Skip to content

NullVPN 1.5.0

Latest

Choose a tag to compare

@snarefps snarefps released this 04 Oct 18:22
8bbf729
NullVPN

NullVPN 1.5.0

Switch servers without disconnecting, an Auto server in every subscription, a reconnect that keeps your traffic held when the network drops, Encrypted Client Hello, and the newest Xray and Aether. On Windows, macOS, iOS, Android and Linux.

English · فارسی پایین تر


🇬🇧 English

✨ Highlights

  • 🔁 Switch servers without disconnecting. Pick another server while connected and NullVPN changes it in place. The tunnel stays up, and with Strict route nothing leaks in between. Connections that were open through the old server are ended, so what they carried reopens through the new one.
  • ⚡ An Auto server in every subscription. It connects to the fastest server by ping and, if you want, keeps checking every 30 seconds and moves to a clearly better one.
  • 📡 Reconnects when the network drops and comes back, on every platform, and with Strict route it holds your traffic until the tunnel is up again.
  • 🔒 Encrypted Client Hello (ECH) in share links (ech=) and in the server editor, so servers behind Cloudflare Workers that need it connect.
  • ⚙️ Newer engines: patterniha/Xray-core v26.10.3 and Aether v2.3.0.
  • 🧭 Settings reorganised into Connection, Desktop and Developer pages, with a blue glass look for buttons and the Servers tabs.

🆕 New

  • Switch servers without disconnecting (Settings → Connection). Choosing another server while connected moves the running session to it.
    • Where the core doesn't own the network adapter (TUN with Zeptun, and the proxy modes) the core is started again on the new server and the tunnel is left alone. Elsewhere the server is swapped inside the running core.
    • Off, a change disconnects and connects again, as before.
    • If the new server won't come up, the old one is put back.
  • Auto server. Every subscription has an Auto row at the top. With switching in place on, it checks the subscription every N seconds (Ping settings, default 30) and moves only to a server that is at least 20 ms and a fifth faster, or when the current one stops answering. With it off, Auto measures once when it connects and stays.
  • Reconnect on a lost network. When the connection goes away, NullVPN says Waiting for the network instead of showing Connected, doesn't use up its retries, and brings the tunnel back when the network returns. With Strict route on (Windows, Linux) everything but the tunnel stays blocked the whole time. Proxy modes on Windows follow the network too.
  • Encrypted Client Hello. Links with ech=cloudflare-ech.com+udp://1.1.1.1 are imported, and there's an ECH config list field in the TLS editor. The lookup it needs leaves by the same network as the server connection, so it works under a tunnel.
  • Aether 2.3.0.
    • WARP-in-MASQUE (QUIC and TCP): the new --gool, with an optional WireGuard endpoint. The old WireGuard-in-WireGuard is now named WARP-in-WARP (classic) and keeps working.
    • ClientHello fragmenting is on by default on the TCP carrier, and turning it off is sent explicitly.
    • New options: ECH resolver and domain, TLS 1.2 cipher suites, fragment the WARP API calls, leave out GREASE values, how often the exit country is checked and statistics are logged, and which Psiphon CDN lists to try.
  • Developer settings (above About, on every platform): turn the log recording off to save memory, show how much memory NullVPN and its engines use, and on iPhone the VPN's memory.
  • Connection and Desktop pages in Settings. Connection holds the tunnel mode, ports, auto-reconnect, the new switching option and the core settings. Desktop holds launch at login, the tray and Windows' efficiency and network tuning.
  • Logs can be turned off. Nothing is kept or parsed while it's off.
  • Swipe a message up to dismiss it.
  • Copy config in each server's menu, including servers inside a subscription.
  • Ping all for Local servers, beside the QR button when Local is open.
  • Tapping the server on Home opens the Servers page on it: it opens its subscription if it was folded, scrolls to it and makes it beat once.
  • Geo files page redesigned: what's in use, a source tile each, and the automatic update interval. On iPhone the files are downloaded by the app and sent to the VPN, which uses them from the next connection.
  • Ping defaults: sorted by ping, with a 3-second timeout. A server that has said nothing by the timeout is given up on, instead of being tried again for as long again.
  • Updates keep their download in the app's own folder, reuse a finished verified file instead of downloading again, and show where it is.

