TUIC — VPN-протокол на базе QUIC. Аналог Hysteria2, быстрый, устойчив к потере пакетов. Маскируется под обычный QUIC-трафик.
# Скачать бинарник
wget https://github.com/daeuniverse/tuic/releases/latest/download/tuic-server-x86_64-linux-gnu
chmod +x tuic-server-x86_64-linux-gnu
sudo mv tuic-server-x86_64-linux-gnu /usr/local/bin/tuic-server
# UUID
cat /proc/sys/kernel/random/uuid
# Ключи (как в Reality — x25519)
tuic-server -gen-cert
Или использовать обычный пароль:
openssl rand -hex 16
sudo mkdir -p /etc/tuic
sudo nano /etc/tuic/config.json
{
"server": "0.0.0.0",
"port": 443,
"uuid": "ВАШ_UUID",
"password": "ВАШ_ПАРОЛЬ",
"cert": "/path/to/cert.pem",
"key": "/path/to/key.pem",
"congestion_control": "bbr",
"alpn": ["h3"],
"max_idle_time": 60,
"send_window": 16777216,
"receive_window": 8388608
}
certиkey— SSL-сертификат. Можно использовать Let's Encrypt или self-signed.
congestion_control:bbr(рекомендуется),cubic,new_reno.
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
-keyout /etc/tuic/key.pem -out /etc/tuic/cert.pem \
-subj "/CN=your-domain.com"
sudo nano /etc/systemd/system/tuic.service
[Unit]
Description=TUIC VPN Server
After=network.target
[Service]
Type=simple
ExecStart=/usr/local/bin/tuic-server -c /etc/tuic/config.json
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable tuic
sudo systemctl start tuic
sudo systemctl status tuic
sudo ufw allow 443/udp
⚠️ TUIC работает по UDP (QUIC), не TCP!
tuic://ВАШ_UUID:ВАШ_ПАРОЛЬ@SERVER_IP:443?congestion_control=bbr&alpn=h3&sni=your-domain.com&allow_insecure=1#TUIC
| Платформа | Клиент |
|---|---|
| Android | Hiddify, v2rayNG |
| iOS | Shadowrocket, V2Box, Streisand |
| Windows | Hiddify, v2rayN, Nekoray |
| macOS | Hiddify, ClashMeta |
| Linux | tuic-client, Hiddify, ClashMeta |
proxies:
- name: "TUIC"
type: tuic
server: SERVER_IP
port: 443
uuid: ВАШ_UUID
password: ВАШ_ПАРОЛЬ
congestion-controller: bbr
alpn:
- h3
sni: your-domain.com
skip-cert-verify: true
udp-over-stream: false
{
"relay": {
"server": "SERVER_IP",
"port": 443,
"uuid": "ВАШ_UUID",
"password": "ВАШ_ПАРОЛЬ",
"sni": "your-domain.com",
"congestion_control": "bbr",
"alpn": ["h3"],
"cert": "path/to/cacert.pem"
},
"local": {
"server": "127.0.0.1",
"port": 1080
}
}
tuic-client -c /etc/tuic/client.json
SOCKS5 на 127.0.0.1:1080.
| Параметр | TUIC | Hysteria2 |
|---|---|---|
| Транспорт | QUIC | QUIC |
| Скорость | ⭐⭐⭐⭐⭐ | ⭐⭐⭐⭐⭐ |
| Устойчивость к потере пакетов | ⭐⭐⭐⭐ | ⭐⭐⭐⭐⭐ |
| Congestion control | BBR, Cubic, New Reno | BBR, Cubic |
| Мультиплексирование | ✅ | ✅ |
| Masquerade | ❌ | ✅ (bing.com) |
| Настройка | простая | простая |
Hysteria2 лучше для нестабильных сетей (мобильный интернет). TUIC — проще, если masquerade не нужен.
# Статус
sudo systemctl status tuic
# Логи
sudo journalctl -u tuic -f
# Порт (UDP!)
sudo ss -ulnp | grep 443
Последнее обновление: 2026-07-18