# Laboratory VPN protocol benchmark — Qeli 0.8.0 Run period: **2026-09-01T17:05:33Z — 2026-09-02T05:20:05Z (UTC)**. Data status: **complete**. This document records the completed laboratory run, methodology, configuration parameters, and results. Throughput was measured with `iperf3`. The H/B/T/A attributes describe enabled masking mechanisms and preflight/PCAP observations; they do not measure the probability of classification by an external DPI system. ## 1. Factual summary - Full `rep1`: **34** available modes. `rep2` and `rep3`: **25** masked modes. By design, the **9** control modes have only `n=1`. - Preliminary dual-stack gate for new profiles: **19/19**. - Qeli: **12/12** profiles emitted the runtime marker `PACKET_MUX_V1 active ... policy=required`. - Mean TCP `P=4` across all 12 Qeli profiles: **1220 Mbit/s**. For each mode, repeat medians were first calculated for all four directions; the resulting mode values were then averaged. - Highest mean TCP `P=4` in the full set: **WireGuard plain — 3161 Mbit/s**. - Highest mean TCP `P=4` among masked modes: **AmneziaWG full 3.1 — 2820 Mbit/s**. - Of **100** masked-mode directions, the `rep1` UDP ceiling rate was confirmed with loss ≤1% in all three repeats for **54** directions; **46** directions produced fewer than 3/3 passes. For Qeli, **24/48** directions were confirmed 3/3, with **113/144** clean windows in total at the `rep1` ceiling rate. - Baseline drift after the matrix: upload **+1.48%**, download **-1.71%**. No automatic rejection threshold was applied. ### 1.1. Aggregate summary | Group | Modes | TCP P=4, Mbit/s | UDP rep1 ceiling, Mbit/s | | --- | --- | --- | --- | | Qeli: fast TCP profiles | 5 | 1767 | 1365 | | Qeli: heavyweight TCP profiles | 3 | 1274 | 1048 | | Qeli: native UDP profiles | 4 | 496 | 409 | | AmneziaWG full 3.1 | 1 | 2820 | 1256 | | Xray VLESS TLS/REALITY + Vision | 2 | 995 | 347 | | Hysteria 2 QUIC TLS/Salamander | 2 | 947 | 375 | | OpenVPN with wrappers | 6 | 310 | 289 | | WireGuard with wrappers | 2 | 452 | 403 | In this table, `TCP P=4` is the mean across the included modes, where each mode value is the mean of four directions calculated from repeat medians. `UDP rep1 ceiling` is the mean offered rate found in `rep1` across IPv4/IPv6 and upload/download; it is not mean achieved goodput. The groups do not have equal H/B/T/A depth, so the table records the performance of the selected configurations rather than ranking their stealth. Qeli group composition: fast TCP — `tcp-plain-raw`, `tcp-faketls`, `tcp-padding`, `tcp-frag`, `tcp-reality`; heavyweight TCP — `tcp-obfs`, `tcp-reality-tls`, `tcp-obfs-awg`; native UDP — `udp-faketls`, `udp-padding`, `udp-quic`, `udp-faketls-awg`. OpenVPN with wrappers includes stunnel DTLS/TLS, XOR UDP/TCP, and Cloak TCP/UDP; WireGuard with wrappers includes wg-obfuscator STUN and experimental Cloak. ## 2. Laboratory environment and run hygiene - VM server: `10.66.116.10`; VM client: `10.66.116.11`. - Both VMs: Debian, kernel `6.12.105+deb13-amd64`, **2 vCPU**, **2 GiB RAM**. - Both VMs were fully and synchronously rebooted before the numerical run. Server boot ID: `cf04df08-770d-4ce9-a32a-222e5dd7c319`; client: `ffbf54d8-6c2d-46ed-89ba-36db7b2b24e7`. - Background VPN services and system maintenance timers were stopped before the baseline; Qeli and Android emulator/ADB autostarts were runtime-masked. - The absence of `qemu-system`, `adb`, and `netem` was verified on both VMs; the IPv6 INPUT/FORWARD/OUTPUT