نقل XHTTP في Xray: دليل الإعداد والمقارنة بين XHTTP وHTTP (2026)

الخلاصة

ما هو XHTTP في Xray، كيف يختلف عن HTTP وWS وgRPC، وكيف تضبطه على الخادم والعميل لتحصين أفضل ضد DPI. مع أمثلة تطبيقية.

لا تريد إعداد خادم بنفسك؟ احصل على خادم جاهز
نقل XHTTP في Xray: دليل الإعداد والمقارنة بين XHTTP وHTTP (2026)

مقدمة

نقل XHTTP في Xray أصبح سريعًا من أكثر الطرق العملية للتنكر في حركة البيانات كـ HTTP عادي وتجاوز فعال لأنظمة DPI الحديثة من 2024 حتى 2026. السبب بسيط: العديد من الشبكات تستمر في السماح بحركة HTTP(S) الكلاسيكية للحركة الشرعية، وXHTTP يقلد هذا الحوار بدون أعباء ثقيلة لبروتوكولات HTTP/2 أو WebSocket. في هذا الدليل، سنستعرض ما يعنيه XHTTP في سياق Xray، كيف يعمل داخليًا، كيف يختلف عن نقل HTTP العادي، نقدم خطط إعداد قوية مضادة لـ DPI، قوائم تحقق، نصائح للأداء والمراقبة، بالإضافة إلى الأخطاء الشائعة التي تؤدي إلى انقطاعات في الشبكات الواقعية. في النهاية، ستحصل على منهجية منظمة لتصميم، نشر، وصيانة XHTTP خصيصًا لسيناريوهاتك — بدءاً من الوصول المنزلي حتى المحيط المؤسسي والشبكات المتنقلة.

الأساسيات

ما هو Xray والنقل؟

Xray-core هو محرك وكيل عالي الأداء يقدم نموذجًا مرنًا من البروتوكول + النقل + التشفير. البروتوكولات على مستوى التطبيق (VLESS، VMess، Trojan، إلخ) تتولى المصادقة وتعدد الجلسات، بينما النقل (TCP، WebSocket، HTTP/2، gRPC، QUIC، XHTTP) يحدد كيف تنتقل البيانات عبر الشبكة وما هو أثرها الظاهري على أنظمة DPI والوسطاء. التشفير (TLS/XTLS/REALITY) وتقليد العميل (uTLS، بصمات JA3) تخفي المحتويات وتماثل ملفات تعريف TLS حقيقية لتتصرف مثل المتصفحات الحقيقية.

أين يقع XHTTP ضمن هذا الإطار؟

XHTTP هو وضع نقل يقلد سلوك حوار HTTP/1.1 الكلاسيكي ويدعم كلًا من TLS وTCP عادي (لا حاجة لمكافئات h2c). هدفه تقديم أكثر ملف DPI «طبيعي» ممكن: رؤوس، طرق، مسارات، استمرارية الاتصال، تشفير بنمط chunked، أنماط الترقية — وبعد المصافحة الشرعية، يتحول التيار إلى قناة ثنائية الاتجاه لبيانات البروكسي الحقيقية. من الخارج، يبدو كطلب/استجابة HTTP طويل العمر مع اتصال مباشر؛ داخليًا يعمل كقناة نقل لبيانات VLESS/VMess الخاصة بك.

لماذا ينجح ضد DPI؟

  • دلالات HTTP/1.1. معظم أنظمة DPI «تفهم» وتسمح بالرؤوس والطرق التقليدية (GET/POST/OPTIONS)، والترميزات (chunked)، والاتصالات المستمرة.
  • إطار أدنى. خلافًا لـ HTTP/2 وWebSocket، لا يقدم XHTTP إطارات أو رموز تشغيل واضحة، يحافظ على التيار كما لو كان جسم طلب POST أو ترقية اتصال. لهذه الأسباب يرى المفتشون هذا نمط «طبيعي».
  • تقليد مرن. يمكن تخصيص الرؤوس (User-Agent، Accept، Referer)، والمسارات، والمضيفين، وأكواد الاستجابة، وفواصل الإرسال حسب سلوكيات الخوادم الخلفية الحقيقية.

