masque.mdx 3.3 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859
  1. ---
  2. title: MASQUE
  3. description: Serve MASQUE (CONNECT-IP) inbounds in 3x-ui, connect outbounds to MASQUE servers, and reach Cloudflare WARP over MASQUE.
  4. icon: Waypoints
  5. ---
  6. **MASQUE** carries IP packets over HTTP/3 (or HTTP/2) with the CONNECT-IP method, so a
  7. client gets a full layer-3 tunnel that looks like ordinary HTTPS traffic. xray-core
  8. serves it natively; 3x-ui offers it as an inbound protocol, an outbound protocol, and the
  9. matching `masque` transport they both ride on.
  10. ## Inbound
  11. | Field | Description |
  12. | ---------------- | ----------- |
  13. | **Clients** | Each client logs in with its **email** and **password** (HTTP Basic auth). Traffic, quotas, IP limits and expiry work like any other multi-user protocol. |
  14. | **Address pool** | Prefixes the tunnel addresses are leased from — at most one IPv4 and one IPv6 (default `10.14.0.1/24`, `fd14::1/64`). The pool size caps how many clients can be connected at once. |
  15. | **MTU** | Tunnel MTU, 1280–65535; leave empty for the core default. |
  16. | **Path** | Request path the server answers on (default `/.well-known/masque/ip/*/*/`). |
  17. | **Security** | Always TLS. The ALPN picks the listeners: `h3` serves HTTP/3 on UDP, `h2` serves HTTP/2 on TCP, and both together serve both. |
  18. <Callout type="info">
  19. MASQUE has no share-link format, so MASQUE inbounds get no link, QR code or Clash
  20. entry. Clients get a ready-to-import config from the **JSON subscription**: a `masque`
  21. outbound that authenticates with the client's email and password.
  22. </Callout>
  23. ## Outbound
  24. Pick **masque** as the outbound protocol, then set:
  25. | Field | Description |
  26. | ----------------------- | ----------- |
  27. | **Address / Port** | The MASQUE server. |
  28. | **Remote DNS** | Optional DNS server IPs queried inside the tunnel. |
  29. | **Host / Path** | Authority and path of the CONNECT-IP request; the path must match the server's. |
  30. | **Username / Password** | HTTP Basic credentials — on a 3x-ui server, the client's email and password. |
  31. | **Headers** | Extra request headers. |
  32. | **TLS** | Required. An ALPN of `h2` alone switches to HTTP/2 over TCP; otherwise HTTP/3 is used. |
  33. ## WARP over MASQUE
  34. The quickest way is **Xray → Outbounds → WARP → Add WARP over MASQUE outbound**: the panel
  35. registers a separate WARP device, enrolls a MASQUE key for it and adds a ready `warp-masque`
  36. outbound (or refreshes the existing one). Your WireGuard WARP registration is not touched.
  37. To set it up by hand instead:
  38. Turn on **WARP** in the masque transport to reach Cloudflare WARP through its MASQUE
  39. endpoint instead of WireGuard. It takes a WARP registration enrolled for MASQUE:
  40. | Field | Description |
  41. | ----------------------- | ----------- |
  42. | **Private key** | The enrolled ECDSA P-256 private key (PEM, or base64 DER). |
  43. | **Endpoint public key** | Cloudflare's endpoint public key returned by the enrollment. |
  44. | **Tunnel addresses** | The IPv4 and IPv6 addresses Cloudflare assigned to the registration. |
  45. Host and path then default to Cloudflare's endpoint, and WARP can't be combined with a
  46. username or password. Point the outbound at the endpoint address from your enrollment and
  47. set the TLS server name to `consumer-masque.cloudflareclient.com`.