EliteProx logo
Guide

Your EliteProx Line over Xray REALITY: How It Works and Setup

The VLESS option on an EliteProx line is the same dedicated modem and the same carrier IP you already have, delivered through a tunnel that is indistinguishable from a browser visiting a large website. This piece is for the customer who wants to understand what they are switching on before they switch it on. The first half explains the mechanism in plain terms. The second half is the setup, one short list per platform, followed by the checks we use ourselves.

What VLESS and REALITY actually do

VLESS is the protocol the Xray project uses to carry your traffic between a client on your device and a server on our rack. It is lean by design: it identifies you with a single id and leaves encryption to the transport layer. REALITY is that transport. When your client connects, it performs a genuine TLS handshake that borrows the certificate of a well-known public site, so a network in between sees a normal HTTPS session to that site. Only a client holding our server's public key and your short id can complete the handshake and open the tunnel underneath.

The value is twofold. Your credentials and your traffic are encrypted between your device and our server, which a plain SOCKS5 login is not. And because the tunnel is established at the device level, every application on the machine can use the line, including those with no proxy settings of their own.

The exit is unchanged. Once inside the tunnel, traffic goes to your dedicated modem and leaves on its carrier IP. Websites see exactly what they see when you use the SOCKS5 endpoint.

One detail that surprises people: the tunnel does not need a domain of ours. The certificate it presents belongs to the public site named in your link, and the client checks our server's key underneath it. That is why there is nothing to install on your side beyond a client, no certificate to trust, and nothing in the connection that names EliteProx.

Copy the line

Open the EliteProx dashboard, go to My proxies and press the copy button on the VLESS / Xray row of your line. The string beginning vless:// is the full credential and includes your id; treat it as a password, and use Revoke access on the card to replace it if needed. VLESS runs on our server-based lines; when buying or moving, tick VLESS / Xray so only qualifying locations are offered.

Mac and iPhone

  1. Install V2Box from the App Store; it is one app for both platforms.
  2. Open Configs, tap the plus button, then Import from clipboard.
  3. Select the line and press connect. Allow the VPN configuration when asked.
  4. The VPN badge confirms the device is on the line. Streisand is an equally good iPhone alternative.

Windows

  1. Download the With-Core zip from the v2rayN releases page, extract it and run v2rayN.exe.
  2. Press Ctrl and V to import the line from the clipboard.
  3. Right-click the line, choose Set as active server, and set System proxy to Set system proxy in the bottom bar.
  4. Use Test real delay on the line to confirm the tunnel answers. For applications that ignore the Windows proxy setting, switch on TUN mode.

Android

  1. Install v2rayNG from Google Play or from its releases page.
  2. Tap the plus button and choose Import config from clipboard.
  3. Select the line, tap the V button and allow the VPN request. A key icon in the status bar confirms the connection.

Linux and servers

Install the Xray core and write a configuration with a local SOCKS inbound and a VLESS outbound using the values from your link: the id before the at sign, the host and port, and the sni, pbk, sid and fp parameters mapped to serverName, publicKey, shortId and fingerprint under realitySettings, with security set to reality and flow set to xtls-rprx-vision. Run xray with that file and point your software at the local port.

xray run -c config.json
curl -x socks5h://127.0.0.1:1080 https://ifconfig.me

Verification and the three usual faults

With the client connected, load an IP check site or press the Status link on the dashboard card; you should see your line's carrier IP. Rotation and sticky sessions work as before and do not interrupt the tunnel.

If the handshake fails, the device clock is almost always the reason; REALITY validates real certificates and needs an accurate date. If the client reports an invalid user id, the line was moved or its modem switched, which issues a new id; copy the current link. If the tunnel connects but your own IP still shows, the client's system proxy or VPN mode is off.

Frequently asked

Is REALITY a VPN?

It behaves like one on the device, routing everything through the tunnel, but the far end is your dedicated mobile modem rather than a shared VPN server.

Does the tunnel weaken the dedicated nature of the line?

No. The modem is still yours alone. The tunnel only replaces the path between your device and our server.

Which port does the tunnel use?

The port is in your link. Most of our lines serve REALITY on a port that ordinary networks allow; if a corporate network blocks it, ask support for a line on port 443.

USA mobile proxies on hardware we own

Real 4G and 5G carrier IPs in eight US metros, with unlimited rotation, sticky sessions and HTTP(S) or SOCKS5. Try a line by the hour from $2 for the first two hours, or take a full day from $6; the hours you paid count toward the day.

View plans See all locations

More guides

All EliteProx resources →