⚡ Improved

  • A newer Xray core, v26.10.3: fixes for Vision, finalmask, WireGuard and the QUIC sniffer, and lower memory for the geo databases. The XDNS finalmask options changed shape upstream, so an XDNS link from before needs updating.
  • Blue glass buttons, the same as the dock's selected item, and the same look for the Subscriptions / Local tabs. The Servers header icons are larger, and the Settings rows use new icons.
  • Keyboard on phones: the dock gets out of the way while you type.
  • iPhone ping is measured on a warm connection, like the connected ping, instead of timing the whole handshake.
  • Quit and Dock on a Mac: ⌘Q and the Dock's Quit now stop the tunnel properly, and clicking the Dock icon brings back a window hidden in the tray.

🐞 Fixed

  • Edit server and every text field on a phone: with the keyboard up, the page was shortened twice and only a thin strip of it showed.
  • iPhone: changing the server of a connected tunnel could end disconnected and never reconnect. The request now reaches the VPN over a channel that works under every signing, and a fallback reconnect waits for the old tunnel to stop first.
  • Disconnecting during a reconnect could bring the tunnel back by itself.
  • Trojan and other TLS links with ech= connected without ECH and failed.
  • The IP address, country and ping shown after changing server in place were the old server's.
  • Windows: reconnect wasn't triggered when Wi-Fi was turned off, in TUN or in the proxy modes.

🙏 Thanks

A big thank you to patterniha for patterniha/Xray-core, the Xray core NullVPN runs on every platform, and for the free configs shared with everyone in Iran. And to CluvexStudio for Aether and Noisemux for Zeptun.

📦 Downloads

Platform File
Windows 10 / 11 (64-bit) NullVPN-windows-x64-setup.exe
Android 7.0+, most phones ⭐ NullVPN-android-arm64-v8a.apk
Android, older 32-bit phones NullVPN-android-armeabi-v7a.apk
Android, emulators and x86 tablets NullVPN-android-x86_64.apk
macOS 12+ Intel and Apple Silicon NullVPN-macos-universal.dmg
iPhone / iPad, iOS 15+ sign it yourself NullVPN-ios-unsigned.ipa
Linux Debian, Ubuntu, Mint ⭐ NullVPN-linux-amd64.deb
Linux Fedora, RHEL, openSUSE NullVPN-linux-x86_64.rpm
Linux any distribution, no install NullVPN-linux-x86_64.AppImage
Linux manual install NullVPN-linux-x64.tar.gz

Tip

Not sure which Android file to pick? Choose arm64-v8a. On Linux, pick the .deb for Debian, Ubuntu or Mint, and the .rpm for Fedora.

📝 Install notes

  • Windows: the installer isn't code-signed yet, so SmartScreen may show "Windows protected your PC". Click More info → Run anyway. It needs administrator rights, since it installs for all users.
  • macOS: open the .dmg and drag NullVPN into Applications. The app isn't signed by Apple yet, so run this once in Terminal before opening it: xattr -dr com.apple.quarantine /Applications/NullVPN.app. Updates from inside the app don't need it again.
  • iOS: the .ipa is unsigned. Sign and install it with ESign, Sideloadly or Xcode, using a certificate whose provisioning profile includes the Network Extension entitlement (packet tunnel). The first time you connect, iOS asks to add a VPN configuration; tap Allow.
  • TUN mode on macOS asks for your administrator password the first time, to install its helper. It asks once, not on every connect. To remove the helper later: sudo /Library/PrivilegedHelperTools/com.nullvpn.helper uninstall.
  • Android: Google Play Protect may say it hasn't scanned the app yet. Tap Scan, or More info → Install.
  • Linux tray: the tray icon needs your desktop's AppIndicator support. GNOME needs the AppIndicator extension; KDE, Cinnamon, XFCE and MATE have it built in. The .deb and .rpm install the library it needs.
  • Updating keeps your servers, subscriptions and settings.

🐧 Linux: install and uninstall

# .deb   Debian, Ubuntu, Mint
sudo apt install ./NullVPN-linux-amd64.deb
sudo apt remove nullvpn

# .rpm   Fedora, RHEL (openSUSE: zypper)
sudo dnf install ./NullVPN-linux-x86_64.rpm
sudo dnf remove nullvpn

# AppImage   no install
chmod +x NullVPN-linux-x86_64.AppImage
./NullVPN-linux-x86_64.AppImage

# .tar.gz   installs to /opt/nullvpn
tar -xzf NullVPN-linux-x64.tar.gz
cd NullVPN-1.5.0-x64
sudo ./install.sh
sudo /opt/nullvpn/uninstall.sh

