AetherST Tunnel
Advanced, high-performance censorship circumvention client for Android and Windows. Bypass Deep Packet Inspection with MASQUE, WireGuard, and Gool protocols.
What is AetherST?
Production-grade tunnel client
AetherST Tunnel is a high-performance VPN and proxy client built on the battle-tested Aether core engine. It combines the power of Cloudflare WARP with advanced tunnel protocols to provide stable, secure connectivity in the most restricted network environments.
Stealth Protocols
MASQUE, WireGuard, Gool with advanced DPI bypass
Multi-Platform
Android & Windows with unified UI
High Performance
Low latency, high throughput, zero-copy
Zero Trust
Enterprise Cloudflare Gateway support
Android App Guide
Complete guide to installing, configuring, and using AetherST on Android.
1 Installation
Download the APK
Go to the Releases page and download the APK matching your device architecture.
aetherst-v1.5.6-arm64-v8a.apk
arm64-v8a is recommended for most modern devices. Use armeabi-v7a for older devices.
Install the APK
Open the downloaded APK file. Your device may ask to allow installation from unknown sources — this is normal for sideloaded apps.
- 1. Tap the downloaded file
- 2. Enable "Install from unknown sources" if prompted
- 3. Tap "Install" and wait for completion
Grant Permissions
The app will request VPN permission on first launch. This is required for the tunnel to work. Tap "Allow" when prompted.
2 First Launch
Initial Setup Wizard
On first launch, AetherST walks you through a quick setup:
- 1Protocol Selection — Choose between MASQUE, WireGuard, or Gool. If unsure, select MASQUE (recommended).
- 2Obfuscation Profile — Select a noise level. Start with the default (balanced). Increase if connections fail.
- 3Scan Mode — Choose how aggressively to search for endpoints. "Balanced" works in most cases.
Connect
Tap the large connect button on the main screen. The app will:
- Scan for the best Cloudflare endpoint
- Establish an encrypted tunnel
- Verify the connection with a data-plane check
- Show "Connected" status when ready
Tip: The first connection may take 10-30 seconds while the app scans for endpoints. Subsequent connections are faster if you enable "Quick Reconnect".
3 Dashboard Overview
Connection Status
Shows Connected/Disconnected with real-time data stats (upload/download speed, total data transferred).
Protocol Info
Displays active protocol (MASQUE/WireGuard/Gool), carrier (H3/H2), and current obfuscation profile.
Endpoint Details
Shows the connected Cloudflare edge IP, latency, and scan mode used.
IP Lookup
Built-in tool to check your public IP and confirm traffic is routing through the tunnel.
4 Settings Reference
Protocol Settings
Protocol
MASQUE (default), WireGuard, or Gool. MASQUE is recommended for most networks as it looks like regular HTTPS traffic.
Carrier (MASQUE only)
H3 (HTTP/3 over QUIC, default) or H2 (HTTP/2 over TCP). Switch to H2 if UDP is blocked.
Obfuscation Profile
Firewall (default for MASQUE), GFW, Off for MASQUE. Balanced (default), Aggressive, Light, Off for WireGuard/Gool.
Scan Mode
Turbo (fastest), Balanced (default), Thorough (best quality), Stealth (quietest), Ironclad (most reliable).
ClientHello Fragmentation (H2 only)
Splits the TLS ClientHello into chunks. Helps bypass DPI that reads the SNI from a single packet. Off by default.
Connection Settings
Quick Reconnect
When enabled, automatically reconnects to the last known-good endpoint without rescanning. Faster reconnection.
IPv4 / IPv6 / Dual
Which IP version to scan for. IPv4 is safest if your network has no IPv6 support.
Custom Endpoint
Manually set a Cloudflare edge IP:port to skip scanning entirely. Use when you know a working address.
Advanced Settings
DNS
Custom DNS resolvers used inside the tunnel. Defaults to Cloudflare DNS (1.1.1.1).
Keepalive (WireGuard/Gool)
Interval in seconds for keepalive packets. Default is 5. Helps maintain connections through NAT.
Zero Trust (Team)
Enroll as a managed device on your Cloudflare Zero Trust account. Requires team name and authentication method.
Routing Rules
Block or direct specific traffic. Block refuses connections; Direct bypasses the tunnel for domestic sites and LAN.
Upstream Proxy
Route all Aether traffic through another proxy (SOCKS5 or HTTP). For chaining behind an existing VPN.
Log Level
Set verbosity from Error to Trace. Use Trace for debugging connection issues.
