AnyConnect VPN client.

💻 Accessing 3x-ui Web Interface

Create SSH tunnel:

ssh -L 2053:localhost:2053 <your_user>@<your_server_ip>

Then open in browser:

http://localhost:2053

🔮 Creating a Reality Proxy and Users in 3x-ui

  • Use TCP protocol on port 443

  • Enable Proxy Protocol

  • Set:

    Destination: <REALITY_DOMAIN>:443
    SNI: <REALITY_DOMAIN>
    Flow: xtls-rprx-vision
    

📲 Connecting to Reality Proxy

  • Linux & Windows: Hiddify or NekoBox
  • Android: husi or NekoBox
  • iOS: FoXray

📄 License

This project is licensed under the GPLv3 License.

About

A comprehensive Docker-based VPN and proxy solution integrating

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages