通过Obfs4混淆Softether VPN的技术求助:解决国内限速问题
Hey there! Since you’ve already nailed using Obfs4 to get full speed with HTTPS proxies, we just need to tweak how it integrates with Softether to bypass that frustrating 600-700 KBytes/s limit. Let’s break down the most likely fixes step by step:
1. Verify the Traffic Forwarding Chain
Obfs4 works by wrapping traffic from a local port and forwarding it to the target server—so your Softether client needs to connect to Obfs4’s local listening port, not directly to the Softether server. Here’s how to set this up correctly:
- Server-side: Run Obfs4 to forward incoming Obfs4 traffic to your Softether server’s listening port. For example, if Softether is using port 5555 locally:
(Port 443 is a safe choice since it’s commonly used for HTTPS, making the obfuscated traffic harder to detect.)obfs4proxy -logLevel INFO -server -bind 0.0.0.0:443 -target 127.0.0.1:5555 - Client-side: Run Obfs4 to listen on a local port and forward traffic to your server’s Obfs4 port:
Then configure your Softether client to connect toobfs4proxy -logLevel INFO -client -bind 127.0.0.1:8080 -target your-server-public-ip:443127.0.0.1:8080instead of the server’s IP directly.
2. Switch Softether to a Protocol More Compatible with Obfs4
Softether’s native protocol might have unique signatures that could still trigger detection even with Obfs4. Try switching to OpenVPN protocol in your Softether client settings:
- In the Softether VPN Client Manager, create a new connection and select "OpenVPN" as the protocol type.
- Point this OpenVPN connection to Obfs4’s local listening port (same as step 1) instead of the server’s OpenVPN port. OpenVPN’s traffic is more similar to standard TLS, which plays better with Obfs4’s obfuscation logic.
3. Check MTU and Fragmentation Settings
Mismatched MTU (Maximum Transmission Unit) sizes between Obfs4 and Softether can cause packet fragmentation, which kills speed. Adjust Obfs4’s MTU to match Softether’s default (usually 1400 or 1500):
- Add the
-mtu 1400flag to your Obfs4 commands on both client and server:obfs4proxy -logLevel INFO -server -bind 0.0.0.0:443 -target 127.0.0.1:5555 -mtu 1400 - In your Softether client, go to "Connection Settings" > "Advanced" and set the MTU to the same value.
4. Rule Out Firewall/Network Interference
Make sure no local firewalls (on client or server) are blocking Obfs4 traffic. On Linux, you can allow the port with:
ufw allow 443/tcp ufw allow 8080/tcp
On Windows, check the Windows Defender Firewall settings to ensure Obfs4 and Softether have outgoing/incoming permissions. You can also use tcpdump (Linux) or Wireshark (Windows) to confirm that traffic is flowing between Obfs4 and Softether without drops.
5. Validate Obfs4 Configuration Files
Double-check the obfs4.json file generated on the server—it contains critical parameters like the public key and node ID that the client needs to connect correctly. If you’re using a pre-configured Obfs4 bridge, ensure you’ve copied all the parameters into your client’s Obfs4 setup (instead of manually typing them, which can lead to typos).
Let me know if any of these steps get you closer to that 2-3 MBytes/s speed you’re targeting—we can dig deeper if needed!
内容的提问来源于stack exchange,提问作者Seyed Amin