ماذا تقارن به: النقل HTTP العادي في Xray

يقدم Xray نقل HTTP (غالبًا HTTP/2 أو أوضاع مشابهة لـ h2c) مركزًا على الإطارات وتعدد التيارات ضمن HTTP/2. هذا الأسلوب مريح لكنه يترك بصمات واضحة (ALPN h2، ملفات تعريف HPACK، مقدمات محددة) ويتطلب تفاوضًا أعقد. XHTTP يتجنب الإشارات الواضحة لـ HTTP/2 وغالبًا مفضل في الشبكات «المقيدة» التي تسمح فقط بـ HTTP/1.1 «البسيط» فوق TLS 1.3، بينما تُشتبه أو تُمنع مقاطع HTTP/2/H3.

التفاصيل العميقة

بنية تيار XHTTP

  1. إقامة TLS/TCP. يقوم العميل بتأسيس اتصال TCP (أو TLS). عند استخدام TLS، تُفعل uTLS لتقليد متصفح حقيقي (JA3، SNI، ALPN — عادة http/1.1 وربما h2 للواقعية).
  2. طلب HTTP. يرسل العميل طلب HTTP/1.1 معقول: طريقة (غالبًا POST أو GET)، مسار (مثل /api، /health، /v1/upload)، رؤوس (Host، User-Agent، Accept، Accept-Language، Content-Type، Connection: keep-alive، TE: trailers، Cache-Control، X-Requested-With، إلخ). يمكن أن تكون الأنماط: «جسم POST طويل» أو تبادل «يشبه الترقية».
  3. استجابة الخادم. يرد الخادم برمز 200/204/101 (حسب النمط)، رؤوس ملائمة (Server: nginx، Date، Content-Type، Transfer-Encoding: chunked، Connection: keep-alive)، ثم يبقي الاتصال مفتوحًا.
  4. النفق. بعدها يبدأ الجانبان في تبادل بايتات بروتوكول Xray «المفيدة» مخبأة داخل جسم/chunks. بالنسبة لـ DPI، هذا اتصال HTTP حي بجسم/chunks مستمر.

الفروق الرئيسية بين XHTTP وHTTP/2 وWebSocket

  • لا إطارات واضحة على مستوى المتصفح. H2/H3 يكشفان عن طريق ALPN h2/h3، الأولويات، HPACK/QPACK. WS يظهر الترقية: websocket، رؤوس Sec-WebSocket-Key/Accept. XHTTP يستخدم رؤوس «عادية».
  • بصمات أقل. غالبًا ما تُدرب DPI على كشف WebSocket وملفات HPACK غير المعتادة. XHTTP يُدمج ضمن حزمة HTTP/1.1 القديمة والمعروفة.
  • أهداف كاذبة مرنة. يمكنه تقليد محمل، مرفّع، SSE طويل، أو نقطة نهاية API بطيئة بشكل مقنع.
  • اعتمادية في شبكات «صاخبة». معالجة HTTP/1.1 البسيطة والنمط chunked غالبًا ما تعمل بموثوقية خلف بروكسيات المؤسسات وNATs.

الأداء والاستهلاك

  • هدر الرؤوس: صغير لكن متوقع؛ تأثيره مهمل في الجلسات الطويلة.
  • زمن الاستجابة RTT: زمن انتقال إضافي واحد للطلب/الرد HTTP بعد مصافحة TLS، يقلل منه الاتصال المستمر والبيانات المبكرة (إن كانت مدعومة).
  • الإنتاجية: مشابهة لـ TCP+TLS العادي؛ الاختناقات هي البروكسي/الموازن ومساحات التخزين المؤقتة.

التوافق وALPN

عمليًا، تعيين ALPN إلى «http/1.1» يعطي الملف المحايد الأفضل. إذا كانت الشبكة تُطبق تفضيل h2، يمكن إضافة «h2» إلى القائمة، لكن يجب على الخادم التعامل معه بشكل صحيح؛ وإلا تؤدي المفاوضات إلى فشل إضافي. للمزيد من الواقعية، فعل uTLS لتقليد Chrome/Firefox الحديث.