policy was `ACCEPT`. - More than 21 GiB remained free on each VM after cleanup. No source files or user configurations were removed during cleanup. - Runtime sysctl settings were identical on both sides: `rmem_max/wmem_max=16777216`, default buffers `1048576`, `netdev_max_backlog=5000`, and UDP minimum buffers `16384`. - The egress qdisc of the external virtio interfaces was left in the laboratory default state: server `fq_codel`, client `fq`. This state remained unchanged for every mode and matches the previous cycle, but upload and download should be compared within their respective directions rather than treating their difference solely as a VPN property. - Measurements were performed inside one Proxmox laboratory environment between two VMs. WAN latency, jitter, and loss were not emulated; the results characterize throughput and processing cost under these conditions. Full-reboot artifact: `release\competitor_repeat_080_reboot_2026-09-01.json`. ## 3. Measurement procedure 1. A direct baseline against the external address `10.66.116.10` was measured on the new boot IDs: five upload/download repeats, 12 seconds, TCP, one stream. 2. `rep1` is a full pass over 34 modes in forward order. `rep2` is a reduced pass over 25 masked modes in reverse order; `rep3` uses the same reduced set in a deterministically shuffled order. This reduces systematic warm-up and cache effects. 3. Each mode was started from scratch for every repeat required by policy. Control modes ran once; masked modes ran three times. Processes, TUN/WG/AWG interfaces, policy routing, and XFRM state were removed before the next mode. 4. IPv4 and IPv6 ping had to pass after startup. Qeli additionally required verification of the Recordizer runtime marker. 5. TCP: IPv4/IPv6 × upload/download. The full `rep1` measured `P=1` and `P=4`; reduced `rep2/rep3` measured only `P=4`. Each window lasted 15 seconds, with the first 3 seconds excluded using `-O 3`. 6. UDP: 1200-byte payload, a 15-second window, and a 3-second warm-up. `rep1` requires 300/450/600 Mbit/s; the offered load is then raised to the actual boundary (30 Gbit/s safety ceiling), and the loss ≤1% boundary is refined to 25 Mbit/s steps. `rep2/rep3` test exactly two points in each direction: the clean ceiling found in `rep1` and the first failed step. 7. `UDP rep1 ceiling` is the offered rate found in the full pass. The `[pass/n; median loss]` format shows how many checks of that same point remained within loss ≤1%. Controls use `n=1`; masked modes use `n=3`. If `pass1`; `—` for controls means there were no repeats, not zero variance. ## 7. CPU, RSS, and kernel drops | Product / mode | TCP P=4 CPU VM S/C, % | UDP ref CPU VM S/C, % | TCP P=4 VPN CPU S/C, % VM | UDP ref VPN CPU S/C, % VM | RSS max S/C, MiB | softnet drops S/C | | --- | --- | --- | --- | --- | --- | --- | | WireGuard plain | 80.1 / 82.3 | 76.7 / 78.9 | 0.0 / 0.0 | 0.0 / 0.0 | 0.0 / 0.0 | 0 / 0 | | WireGuard + wg-obfuscator STUN | 69.9 / 71.5 | 62.3 / 61.6 | 32.2 / 32.6 | 25.6 / 25.1 | 1.1 / 1.1 | 0 / 0 | | AmneziaWG mask-off | 78.7 / 81.7 | 78.9 / 78.4 | 0.0 / 0.0 | 0.0 / 0.0 | 0.0 / 0.0 | 0 / 0 | | AmneziaWG full 3.1 | 75.9 / 78.3 | 76.0 / 74.3 | 0.0 / 0.0 | 0.0 / 0.0 | 0.0 / 0.0 | 0 / 0 | | OpenVPN UDP userspace | 55.5 / 52.2 | 52.2 / 48.8 | 45.7 / 41.7 | 36.5 / 33.0 | 9.8 / 9.6 | 0 / 0 | | OpenVPN UDP + DCO | 57.6 / 54.9 | 38.3 / 38.6 | 0.0 / 0.0 | 0.0 / 0.0 | 9.8 / 9.6 | 0 / 0 | | OpenVPN UDP + stunnel DTLS | 77.7 / 55.9 | 72.4 / 53.8 | 71.3 / 48.7 | 62.9 / 42.3 | 19.9 / 19.5 | 0 / 0 | | OpenVPN TCP userspace | 55.7 / 57.8 | 57.8 / 58.8 | 45.0 / 43.4 | 37.7 / 38.0 | 9.9 / 9.7 | 0 / 0 | | OpenVPN TCP + stunnel TLS 1.3 | 85.0 / 85.2 | 69.9 / 69.6 | 73.5 / 74.3 | 56.3 / 54.3 | 20.0 / 19.6 | 0 / 0 | | IPsec strongSwan ESP | 64.2 / 60.8 | 39.5 / 39.3 | 0.0 / 0.0 | 0.0 / 0.0 | 10.3 / 10.4 | 0 / 0 | | IPsec strongSwan NAT-T | 64.9 / 60.5 | 37.0 / 36.1 | 0.0 / 0.0 | 0.0 / 0.0 | 10.3 / 10.4 | 0 / 0 | | Xray VLESS + TLS + Vision (TUN) | 22.1 / 75.8 | 57.4 / 62.3 | 15.2 / 65.7 | 42.1 / 46.5 | 51.3 / 97.9 | 0 / 0 | | Xray VLESS + REALITY + Vision (TUN) | 21.0 / 76.1 | 59.8 / 62.9 | 15.2 / 65.8 | 44.2 / 47.4 | 55.2 / 99.1 | 0 / 0 | | Hysteria 2 QUIC TLS (TUN) | 69.1 / 89.8 | 71.1 / 69.4 | 62.7 / 80.0 | 56.9 / 56.1 | 109.9 / 116.7 | 0 / 0 | | Hysteria 2 QUIC + Salamander (TUN) | 68.1 / 86.4 | 71.5 / 70.0 | 58.7 / 76.6 | 57.2 / 57.3 | 43.0 / 59.6 | 0 / 0 | | OpenVPN-XOR build UDP, scramble off | 56.3 / 50.8 | 51.6 / 46.4 | 46.6 / 41.6 | 33.7 / 30.5 | 9.8 / 9.6 | 0 / 0 | | OpenVPN UDP + XOR | 54.5 / 53.2 | 52.9 / 51.9 | 46.1 / 43.4 | 40.2 / 35.3 | 9.8 / 9.6 | 0 / 0 | | OpenVPN-XOR build TCP, scramble off | 55.2 / 55.8 | 60.9 / 61.3 | 44.3 / 43.7 | 39.5 / 42.1 | 9.9 / 9.7 | 0 / 0 | | OpenVPN TCP + XOR | 53.4 / 54.9 | 58.4 / 58.8 | 43.2 / 44.7 | 41.5 / 41.3 | 10.0 / 9.6 | 0 / 0 | | OpenVPN TCP + Cloak | 77.3 / 78.0 | 71.5 / 69.8 | 71.5 / 72.6 | 58.4 / 56.6 | 123.7 / 90.6 | 0 / 0 | | OpenVPN UDP + Cloak (experimental) | 81.4 / 82.0 | 77.6 / 77.4 | 76.3 / 76.6 | 64.9 / 64.0 | 37.4 / 33.7 | 0 / 0 | | WireGuard + Cloak (experimental) | 81.9 / 83.2 | 73.7 / 75.9 | 47.6 / 51.0 | 36.8 / 41.1 | 25.2 / 61.5 | 0 / 0 | | Qeli 0.8.0 tcp-plain-raw + Recordizer | 72.7 / 81.6 | 70.8 / 72.5 | 62.8 / 70.6 | 47.5 / 49.5 | 117.5 / 93.6 | 0 / 0 | | Qeli 0.8.0 tcp-faketls + Recordizer | 74.1 / 82.1 | 69.6 / 70.9 | 64.1 / 70.4 | 46.0 / 48.5 | 118.5 / 94.1 | 0 / 0 | | Qeli 0.8.0 tcp-padding + Recordizer | 73.8 / 83.1 | 70.2 / 71.1 | 63.6 / 70.6 | 46.2 / 48.6 | 116.7 / 93.9 | 0 / 0 | | Qeli 0.8.0 tcp-frag + Recordizer | 76.0 / 82.7 | 71.3 / 71.0 | 65.6 / 71.2 | 47.8 / 49.2 | 117.4 / 94.1 | 0 / 0 | | Qeli 0.8.0 tcp-obfs + Recordizer | 71.5 / 80.1 | 67.5 / 71.8 | 61.9 / 70.5 | 48.3 / 52.3 | 120.4 / 97.7 | 0 / 0 | | Qeli 0.8.0 tcp-reality + Recordizer | 74.7 / 82.3 | 69.5 / 70.7 | 64.4 / 70.3 | 46.2 / 49.1 | 115.3 / 95.3 | 0 / 0 | | Qeli 0.8.0 tcp-reality-tls + Recordizer | 62.7 / 70.9 | 70.4 / 71.8 | 54.9 / 61.8 | 50.1 / 52.0 | 123.5 / 106.8 | 0 / 0 | | Qeli 0.8.0 udp-faketls + Recordizer | 71.7 / 78.5 | 65.7 / 67.5 | 64.8 / 70.3 | 49.7 / 52.2 | 160.9 / 53.0 | 0 / 0 | | Qeli 0.8.0 udp-padding + Recordizer | 72.1 / 79.4 | 68.0 / 70.2 | 65.3 / 71.1 | 51.4 / 54.6 | 170.9 / 51.8 | 0 / 0 | | Qeli 0.8.0 udp-quic + Recordizer | 71.8 / 79.6 | 66.6 / 68.4 | 64.7 / 70.9 | 50.1 / 52.6 | 168.7 / 51.5 | 0 / 0 | | Qeli 0.8.0 tcp-obfs-awg + Recordizer | 70.5 / 80.5 | 66.2 / 70.6 | 62.4 / 71.4 | 47.2 / 50.6 | 122.2 / 97.7 | 0 / 0 | | Qeli 0.8.0 udp-faketls-awg + Recordizer | 72.2 / 80.8 | 67.5 / 69.0 | 63.9 / 71.7 | 50.8 / 53.5 | 165.2 / 51.8 | 0 / 0 | CPU VM is the total load of the two-core VM. The table aggregates repeatable TCP `P=4` windows and UDP windows at the `rep1 ceiling`. VPN userspace CPU does not include the WireGuard/AWG kernel datapath; CPU VM is the primary metric for those modes. RSS combines the underlying VPN and its wrapper. `softnet drops` are summed across all TCP windows and