🇮🇷 فارسی

✨ مهم ترین تغییرات

  • 🔁 تعویض سرور بدون قطع اتصال. وقتی وصلی و سرور دیگه ای انتخاب میکنی، NullVPN سرور رو درجا عوض میکنه. تانل سر جاش میمونه و با Strict route بین تعویض هیچ ترافیکی نشت نمیکنه. اتصال هایی که از سرور قبلی باز بودن بسته میشن و از سرور جدید دوباره باز میشن.
  • ⚡ یک سرور «خودکار» توی هر اشتراک. به سریع ترین سرور بر اساس پینگ وصل میشه و اگه بخوای هر ۳۰ ثانیه چک میکنه و فقط به سرور واضحاً بهتر میره.
  • 📡 وصل شدن دوباره بعد از قطع و وصل شدن شبکه، روی همه پلتفرم ها؛ و با Strict route تا برگشتن تانل ترافیکت بسته میمونه.
  • 🔒 Encrypted Client Hello (ECH) توی لینک ها (ech=) و توی ویرایشگر سرور، تا سرورهای پشت Cloudflare Workers که بهش نیاز دارن وصل بشن.
  • ⚙️ هسته های جدید: patterniha/Xray-core نسخه v26.10.3 و Aether نسخه v2.3.0.
  • 🧭 تنظیمات مرتب شد توی صفحه های اتصال، دسکتاپ و توسعه دهنده، با ظاهر شیشه ای آبی برای دکمه ها و تب های سرورها.

🆕 جدید

  • تعویض سرور بدون قطع اتصال (تنظیمات ← اتصال). انتخاب سرور دیگه موقع اتصال، نشست در حال اجرا رو به اون منتقل میکنه.
    • وقتی هسته صاحب کارت شبکه نیست (TUN با Zeptun و حالت های پروکسی) هسته روی سرور جدید دوباره راه میفته و تانل دست نمیخوره. جاهای دیگه سرور داخل هسته در حال اجرا عوض میشه.
    • اگه خاموش باشه، تعویض مثل قبل قطع و وصل میکنه.
    • اگه سرور جدید بالا نیاد، سرور قبلی برمیگرده.
  • سرور خودکار. بالای هر اشتراک یک ردیف خودکار هست. وقتی تعویض درجا روشنه، هر N ثانیه (تنظیمات پینگ، پیش فرض ۳۰) اشتراک رو چک میکنه و فقط به سروری میره که حداقل ۲۰ میلی ثانیه و یک پنجم سریع تر باشه یا وقتی سرور فعلی جواب نده. وقتی خاموشه، یک بار موقع اتصال اندازه میگیره و همون میمونه.
  • وصل شدن دوباره بعد از قطع شبکه. وقتی شبکه میره، به جای «وصل» پیام منتظر شبکه نشون میده، تلاش های دوباره رو تموم نمیکنه و وقتی شبکه برگشت تانل رو برمیگردونه. با Strict route (ویندوز، لینوکس) همه چیز به جز تانل تمام این مدت بسته میمونه. حالت های پروکسی توی ویندوز هم شبکه رو دنبال میکنن.
  • Encrypted Client Hello. لینک هایی مثل ech=cloudflare-ech.com+udp://1.1.1.1 وارد میشن و یک فیلد ECH config list توی ویرایشگر TLS هست. جستجوی لازمش از همون شبکه ای میره که اتصال سرور میره، پس زیر تانل هم کار میکنه.
  • Aether 2.3.0.
    • WARP-in-MASQUE (QUIC و TCP): --gool جدید، با نقطه WireGuard اختیاری. WireGuard-in-WireGuard قدیمی حالا WARP-in-WARP (classic) اسم داره و مثل قبل کار میکنه.
    • تکه تکه کردن ClientHello پیش فرض روشنه روی حامل TCP، و خاموش کردنش صریحاً فرستاده میشه.
    • گزینه های جدید: نام سرور و دامنه ECH، رمزهای TLS 1.2، تکه تکه کردن درخواست های API وارپ، حذف مقادیر GREASE، هر چند وقت کشور خروجی چک بشه و آمار ثبت بشه، و کدوم فهرست های CDN سایفون امتحان بشن.
  • تنظیمات توسعه دهنده (بالای «درباره»، روی همه پلتفرم ها): ثبت لاگ رو خاموش کن تا حافظه کمتر مصرف بشه، مصرف حافظه NullVPN و هسته ها رو ببین، و روی آیفون حافظه VPN.
  • صفحه های اتصال و دسکتاپ توی تنظیمات. اتصال: حالت تانل، پورت ها، اتصال خودکار، گزینه تعویض جدید و تنظیمات هسته. دسکتاپ: اجرا با ورود، ترِی و تنظیمات کارایی و شبکه ویندوز.
  • لاگ رو میشه خاموش کرد. وقتی خاموشه چیزی نگه داشته یا پردازش نمیشه.
  • پیام ها رو به بالا بکش تا بسته بشن.
  • کپی کانفیگ توی منوی هر سرور، حتی سرورهای داخل اشتراک.
  • پینگ همه برای سرورهای محلی، کنار دکمه QR وقتی تب محلی بازه.
  • زدن روی سرور توی صفحه اصلی صفحه سرورها رو روی همون سرور باز میکنه: اشتراکش رو باز میکنه اگه بسته بود، تا سرور اسکرول میکنه و یک بار ضربان میزنه.
  • صفحه فایل های جغرافیایی از نو طراحی شد: چی استفاده میشه، یک کاشی برای هر منبع، و فاصله به روزرسانی خودکار. روی آیفون برنامه فایل ها رو دانلود میکنه و به VPN میفرسته که از اتصال بعدی ازشون استفاده کنه.
  • پیش فرض های پینگ: مرتب سازی بر اساس پینگ و مهلت ۳ ثانیه. سروری که تا مهلت چیزی نگفته رها میشه، نه اینکه دوباره به همون اندازه امتحان بشه.
  • آپدیت دانلودش رو نگه میداره توی پوشه خود برنامه، فایل کامل و تأیید شده رو دوباره دانلود نمیکنه و جاش رو نشون میده.

