Setup guides
Connect apps, servers and tunnels — step by step.
Client apps per protocol
| Protocol | How to connect |
|---|---|
| VLESS / VMess / Trojan / Shadowsocks / Hysteria2 | Copy one link from the user dashboard, or import the whole subscription URL at once (one link carries all protocols). Android: v2rayNG, NekoBox. iOS: Streisand, FoXray, Shadowrocket. Desktop: NekoRay, Clash Verge, Hiddify, sing-box. |
| Clash users | Import the ?format=clash URL (auto-detected for Clash user-agents): proxies + Zefira select group + site-block rules + MATCH. |
| WireGuard | Download the -wg.conf (panel Download button or user dashboard) and import it into the WireGuard app. No handshake? The server public key is missing: Settings → Server/Hosts → WireGuard server public key (from wg show on the server). |
| OpenVPN | Download the .ovpn (CA + cert + key embedded) and import into OpenVPN Connect / Tunnelblick. Match proto (UDP/TCP) and port with Settings. |
| L2TP/IPsec | Open the -l2tp.txt credentials (server, username, password, IPsec PSK). Windows: Settings → Network → VPN → Add VPN, type L2TP/IPsec with pre-shared key. Android: Settings → Network → VPN → L2TP/IPsec PSK. iOS: Settings → General → VPN → Add L2TP (shared secret = PSK). The server needs UDP 500/4500/1701 open and a matching server-side user entry — create it before selling. |
| Cisco AnyConnect | Install OpenConnect (or the AnyConnect app). Command: openconnect --user=USERNAME SERVER. In the app: add the server, sign in with panel username + password. Default port 443 (Settings → Cisco port). |
| SOCKS5 | Use the socks5:// link. Telegram: Settings → Data and Storage → Proxy → Add SOCKS5 (server, port, username, password). Browsers: SwitchyOmega / FoxyProxy. Clash: included automatically as a socks5 proxy. |
BackPack tunnel walkthrough (Iran ⇄ Kharej)
- Install BackPack on BOTH servers (Iran entry + Kharej exit) with its install script.
- Zefira → Tunnels → create node: transport, Iran IP, Kharej IP, tunnel port, forwarded ports (e.g.
443:8000), UDP flag. Copy the one-time token — it must match on both servers. - Iran server:
backpack→ Setup Iran → same transport, port, name, token, exposed ports, Turbo preset. - Kharej server:
backpack→ Setup Kharej → same values + Iran address. - Verify: Status on both servers, Health Check on errors, then Zefira Check now probes
iran-ip:tunnel-port. Keep the token secret — whoever holds it can join the tunnel.
Transport picks: dirty routes → TCP+Stealth or WSS/WSS-Mux. UDP apps (WireGuard, DNS, games) → enable Forward UDP with KCP/QUIC transports.
No inbound to Iran? Use BackPack Direct mode instead of a reverse tunnel: Setup Iran → Direct → pick a carrier (udp, quic, pck, sni, xdi, spoof). Iran dials out so no inbound port is needed, and forwarded ports work the same. The tunnel port can be pinned to one address (IP:port) in the wizard.
Anti-filter cookbook
- REALITY first: Anti-Censorship → Generate keypair (private stays encrypted, reveal is audit-logged) → paste the private key into the Xray server config. Links rotate SNI automatically (
xtls-rprx-vision). - Stack layers on dirty networks: REALITY or Hysteria2 + obfuscated host (a weird CDN URL hiding the real IP) + per-user subdomains (needs wildcard DNS
*.host— every user gets a random prefix) + CDN SNI spoofing + block-direct-IP (panel reachable only via domain). - Monitor: Nodes section tracks remote servers (status/latency/uptime every 5 min). Pin inbounds to a node — offline/disabled nodes drop out of every subscription link automatically until recovery.
- Diagnose 404s: user expired/disabled/out-of-volume? Then Settings domain/ports, server firewall ports, REALITY keys / WireGuard public key. Sub loads but clients can't connect = server-side ports or keys, almost always.
Ask the AI
The panel ? assistant knows all of the above and acts too: “make user ali 50 gig 30 days vless”, “top up reza 20 gig”, “how do I tunnel Kharej?” — setup answers plus real operations, audit-logged. Full list in Users & Plans → AI assistant.
ZEF