UDP ceiling windows; zero does not rule out loss inside the tunnel protocol as reported by iperf. ## 8. Masking cost in matched pairs | Matched comparison | Control TCP P=1 rep1 avg | Masked TCP P=1 rep1 avg | Change | | --- | --- | --- | --- | | WireGuard: plain → wg-obfuscator STUN | 2888 | 515 | -82.2% | | AmneziaWG: mask-off → full 3.1 | 2988 | 2664 | -10.8% | | OpenVPN XOR UDP: patched control → XOR | 342 | 284 | -17.0% | | OpenVPN XOR TCP: patched control → XOR | 351 | 269 | -23.3% | | OpenVPN TCP: userspace → stunnel TLS | 358 | 415 | +15.9% | | Xray: VLESS TLS Vision → REALITY Vision | 1062 | 1053 | -0.9% | | Hysteria 2: QUIC TLS → Salamander | 1244 | 734 | -41.0% | The matched comparison uses only equivalent `rep1` TCP `P=1` windows across IPv4/IPv6 and upload/download. This preserves equal `n=1` for control and masked profiles; the CV of repeated TCP `P=4` is reported separately to show masked-mode stability. ## 9. Mode configurations ### 9.1. Common cryptography - OpenVPN userspace/XOR/Cloak: TLS 1.3, X25519, data cipher `CHACHA20-POLY1305`, `tun-mtu 1400`, `mssfix 1360`. XOR operates on top of normal AEAD protection; `cipher none` was not used. - OpenVPN DCO: the same negotiated cipher/TLS suite, with the kernel DCO datapath. - strongSwan: ChaCha20-Poly1305; the DTLS mode was excluded after a verified IPv4 preflight defect instead of being replaced with a fabricated number. - Xray: VLESS Vision through TUN; the TLS variant uses TLS 1.3/browser fingerprinting, while the REALITY variant uses `www.cloudflare.com:443`; both use TUN MTU 1400. - Hysteria 2: QUIC/TLS and QUIC+Salamander; the bandwidth limit was raised to **10 Gbit/s**, above the actual tunnel capacity of the environment. ### 9.2. OpenVPN-XOR and Cloak - XOR: OpenVPN 2.7.6 with the five patches from Tunnelblick commit `c9c73dca6c99afbba14b53e291b18f044210a1b5`; `scramble obfuscate`; DCO disabled. Every XOR row has a matched control using the same patched binary without `scramble`. - Cloak 2.12.0: `Transport=direct`, `BrowserSig=chrome`, `NumConn=4`, `EncryptionMethod=chacha20-poly1305`, `ServerName=RedirAddr=www.cloudflare.com`, `KeepAlive=0`, outer TCP/443. - OpenVPN UDP+Cloak and WireGuard+Cloak are marked experimental. The PCAP preflight verified that there was no direct UDP bypass: only four Cloak TCP connections to port 443 existed between `.11` and `.10`. - An unauthorized HTTPS probe of every Cloak arrangement received HTTP 200 from `RedirAddr`, not from the upstream VPN. ### 9.3. Qeli 0.8.0 and mandatory Recordizer All 12 Qeli profiles use `obf.recordizer.policy=required`. If Recordizer negotiation does not succeed, the connection must not proceed to measurement. Preflight confirmed activation in all 12 cases. - `obf.recordizer.policy = required` - `obf.recordizer.batch.delay_min_ms = 2` - `obf.recordizer.batch.delay_max_ms = 8` - `obf.recordizer.batch.max_packets = 16` - `obf.recordizer.batch.max_queue_bytes = 262144` - `obf.recordizer.record.max_payload_bytes = 0` - `obf.recordizer.record.small_min_ratio = 0.25` - `obf.recordizer.record.small_max_ratio = 0.875` - `obf.recordizer.record.full_probability = 0.72` - `obf.recordizer.fragment.enabled = true` - `obf.recordizer.fragment.reassembly_timeout_ms = 3000` - `obf.recordizer.fragment.max_inflight_packets = 64` - `obf.recordizer.fragment.max_reassembly_bytes = 4194304` - `obf.recordizer.fragment.max_fragments_per_packet = 64` Additional profile parameters: separate padding of 32–256 