Independent hosting operator since 2014 · New York · Dallas · Amsterdam Status Looking Glass Contact
D4 NetworksD4 Networks
Client area ↗ Deploy a server
Home / Resources / Set up Hysteria2 as a second endpoint

Tutorials

Set up Hysteria2 as a second endpoint

Oct 11, 2026 · 7 min read

Hysteria2 is a proxy built on QUIC, the protocol behind HTTP/3, so it runs over UDP and answers strangers like a normal HTTP/3 website. This guide sets it up as a second endpoint next to VLESS and REALITY, on a VPS set up as in the first ten minutes on a new VPS.

1. Point a domain at the server

Hysteria2 gets its own certificate, so it needs a domain. Create an A record for the server's IPv4 address and an AAAA record for its IPv6 address, for example hy.example.com.

2. Install Hysteria2

ssh session
$ sudo bash -c "$(curl -fsSL https://get.hy2.sh/)"
$ openssl rand -hex 16

The script installs /usr/local/bin/hysteria and a sample /etc/hysteria/config.yaml, and creates a hysteria user for the service. It does not start anything. The random hex is your password. This guide was tested with Hysteria v2.13.0; run the same command later to update.

3. Open the ports

Hysteria2 asks Let's Encrypt for a certificate through TCP port 80, now and at every renewal. Clients connect on UDP port 443. If you run neither ufw nor firewalld, skip this step.

Ubuntu and Debian
$ sudo ufw allow 80/tcp
$ sudo ufw allow 443/udp
RHEL-based
$ sudo firewall-cmd --get-active-zones
$ zone=public
$ sudo firewall-cmd --permanent --zone="$zone" --add-port=80/tcp
$ sudo firewall-cmd --permanent --zone="$zone" --add-port=443/udp
$ sudo firewall-cmd --reload

For firewalld, replace public with the zone the first command shows.

4. Write the server config

Replace the sample file with this:

/etc/hysteria/config.yaml
listen: :443

acme:
  type: http
  domains:
    - hy.example.com
  email: you@example.com

auth:
  type: password
  password: YOUR-PASSWORD

masquerade:
  type: proxy
  proxy:
    url: https://www.example.com/
    rewriteHost: true

type: http makes Hysteria2 get and renew the certificate through port 80 by itself. Without it, Hysteria2 also tries TCP 443, which REALITY already uses. The masquerade block shows anyone without the password the real website at url, so pick a real site.

The script leaves the config readable by every user on the server, and it holds your password. Fix that, then start the service:

ssh session
$ sudo chgrp hysteria /etc/hysteria/config.yaml
$ sudo chmod 640 /etc/hysteria/config.yaml
$ sudo systemctl enable --now hysteria-server
$ sudo journalctl -u hysteria-server -n 20

The log should show certificate obtained successfully and server up and running. REALITY uses TCP 443 and Hysteria2 uses UDP 443, so both run on one server.

5. Connect a client

share link
hysteria2://YOUR-PASSWORD@hy.example.com:443/?sni=hy.example.com#MyVPS

In v2rayNG, copy the link, tap +, then Import from Clipboard. Tap the new entry to select it, then tap the connect button and allow the VPN request.

Treat the link like a password

It holds everything needed to use your server. Do not post it publicly.

6. Hide the protocol with Salamander

The masquerade answers people who connect to the server, but QUIC also carries your domain name in its first packet. A USENIX Security 2025 paper found that since April 2024 the Great Firewall of China decrypts the first QUIC packet to read the domain name. When that name is on its blocklist, it drops the connection's packets for 180 seconds. Since v2.6.2, Hysteria2 splits that information across packets, and the paper found the firewall does not put split packets back together. Salamander goes further: it scrambles every packet with a second password, so the traffic no longer looks like QUIC. The cost is that the server stops answering as a website. Add this to the server config and restart:

/etc/hysteria/config.yaml
obfs:
  type: salamander
  salamander:
    password: YOUR-OBFS-PASSWORD

Then add &obfs=salamander&obfs-password=YOUR-OBFS-PASSWORD to the link, before the #. Neither setup is guaranteed to stay reachable from China.

7. When it does not connect

  • If the client shows authentication error, HTTP status code: 404, the password differs.
  • If the client waits and never connects, the Salamander setting differs between server and link, or UDP 443 is blocked.
  • If the log never shows certificate obtained successfully, check the DNS records and TCP port 80.

Quick reference

TaskCommand
Install or updatesudo bash -c "$(curl -fsSL https://get.hy2.sh/)"
New passwordopenssl rand -hex 16
Apply a config changesudo systemctl restart hysteria-server
Logssudo journalctl -u hysteria-server -n 20
Check it runs on UDPsudo ss -lnup (look for 443)

Where to go next

Hysteria2 uses UDP and REALITY uses TCP, so if a network blocks one, the other may still work. Turn on BBR from the REALITY guide for the TCP side. Before you order, use the Looking Glass to test the route from your network to each location.

hysteria2 hysteria quic udp proxy ubuntu debian almalinux

Related articles