白嫖Hysteria2的硬核避雷指南:这三招开错等于白给 | Hysteria2 Tuning: 3 Tricks That Might Get You Blocked If You Use Wrong
很多人搭Hysteria2的第一反应,就是把所有隐蔽功能全拉满——混淆、端口跳、伪装全开,觉得叠的buff越多越安全。这逻辑就像你去商圈逛街,为了不被保安盯上,套了三件外套戴了两层口罩,结果保安第一眼就锁定你:这人鬼鬼祟祟,指定不对劲。真正的隐身高手,都是穿得和路人一模一样,悄咪咪就混过去了。
Many people’s first instinct when setting up Hysteria2 is to crank every stealth feature to max — obfuscation, port hopping, masquerade all on, thinking more layers equal better safety. That’s like walking through a mall in three coats and two face masks to avoid security attention. Guess who the guard notices first? The guy who looks obviously out of place. Real stealth masters dress just like everyone else and slip right in without a second glance.
今天就把Hysteria2的三大隐身术拆明白:各自对付什么场景、什么时候该开、开错了会有什么反效果。这仨不是叠加的增益,是三套不同的皮肤,穿错了反而直接社死。
Today we’re breaking down Hysteria2’s three stealth tricks: what each one fights, when to use it, and when it backfires. They aren’t stackable buffs — they’re three separate disguises. Wear the wrong one and you’ll stick out like a sore thumb.
先说域名伪装(masquerade),这是你的“日常通勤装”。Hysteria2本身就长着一张标准HTTP/3的脸,伪装再给它配上真实网站的内容,别人扫端口过来一看,就是个正儿八经的网站,挑不出一点毛病。这招零副作用,默认就该开,就像你出门总得穿件正常衣服。
First up is masquerade — your everyday casual outfit. Hysteria2 already looks like standard HTTP/3 traffic by default; masquerade adds real website content on top, so any port scan sees a perfectly normal web server with nothing to hide. Zero downsides, always turn it on — just like you’d wear regular clothes going outside.
然后是obfs混淆(Salamander),这是你的“夜行衣”。只有当对方已经盯上了所有HTTP/3流量、见QUIC就掐的时候,你才需要把数据包搅成随机字节的样子混过去。平时穿夜行衣上街,不是明摆着告诉别人你心里有鬼吗?
Next is Salamander obfuscation — your black night suit. You only pull this out when the network is actively targeting and blocking all QUIC/HTTP3 traffic, and you need to scramble every packet into random unrecognizable bytes. Walking around in a night suit on a normal day is basically screaming “I’m hiding something” to every observer.
最后是端口跳跃,这是你的“走位身法”。对付的是那种“单端口流量大就限速”的懒政QoS,你不停换端口连,它就抓不住你哪条是主力流量。要是线路本来就不限速,你跳来跳去纯纯浪费体力。
Last is port hopping — your footwork to dodge traffic cops. It works great against lazy QoS that throttles heavy single-port traffic. If you keep switching ports, the system can’t pin down your main flow and slow you down. If your line isn’t throttled in the first place, hopping around is just wasted effort.
这里有个最关键的取舍:开了obfs之后,你的流量就不再是合法的QUIC了,等于主动放弃了“我是正常网站”的身份。所以默认策略永远是:伪装拉满,obfs先关,真被封了再掏出来。就像平时好好走路没人管你,真被追了再跑。
Here’s the critical tradeoff: once you enable obfuscation, your traffic is no longer valid QUIC — you give up the entire “I’m a normal website” cover identity. The default strategy should always be: full masquerade, obfs off. Only break out the obfuscation when you actually get blocked. It’s just like walking normally in public — you only run when someone’s actually chasing you.