⚡ بهبودها

  • هسته جدیدتر Xray، v26.10.3: رفع مشکلات Vision، finalmask، WireGuard و QUIC sniffer، و حافظه کمتر برای پایگاه های جغرافیایی. گزینه های XDNS finalmask توی هسته تغییر شکل دادن، پس لینک XDNS قدیمی باید به روز بشه.
  • دکمه های شیشه ای آبی، مثل مورد انتخاب شده داک، و همین ظاهر برای تب های اشتراک ها / محلی. آیکون های بالای صفحه سرورها بزرگ تر شدن و ردیف های تنظیمات آیکون جدید دارن.
  • کیبورد روی گوشی: وقتی تایپ میکنی داک کنار میره.
  • پینگ آیفون روی اتصال گرم اندازه گرفته میشه، مثل پینگ وصل، نه کل دست دادن.
  • خروج و داک توی مک: ⌘Q و Quit داک حالا تانل رو درست متوقف میکنن، و زدن روی آیکون داک پنجره پنهان شده توی ترِی رو برمیگردونه.

🐞 رفع مشکلات

  • ویرایش سرور و همه فیلدهای متنی روی گوشی: با کیبورد باز، صفحه دو بار کوتاه میشد و فقط یک نوار باریک ازش دیده میشد.
  • آیفون: عوض کردن سرور تانل وصل میتونست قطع بمونه و دیگه وصل نشه. درخواست حالا از کانالی به VPN میرسه که با هر امضایی کار میکنه، و وصل مجدد جایگزین صبر میکنه تا تانل قبلی کامل متوقف بشه.
  • قطع کردن وسط وصل شدن دوباره میتونست تانل رو خودبه خود برگردونه.
  • لینک های Trojan و TLS دیگه با ech= بدون ECH وصل میشدن و کار نمیکردن.
  • آی پی، کشور و پینگی که بعد از تعویض درجای سرور نشون داده میشد مال سرور قبلی بود.
  • ویندوز: با خاموش کردن Wi-Fi، وصل مجدد فعال نمیشد، هم توی TUN و هم توی حالت های پروکسی.

🙏 تشکر

یک تشکر ویژه از patterniha برای patterniha/Xray-core، هسته Xray ای که NullVPN روی همه پلتفرم ها ازش استفاده میکنه، و برای کانفیگ های رایگانی که با همه توی ایران به اشتراک میذاره. و از CluvexStudio برای Aether و Noisemux برای Zeptun.