القسم العملي 1: إعداد VLESS+XHTTP بسيط فوق TLS

الهدف

إعداد Xray مع بروتوكول VLESS ونقل XHTTP على المنفذ 443/tcp باستخدام شهادة صالحة. استضافة موقع عادي على نفس النطاق أو صفحة ثابتة؛ يذهب مرور البروكسي عبر مسار XHTTP.

الخطوات

  1. النطاق وDNS. ضبط سجلات A/AAAA تشير إلى VPS الخاص بك. تأكد من عدم وجود IP في قوائم الحظر المعروفة.
  2. الشهادة. تركيب certbot أو Caddy للتعامل التلقائي مع TLS. قلل ALPN غير الضروري إن لم تستخدم h2.
  3. Xray. تحديث إلى نسخة 2026 الحالية. تحقق من دعم بنية XHTTP.
  4. إعداد الخادم. إنشاء VLESS وارد مع streamSettings: network: xhttp، security: tls. ضع رؤوس ومسار معقول.
  5. إعداد العميل. استخدم نفس network: xhttp، serverName، والمسار/المضيف كالخادم. فعّل uTLS.
  6. الجدار الناري. فتح 443/tcp وحجب المنافذ غير الضرورية. تفعيل تحسينات conntrack.
  7. التحقق. تنفيذ curl -v https://your_domain/path — يجب أن تحصل على 200/204 حقيقي. تحقق لاحقًا من اتصال العميل والقياسات في السجلات.

معلمات مثال (موجز)