bytes with probability 0.8 when enabled; 15 s heartbeat; AWG `jc=4`, `jmin=40`, `jmax=200`; dual-stack pools `10.9.0.0/24 + fd42:206:1::/64` for TCP and `10.10.0.0/24 + fd42:206:2::/64` for UDP; TUN MTU 1400. Test credentials, identity keys, XOR/Cloak secrets, and the Qeli obfs key are not exported into the report. ### 9.4. WireGuard, AmneziaWG, strongSwan, Xray, and Hysteria 2 - WireGuard plain: MTU 1400, `PersistentKeepalive=25`. In the wg-obfuscator profile, inner WireGuard uses MTU 1380 and a local endpoint; the outer obfuscator uses UDP/443, client `masking=STUN`, server `masking=AUTO`, `allow-clean=false`, `max-dummy=4`, and `idle-timeout=300`. - AmneziaWG mask-off: MTU 1380, `Jc/Jmin/Jmax=0`, `S1..S4=0`, fixed `H1..H4=1..4`, `RandomTrailers=off`, `AdvancedSecurity=off`. Full 3.1: MTU 1360, `Jc=8`, `Jmin=40`, `Jmax=70`, `S1/S2/S3/S4=86/73/64/32`, configured nonstandard `H1..H4`, `HeaderProtectionKey`, `ContentPaddingAddition=16-64`, `RandomTrailers=on`, and `AdvancedSecurity=on`. - strongSwan: IKEv2, PSK, tunnel mode, `mobike=no`, with no reauthentication or rekeying during the test. IKE used `chacha20poly1305-prfsha256-curve25519` and ESP used `chacha20poly1305-curve25519`; ESP and NAT-T differ by `encap=no/yes`. - Xray: VLESS with `xtls-rprx-vision`, `raw` transport, TUN MTU 1400, and dual-stack routes. The TLS profile uses TLS 1.3 and the Chrome fingerprint; REALITY uses the Chrome fingerprint, target/SNI `www.cloudflare.com:443`, a short ID, and an X25519 keypair. Laboratory ports: 24443 for TLS and 24444 for REALITY. - Hysteria 2: TUN MTU 1400, QUIC, 8 MiB stream and 20 MiB connection windows, `maxIncomingStreams=1024`, PMTUD enabled, and a 10 s client keepalive. The profiles differ by the presence of Salamander; ports are 24445/24446. During preflight, the `up/down` limits were increased from 1 to 10 Gbit/s so a configuration limit would not restrict the measurement. The TLS client used a laboratory certificate with `insecure=true`; this is a test-environment setting, not a production recommendation. - All WG/AWG, Xray, Hysteria, and Qeli configurations routed the same control IPv4/IPv6 destinations. Secret keys and passwords are not included in the report. ## 10. PCAP/preflight and limits of DPI conclusions - All 19 new or changed profiles passed IPv4/IPv6 TCP/UDP smoke tests: OpenVPN-XOR (4), Cloak (3), Qeli Recordizer (12). - The Cloak PCAP contained only TCP/443; there was no direct UDP/11965 or UDP/51850 traffic between the VMs. - The first OpenVPN payload bytes in the patched control contained a recognizable original structure, while `scramble obfuscate` changed them; authentication and `CHACHA20-POLY1305` remained enabled. - H/B/T/A is a technical assessment of enabled mechanisms, not a probability of detection. A publishable claim that a mode “is not detected by DPI” would require independent classifiers, multiple networks, long-lived flows, and an active-probe corpus. This report can correctly state only which surfaces are masked and at what throughput/CPU cost. ### 10.1. Interpretation limits - Control modes have `n=1`; their run-to-run variance was not measured. Masked modes have `n=3` only for TCP `P=4` and UDP verification points; TCP `P=1` and UDP 600 belong to `rep1`. - For UDP, the reduced repeats checked the discovered rate and the first failed step, but did not search again for a lower sustainable ceiling. Therefore `pass, Tunnelblick XOR warning , Cloak , Xray , Hysteria , strongSwan .