Skip to content

Endpoints ​

endpoints hold protocol stacks that are inbound and outbound at once: a WireGuard or Tailscale instance, for example, both accepts connections arriving through the tunnel and originates connections into it. The entry shape is the same flat envelope as inbounds and outbounds — type / tag plus the selected type's own fields at the same level.

Envelope ​

FieldTypeDefaultAllowed valuesDescription
typestring—wireguard | openconnect | openvpn-client | openvpn-server | tailscaleEndpoint type. Selects which option struct the rest of the object is decoded into.
tagstring——Unique name for this endpoint. Usable wherever an outbound tag is expected, and matchable by route rules on the inbound side.

Source: option/endpoint.go:18-22 · pinned at v1.14.2 (af6e64c)

Per-type fields are documented on WireGuard and Tailscale. OpenVPN and OpenConnect are documented on OpenVPN and OpenConnect.

Minimal example ​

json
{
  "endpoints": [
    {
      "type": "wireguard",
      "tag": "wg-ep",
      "address": ["10.0.0.2/32"],
      "private_key": "<base64-private-key>",
      "peers": [
        {
          "address": "wg.example.com",
          "port": 51820,
          "public_key": "<base64-public-key>",
          "allowed_ips": ["0.0.0.0/0"]
        }
      ]
    }
  ],
  "route": { "final": "wg-ep" }
}

Notes ​

  • WireGuard is an endpoint; there is no wireguard outbound. The same struct covers both directions of the tunnel.
  • wireguard requires a build with the with_wireguard tag, tailscale one with with_tailscale, openvpn-client / openvpn-server one with with_openvpn, and openconnect one with with_openconnect (official release binaries include all four).
  • openvpn-client / openvpn-server interoperate with standard OpenVPN servers and clients, including static-key mode and legacy ciphers and digests. The companion openvpn DNS server type uses the DNS options the OpenVPN server pushes.
  • openconnect is client-only and talks to Cisco AnyConnect, GlobalProtect, Fortinet, F5, Pulse Connect Secure and Juniper Network Connect servers; the openconnect DNS server type uses its pushed split-DNS resolvers. Interactive logins (e.g. SSO) go through the graphical clients or the sing-box Dashboard.
  • TCP, UDP and ICMP connections from L3 inbounds (TUN, WireGuard, Tailscale) can be forwarded to WireGuard and Tailscale endpoints directly at L3 during pre-match, without L3-to-L4 translation.
  • Route rules can match traffic coming out of an endpoint the same way they match an inbound tag.

Cross-core notes ​

  • Xray-core keeps WireGuard as a normal inbound or outbound protocol (protocol: "wireguard" with IsClient decided by position). See Xray WireGuard.
  • mihomo models WireGuard as a proxy (outbound) only. See mihomo WireGuard.

Source: option/endpoint.go:18-22 · v1.14.2 (af6e64c)

Core Tutorial by Argsment