### 一、服务端配置(官方二进制最稳)
### 1. Server Configuration (Official Binary = Most Reliable)
这三项高级功能用官方Hysteria2二进制配置最可控,3X-UI面板里的Xray内核版本对端口跳跃和完整伪装支持有限。配置文件默认路径为 `/etc/hysteria/config.yaml`:
These three advanced features are most controllable with the official Hysteria2 binary. The Xray-core implementation in 3X-UI has limited support for full port hopping and complete masquerade. Default config file path: `/etc/hysteria/config.yaml`
```yaml
listen: :443 # QUIC 监听 UDP/443
tls: # 有域名推荐用 ACME 自动签证书
acme:
domains:
- your.domain.net
email: you@example.com
# 没域名就用自签证书 + 客户端 insecure,见下
auth:
type: password
password: <连接密码_设强一点>
obfs: # 仅当 QUIC 被针对性封锁时才启用
type: salamander
salamander:
password: <混淆密码_两端必须一致>
masquerade: # 域名伪装:反代一个真实网站
type: proxy
proxy:
url: https://news.ycombinator.com/
rewriteHost: true
listenHTTP: :80 # 顺带在 TCP 80/443 也扮成网站
listenHTTPS: :443
forceHTTPS: true
```
伪装模式一共有三种:file(静态文件服务器)、proxy(反向代理其他网站)、string(永远返回固定内容)。其中proxy模式最像真实网站,目标URL选一个和你VPS无关、访问正常的普通站点即可。
There are three masquerade modes: file (static file server), proxy (reverse proxy another site), string (always return fixed content). Proxy mode looks the most authentic — just pick a normal, unrelated website as the target URL.
### 二、端口跳跃:防火墙端口重定向
### 2. Port Hopping: Firewall Port Redirection
客户端在一段端口范围里不停换端口连接,服务端就要把整段UDP端口全部重定向到真正监听的443端口。推荐使用nftables,记得把`eth0`换成你服务器的真实网卡名:
For the client to hop across a port range, the server needs to redirect the entire UDP port range to the actual listening port 443. nftables is recommended; replace `eth0` with your actual network interface name:
```bash
# 把 eth0 换成你的真实网卡名
nft add table inet hysteria
nft add chain inet hysteria prerouting '{ type nat hook prerouting priority dstnat; }'
nft add rule inet hysteria prerouting iif "eth0" udp dport 20000-50000 counter redirect to :443
```
如果你更习惯用iptables,IPv4和IPv6都要单独添加规则:
If you prefer iptables, add separate rules for both IPv4 and IPv6:
```bash
iptables -t nat -A PREROUTING -i eth0 -p udp --dport 20000:50000 -j REDIRECT --to-ports 443
ip6tables -t nat -A PREROUTING -i eth0 -p udp --dport 20000:50000 -j REDIRECT --to-ports 443
```
划重点:云厂商安全组和服务器内部防火墙,都要放行整段 **UDP 20000-50000**。新版Hysteria2支持原生监听端口范围并自动配置防火墙,可用`HYSTERIA_FIREWALL_BACKEND`指定iptables或nftables后端;老版本nftables曾有兼容问题,建议服务端客户端都升级到最新版。
Important: Open the full UDP range **20000-50000** in both your cloud security group and server firewall. Newer Hysteria2 versions support native port range listening and automatic firewall setup via the `HYSTERIA_FIREWALL_BACKEND` variable (choose iptables or nftables). Older versions had nftables compatibility issues, so upgrade both server and client to the latest release.
### 三、客户端配置
### 3. Client Configuration
#### A. 官方Hysteria客户端(YAML格式)
#### A. Official Hysteria Client (YAML Format)
在server地址后直接写端口范围,就会自动开启端口跳跃。跳跃间隔可以设固定值,也可以设随机区间,二者二选一;都不填的话默认固定30秒。
Adding a port range after the server address automatically enables port hopping. You can set a fixed hop interval or a random range — pick one, not both. Default is 30 seconds if left unset.
```yaml
server: your.domain.net:20000-50000 # 端口范围 = 触发端口跳跃
auth: <连接密码>
obfs:
type: salamander
salamander:
password: <混淆密码_两端一致>
tls:
sni: your.domain.net # 没域名时填你的伪装网址
insecure: false # 自签证书才改 true
hopInterval: 30s # 或用 minHopInterval/maxHopInterval 随机跳
socks5:
listen: 127.0.0.1:1080
http:
listen: 127.0.0.1:8080
```
#### B. Karing / sing-box 客户端(JSON出站配置)
#### B. Karing / sing-box Client (JSON Outbound)
Karing底层是sing-box内核,手动编辑配置使用这个格式。注意两个常见坑:端口范围用冒号写法放在`server_ports`数组里;带宽参数是纯数字Mbps,不能带单位字符串。
Karing runs on the sing-box kernel, use this format for manual config. Two common pitfalls: port range uses colon syntax in the `server_ports` array; bandwidth values are plain integers in Mbps — no unit strings allowed.