📦 دانلود

پلتفرم فایل
ویندوز ۱۰ و ۱۱ (۶۴ بیتی) NullVPN-windows-x64-setup.exe
اندروید ۷ به بالا، بیشتر گوشی ها ⭐ NullVPN-android-arm64-v8a.apk
اندروید، گوشی های قدیمی ۳۲ بیتی NullVPN-android-armeabi-v7a.apk
اندروید، شبیه ساز و تبلت x86 NullVPN-android-x86_64.apk
مک، macOS 12 به بالا اینتل و Apple Silicon NullVPN-macos-universal.dmg
آیفون / آیپد، iOS 15 به بالا خودت امضا کن NullVPN-ios-unsigned.ipa
لینوکس دبیان، اوبونتو، مینت ⭐ NullVPN-linux-amd64.deb
لینوکس فدورا، RHEL، اوپن سوزه NullVPN-linux-x86_64.rpm
لینوکس هر توزیعی، بدون نصب NullVPN-linux-x86_64.AppImage
لینوکس نصب دستی NullVPN-linux-x64.tar.gz

[!TIP]
نمیدونی کدوم فایل اندروید رو بگیری؟ arm64-v8a رو بگیر. روی لینوکس، برای دبیان و اوبونتو و مینت .deb و برای فدورا .rpm رو بگیر.

📝 نکته های نصب

  • ویندوز: فایل نصب هنوز امضای دیجیتال نداره، برای همین ممکنه SmartScreen پیام «Windows protected your PC» نشون بده. روی More info و بعد Run anyway بزن. چون برای همه کاربرها نصب میکنه، دسترسی ادمین میخواد.
  • مک: فایل .dmg رو باز کن و NullVPN رو بکش توی Applications. برنامه هنوز امضای اپل نداره، پس قبل از باز کردنش یک بار توی Terminal بزن: xattr -dr com.apple.quarantine /Applications/NullVPN.app آپدیت های داخل برنامه دیگه لازمش ندارن.
  • iOS: فایل .ipa امضا نداره. با ESign، Sideloadly یا Xcode امضا و نصبش کن، با سرتیفیکیتی که پروفایلش دسترسی Network Extension (packet tunnel) داره. بار اول که وصل میشی، iOS میپرسه VPN Configuration اضافه بشه Allow رو بزن.
  • حالت TUN توی مک بار اول رمز ادمین رو میپرسه تا هلپرش رو نصب کنه؛ فقط یک بار، نه هر بار که وصل میشی. برای حذف هلپر: sudo /Library/PrivilegedHelperTools/com.nullvpn.helper uninstall
  • اندروید: ممکنه Google Play Protect بگه برنامه هنوز اسکن نشده. Scan رو بزن، یا روی More info و بعد Install بزن.
  • آیکون کنار ساعت روی لینوکس: به پشتیبانی AppIndicator دسکتاپت نیاز داره. گنوم افزونه AppIndicator رو لازم داره؛ KDE، Cinnamon، XFCE و MATE خودشون دارن. بسته های .deb و .rpm کتابخونه لازم رو نصب میکنن.
  • با آپدیت، سرورها و اشتراک ها و تنظیماتت سر جاشون میمونن.

🔐 SHA-256 checksums
1b18737f8d640fca1d3053ad6b9f96bc6d0129a019005a7112aceedb34eef5e9 NullVPN-windows-x64-setup.exe
4f6437f529115beef0568dec072df65c7bc731405545dc82d17c307f10f20c0d NullVPN-android-arm64-v8a.apk
a69a8cfd28356a63cc6a392d2092ddf6d9832134edcd32725aac2079c285d5c4 NullVPN-android-armeabi-v7a.apk
4f5f3629f98e6d38328dfe5acec34732395daf13e90248bdae22ca848a83f247 NullVPN-android-x86_64.apk
eca033071ccae1ea4e7972ac928cd208eb71880a6ac6e73a324bb42bd8ef2caf NullVPN-macos-universal.dmg
1d67079a8dca9aa2ced2f0858160d96c242b4b19790b8e710a4dda82aa6cf757 NullVPN-ios-unsigned.ipa
dd35ddeb3171f85f6c53a6b617402b3fc212e9ba5e223a4e9ee44b1bd41c1961 NullVPN-linux-amd64.deb
904c6e4dba79bbe33b68efc719128f8dc1ef78d0a3386d63451e4b20d39da691 NullVPN-linux-x86_64.rpm
45ac9701914452328ce7ef60c58ffd84e37a481455642ad2d33fc62d4e0f1d62 NullVPN-linux-x86_64.AppImage
015d41580da4dc5d63f7f60b11ac70844df02d0772b519f19a2f1a8e2308d7ed NullVPN-linux-x64.tar.gz

If a file's checksum doesn't match, don't install it.

💬 Telegram channel · 🐞 Report a bug

Made with ❤️ by SNareFPS · Xray core by patterniha