الخادم: البروتوكول: vless؛ العملاء: UUID؛ التشفير: none؛ streamSettings: network: xhttp؛ الأمان: tls؛ tlsSettings: serverName: your_domain؛ alpn: ["http/1.1"]; xhttpSettings: host: ["your_domain"], path: "/api", method: "POST", headers: {"User-Agent": ["Mozilla/5.0"], "Accept": ["* .related-articles { padding-top: 1rem; } .related-title { font-size: 1.75rem; font-weight: 700; color: var(--gray-900); margin-bottom: 1.5rem; padding-bottom: 0.75rem; border-bottom: 2px solid rgba(59,130,246,0.1); } .related-card { display: flex; flex-direction: column; gap: 0.5rem; height: 100%; background: white; border: 2px solid #e5e7eb; border-radius: 1rem; padding: 1.25rem 1.5rem; text-decoration: none; transition: all 0.3s cubic-bezier(0.4,0,0.2,1); box-shadow: 0 2px 8px rgba(0,0,0,0.04); } .related-card:hover { transform: translateY(-4px); box-shadow: 0 12px 24px rgba(59,130,246,0.15); border-color: var(--primary); } .related-card-title { font-size: 1.0625rem; font-weight: 600; color: var(--gray-900); line-height: 1.4; } .related-card-meta { font-size: 0.8125rem; color: #6b7280; display: flex; align-items: center; gap: 0.375rem; } .article-tldr { position: relative; margin: 0 0 2rem; padding: 1.25rem 1.5rem 1.25rem 1.75rem; background: linear-gradient(135deg, rgba(59,130,246,0.06), rgba(139,92,246,0.05)); border-start: 4px solid var(--primary); border-radius: 0.75rem; } .article-tldr-label { display: inline-block; font-size: 0.75rem; font-weight: 700; text-transform: uppercase; letter-spacing: 0.06em; color: var(--primary); margin-bottom: 0.4rem; } .article-tldr p { margin: 0; font-size: 1.0625rem; line-height: 1.6; color: #374151; font-weight: 500; } [data-bs-theme="dark"] .article-tldr { background: linear-gradient(135deg, rgba(59,130,246,0.10), rgba(139,92,246,0.10)); } [data-bs-theme="dark"] .article-tldr p { color: #e5e7eb; } [data-bs-theme="dark"] .article-tldr-label { color: #60a5fa; } .author-bio-extended { margin: 2rem 0; } .author-bio-card { background: linear-gradient(135deg, rgba(59,130,246,0.03), rgba(139,92,246,0.03)); border: 1px solid rgba(59,130,246,0.15); border-radius: 1.5rem; padding: 2rem; box-shadow: 0 4px 12px rgba(0,0,0,0.04); transition: all 0.3s; } .author-bio-card:hover { box-shadow: 0 8px 24px rgba(59,130,246,0.12); transform: translateY(-2px); } .author-bio-header { display: flex; align-items: center; gap: 1rem; margin-bottom: 1.5rem; padding-bottom: 1rem; border-bottom: 2px solid rgba(59,130,246,0.15); } .author-bio-icon { width: 48px; height: 48px; background: linear-gradient(135deg, var(--primary), var(--accent)); border-radius: 12px; display: flex; align-items: center; justify-content: center; box-shadow: 0 4px 12px rgba(59,130,246,0.3); } .author-bio-icon i { color: white; font-size: 1.25rem; } .author-bio-title { font-size: 1.5rem; font-weight: 700; color: var(--gray-900); margin: 0; } .author-bio-content { display: grid; grid-template-columns: 150px 1fr; gap: 2rem; align-items: start; } .author-photo-wrapper { position: relative; width: 150px; height: 150px; } .author-photo { width: 100%; height: 100%; object-fit: cover; border-radius: 1rem; border: 3px solid white; box-shadow: 0 8px 20px rgba(0,0,0,0.1); } .author-photo-badge { position: absolute; bottom: -8px; right: -8px; width: 36px; height: 36px; background: linear-gradient(135deg, var(--success), #059669); border-radius: 50%; display: flex; align-items: center; justify-content: center; border: 3px solid white; } .author-photo-badge i { color: white; font-size: 0.75rem; } .author-main-info { margin-bottom: 1rem; padding-bottom: 1rem; border-bottom: 1px solid rgba(0,0,0,0.08); } .author-name { font-size: 1.25rem; font-weight: 700; color: var(--gray-900); margin: 0 0 0.25rem; } .author-job { font-size: 0.9rem; color: var(--primary); margin: 0; font-weight: 500; } .author-info-list { display: flex; flex-direction: column; gap: 1rem; } .author-info-item { display: flex; gap: 1rem; align-items: flex-start; } .info-icon { width: 36px; height: 36px; min-width: 36px; background: rgba(59,130,246,0.08); border-radius: 8px; display: flex; align-items: center; justify-content: center; } .info-icon i { color: var(--primary); font-size: 0.875rem; } .info-content { font-size: 0.9rem; line-height: 1.5; } .info-content strong { display: block; font-size: 0.8rem; text-transform: uppercase; letter-spacing: 0.5px; color: #6b7280; margin-bottom: 0.25rem; } .expertise-tags { display: flex; flex-wrap: wrap; gap: 0.5rem; margin-top: 0.25rem; } .expertise-tag { padding: 0.25rem 0.75rem; background: rgba(59,130,246,0.08); color: var(--primary); border-radius: 1rem; font-size: 0.8rem; font-weight: 500; border: 1px solid rgba(59,130,246,0.15); } .achievements-list { margin: 0.25rem 0 0; padding-left: 1.25rem; } .achievements-list li { font-size: 0.9rem; margin-bottom: 0.25rem; } .author-bio-text { margin-top: 1rem; padding: 1rem; background: rgba(0,0,0,0.02); border-radius: 0.75rem; border-start: 3px solid var(--primary); } .author-bio-text p { margin: 0; font-size: 0.9rem; line-height: 1.6; color: #4b5563; } @media (max-width: 991px) { .article-content-card { padding: 2rem; } .article-title { font-size: 2rem !important; } .articleBody { font-size: 1rem; } .articleBody h2 { font-size: 1.75rem; } .articleBody h3 { font-size: 1.375rem; } } @media (max-width: 768px) { .article-content-card { padding: 1.5rem; border-radius: 1rem; } .article-title { font-size: 1.75rem !important; } .article-nav-title { font-size: 1rem; } .author-bio-content { grid-template-columns: 1fr; } .author-photo-wrapper { width: 100px; height: 100px; margin: 0 auto; } .info-icon { align-self: flex-start; } } [data-bs-theme="dark"] .article-search { background: #1f2937; border-color: rgba(255,255,255,0.1); color: #f9fafb; } [data-bs-theme="dark"] .article-search::placeholder { color: #9ca3af; } [data-bs-theme="dark"] .article-search:focus { border-color: var(--primary) !important; background: #1f2937; } [data-bs-theme="dark"] .article-content-card { background: #1f2937; border: 1px solid rgba(255,255,255,0.06); } [data-bs-theme="dark"] .article-title { color: #f9fafb !important; } [data-bs-theme="dark"] .article-meta { color: #9ca3af !important; } [data-bs-theme="dark"] .articleBody { color: #d1d5db; } [data-bs-theme="dark"] .articleBody h2, [data-bs-theme="dark"] .articleBody h3, [data-bs-theme="dark"] .articleBody h4 { color: #f9fafb; } [data-bs-theme="dark"] .articleBody a { color: #60a5fa; border-bottom-color: rgba(96,165,250,0.3); } [data-bs-theme="dark"] .articleBody a:hover { color: #93c5fd; border-bottom-color: #60a5fa; } [data-bs-theme="dark"] .articleBody blockquote { background: linear-gradient(135deg, rgba(59,130,246,0.1), rgba(139,92,246,0.1)); color: #d1d5db; } [data-bs-theme="dark"] .articleBody code { background: rgba(255,255,255,0.05); color: #f472b6; } [data-bs-theme="dark"] .articleBody pre { background: #111827; } [data-bs-theme="dark"] .article-nav-link { background: #1f2937; border-color: rgba(255,255,255,0.1); } [data-bs-theme="dark"] .article-nav-link:hover { border-color: rgba(59,130,246,0.5); } [data-bs-theme="dark"] .article-nav-direction { color: #60a5fa; } [data-bs-theme="dark"] .article-nav-title { color: #f9fafb; } [data-bs-theme="dark"] .author-bio-card { background: linear-gradient(135deg, rgba(59,130,246,0.08), rgba(139,92,246,0.08)); border-color: rgba(59,130,246,0.25); } [data-bs-theme="dark"] .author-bio-title, [data-bs-theme="dark"] .author-name { color: #f9fafb; } [data-bs-theme="dark"] .author-job { color: #60a5fa; } [data-bs-theme="dark"] .author-photo { border-color: #1f2937; } [data-bs-theme="dark"] .author-photo-badge { border-color: #1f2937; } [data-bs-theme="dark"] .author-main-info { border-bottom-color: rgba(255,255,255,0.1); } [data-bs-theme="dark"] .info-icon { background: linear-gradient(135deg, rgba(59,130,246,0.15), rgba(139,92,246,0.15)); } [data-bs-theme="dark"] .info-content { color: #d1d5db; } [data-bs-theme="dark"] .info-content strong { color: #f9fafb; } [data-bs-theme="dark"] .expertise-tag { background: linear-gradient(135deg, rgba(59,130,246,0.15), rgba(139,92,246,0.15)); color: #60a5fa; border-color: rgba(59,130,246,0.3); } [data-bs-theme="dark"] .author-bio-text { background: rgba(255,255,255,0.03); border-start-color: #60a5fa; } [data-bs-theme="dark"] .author-bio-text