```json
{
"type": "hysteria2",
"tag": "hy2-out",
"server": "your.domain.net",
"server_port": 443,
"server_ports": ["20000:50000"],
"hop_interval": "30s",
"password": "<连接密码>",
"obfs": { "type": "salamander", "password": "<混淆密码_两端一致>" },
"up_mbps": 50,
"down_mbps": 200,
"tls": { "enabled": true, "server_name": "your.domain.net" }
}
```
#### C. 一键分享链接(扫码导入)
#### C. Share URI (Scan to Import)
URI格式原生支持多端口和obfs参数,生成后直接扫码就能导入客户端,不用手动填写一堆配置。
The URI format natively supports multi-port and obfuscation parameters. Generate once and scan to import — no tedious manual config needed.
```
hysteria2://<连接密码>@your.domain.net:443,20000-50000/?obfs=salamander&obfs-password=<混淆密码>&sni=your.domain.net#MyNode
```
### 四、最容易踩的五个坑
### 4. Top 5 Most Common Pitfalls
1. **两端密码必须完全一致**:obfs密码填错的表现就是连接超时,和服务器没开一模一样,连不上先查这个。
2. **obfs别乱开**:网络还允许QUIC的时候开obfs,等于主动扔掉HTTP/3伪装,得不偿失。先默认关闭测速,真被限速/封锁了再开启。
3. **端口跳跃只作用于UDP**:安全组和防火墙的UDP端口段一定要放行,TCP开了完全没用。
4. **SNI要和证书/伪装域名匹配**:新版服务端默认SNI与证书不匹配时直接断开握手,别随便乱填。
5. **版本统一升最新**:2.8.2之后QUIC握手参数有变更,新旧版本混用可能导致UDP转发失效(TCP不受影响),官方强烈建议两端一起升级。
1. **Passwords must match exactly on both ends**: A wrong obfs password causes connection timeouts that look identical to the server being offline. Check this first if you can’t connect.
2. **Don’t enable obfs by default**: If QUIC is still allowed on your network, turning on obfs throws away your HTTP/3 cover for no gain. Test with it off first, only enable it if you get throttled or blocked.
3. **Port hopping only works on UDP**: Make sure your security group and firewall open the UDP port range — TCP rules do nothing here.
4. **SNI must match your certificate / masquerade domain**: Newer server builds drop the handshake immediately if SNI doesn’t match. Don’t put random values here.
5. **Upgrade both sides to the latest version**: QUIC handshake parameters changed after v2.8.2. Mixing old and new versions can break UDP forwarding (TCP still works). Official recommendation is to upgrade server and client together.
### 附:整条链路一图看懂
### Appendix: Full Link Architecture
从你的设备发出Hysteria2流量,带着端口跳跃和可选混淆,打到Oracle免费VPS上的服务端,对外伪装成正常网站;普通流量直接从VPS出口出去,OpenAI这类站点走WARP第二跳换干净IP,完美兼顾速度和可用性。
Your device sends Hysteria2 traffic with port hopping (and optional obfuscation) to the server on your free Oracle VPS, which masquerades as a normal website to outsiders. Regular traffic exits directly from the VPS IP, while sites like OpenAI route through a second WARP hop for a clean IP — the perfect balance of speed and reliability.
```
[你的设备 Karing(sing-box)]
│ Hysteria2 (QUIC/UDP, 端口跳跃 20000-50000, obfs 可选)
▼
[Oracle 免费 VPS: 3X-UI + Hysteria2 入站, masquerade 伪装成正经网站]
├─ 默认出站 ──────────────► 直接从 VPS IP 出网(YouTube 等)
└─ 路由: openai/chatgpt ──► WARP 出站(干净 IP, GPT 不降智)=免费"第二跳/链式"
```
相关链接(Related Links):
https://github.com/MHSanaei/3x-ui
https://github.com/apernet/hysteria
https://v2.hysteria.network
https://github.com/SagerNet/sing-box
https://github.com/KaringX/karing
https://www.oracle.com/cloud/free/
https://developers.cloudflare.com/warp-client/
评论
发表评论