p { color: #d1d5db; } [data-bs-theme="dark"] .article-share-section h4 { color: #f9fafb; } [data-bs-theme="dark"] .related-title { color: #f9fafb; border-bottom-color: rgba(96,165,250,0.2); } [data-bs-theme="dark"] .related-card { background: #1f2937; border-color: rgba(255,255,255,0.1); } [data-bs-theme="dark"] .related-card:hover { border-color: rgba(59,130,246,0.5); } [data-bs-theme="dark"] .related-card-title { color: #f9fafb; } [data-bs-theme="dark"] .related-card-meta { color: #9ca3af; } body { background: #0A0E14 !important; } .breadcrumb { background: transparent !important; } .breadcrumb-item a { color: #8a94a6; } .breadcrumb-item.active { color: #6B7689 !important; } .breadcrumb-item + .breadcrumb-item::before { color: #4a5260 !important; } .article-content-card { background: transparent !important; border: 0 !important; box-shadow: none !important; } .article-title { color: #F5F6F7 !important; } .article-meta { color: #8a94a6 !important; } .article-meta i { color: #19E3B1 !important; } .article-search { background: #11161F !important; border: 1px solid rgba(245,246,247,.12) !important; color: #F5F6F7 !important; } .article-search::placeholder { color: #6B7689 !important; } .articleBody { color: #C5CAD3 !important; } .articleBody h2, .articleBody h3, .articleBody h4 { color: #F5F6F7 !important; } .articleBody h2 { border-bottom-color: rgba(245,246,247,.10) !important; } .articleBody a { color: #19E3B1 !important; border-bottom-color: rgba(25,227,177,.35) !important; } .articleBody a:hover { color: #3BEBC0 !important; border-bottom-color: #3BEBC0 !important; } .articleBody ul li::marker { color: #19E3B1 !important; } .articleBody blockquote { background: rgba(25,227,177,.05) !important; border-start-color: #19E3B1 !important; color: #aeb6c2 !important; } .articleBody code { background: rgba(25,227,177,.12) !important; color: #3BEBC0 !important; } .articleBody pre { background: #11161F !important; border: 1px solid rgba(245,246,247,.08) !important; color: #c2c9d4 !important; } .articleBody pre code { color: #c2c9d4 !important; } .articleBody img { box-shadow: 0 10px 34px rgba(0,0,0,.5) !important; } .article-tldr { background: rgba(25,227,177,.07) !important; border: 1px solid rgba(25,227,177,.22) !important; border-start: 3px solid #19E3B1 !important; } .article-tldr-label { color: #19E3B1 !important; } .article-tldr p { color: #c2c9d4 !important; } .article-share-section h4 { color: #F5F6F7 !important; } .article-nav-link, .related-card { background: #1A2230 !important; border: 1px solid rgba(245,246,247,.08) !important; box-shadow: none !important; } .article-nav-link:hover, .related-card:hover { border-color: rgba(25,227,177,.35) !important; box-shadow: 0 16px 40px -16px rgba(0,0,0,.6) !important; } .article-nav-direction { color: #19E3B1 !important; } .article-nav-title, .related-card-title, .related-title { color: #F5F6F7 !important; } .related-title { border-bottom-color: rgba(245,246,247,.10) !important; } .related-card-meta { color: #6B7689 !important; } .related-card-meta i { color: #19E3B1 !important; } .author-bio-card { background: #11161F !important; border-color: rgba(245,246,247,.08) !important; } .author-bio-header { border-bottom-color: rgba(245,246,247,.10) !important; } .author-bio-title, .author-name { color: #F5F6F7 !important; } .author-job { color: #19E3B1 !important; } .author-bio-icon { background: #19E3B1 !important; } .author-bio-icon i { color: #0A0E14 !important; } .author-main-info { border-bottom-color: rgba(245,246,247,.08) !important; } .author-photo { border-color: #1A2230 !important; } .info-icon { background: rgba(25,227,177,.12) !important; } .info-icon i { color: #19E3B1 !important; } .info-content { color: #c2c9d4 !important; } .info-content strong { color: #8a94a6 !important; } .expertise-tag { background: rgba(25,227,177,.10) !important; color: #19E3B1 !important; border-color: rgba(25,227,177,.22) !important; } .author-bio-text { background: rgba(255,255,255,.03) !important; border-start-color: #19E3B1 !important; } .author-bio-text p, .achievements-list li, .author-bio-content { color: #aeb6c2 !important; }