5 Troubleshooting
Connection fails immediately
Try switching protocol. Start with MASQUE, then try WireGuard. If both fail, enable Gool mode. Also try increasing the obfuscation level.
Connected but no internet
This usually means the gateway passes handshake but drops data. The app should detect this automatically and try another endpoint. If it persists, change the scan mode to "Thorough".
Battery drain
If using WireGuard, lower the keepalive interval. MASQUE with H3 is generally more battery-efficient than H2.
Slow speeds
Switch from Gool to single-layer WireGuard. If on H2 and UDP is available, try H3. Check if "Quick Reconnect" is enabled to avoid slow rescans.
Windows App Guide
Complete guide to installing, configuring, and using AetherST on Windows.
1 Installation
Download the Installer
Go to the Releases page and download the Windows installer.
AetherST-Setup-1.0.2.exe
Run the Installer
- 1. Double-click the downloaded .exe file
- 2. Click "Yes" on the UAC prompt if it appears
- 3. Follow the installation wizard
- 4. A shortcut will be created on your desktop
Note: Windows may flag the installer as unrecognized. Click "More info" then "Run anyway". This is common for new software without a code-signing certificate.
2 First Launch
Setup Wizard
The first time you run AetherST, it will guide you through configuration:
- 1Choose Protocol — MASQUE is recommended for most networks. It disguises traffic as HTTPS.
- 2Select Obfuscation — Start with the default profile. Increase if the connection is blocked.
- 3Pick Scan Mode — Balanced is the default and works well in most environments.
Connect
Click the Connect button. The app will scan for endpoints and establish the tunnel.
Status indicators:
- Disconnected — Not connected
- Connecting — Scanning and establishing tunnel
- Connected — Tunnel is active and verified
3 Interface Overview
Main Dashboard
Large connect/disconnect button, status indicator, real-time speed and data counters.
Protocol Panel
Quick switching between MASQUE, WireGuard, and Gool. Shows current carrier and obfuscation profile.
Endpoint Info
Connected server IP, location, latency, and scan mode. Copy endpoint for sharing.
System Tray
Minimize to system tray. Quick connect/disconnect from tray icon context menu.
4 Settings Reference
Protocol Settings
Protocol
MASQUE (default), WireGuard, or Gool. Choose based on your network conditions.
Carrier
H3 (default, QUIC/UDP) or H2 (TCP). H2 survives networks that block UDP.
Obfuscation
Adjust based on network strictness. Higher levels = more stealth but slightly more overhead.
Scan Mode
Turbo for speed, Balanced for general use, Thorough for hostile networks, Ironclad for reliability.
System Settings
Auto-start
Launch AetherST when Windows starts. Useful for always-on connectivity.
Minimize to Tray
Keep running in the system tray when the window is closed. Quick access from tray icon.
Quick Reconnect
Reuse the last working endpoint without rescanning. Faster reconnection on startup.
Advanced Settings
DNS
Custom resolvers for the tunnel. Defaults to Cloudflare (1.1.1.1).
Zero Trust
Configure Cloudflare Zero Trust team authentication for enterprise networks.
Routing
Block or direct specific traffic patterns. Useful for excluding banking apps or LAN services.
Upstream Proxy
Chain through another proxy. Supports SOCKS5 and HTTP CONNECT.
5 Troubleshooting
Windows Defender blocks the app
Click "More info" then "Run anyway". The app is safe but lacks a code-signing certificate. You can add an exclusion in Windows Security if needed.
No network after connecting
The gateway may be passing handshake but dropping data. The app should auto-detect this. If not, try switching to a different protocol or increasing the scan mode.
Firewall warnings
Allow AetherST through Windows Firewall when prompted. Both private and public network access may be needed.
Slow scan on startup
Enable "Quick Reconnect" in settings. If the scan still takes too long, switch to "Turbo" mode or set a custom endpoint.
Aether Core
Deep technical reference for the Aether engine that powers AetherST.
What Aether Does
Aether is a user-space proxy client for Cloudflare WARP. It builds a tunnel out of a filtered network and exposes a local SOCKS5 proxy on 127.0.0.1:1819. Point a browser, a terminal, or a system proxy at that address and the traffic leaves through the tunnel.
It needs no root and installs no network driver. Everything happens inside the process: the tunnel, a user-space TCP/IP stack, and the proxy.
Running Aether
aether
aether --masque --scan balanced
aether --wg --noize aggressive --bind 127.0.0.1:1080
Run with no arguments for interactive prompts, or pass flags to skip them. Every flag also has an environment variable equivalent.
Verify:
curl -x socks5h://127.0.0.1:1819 https://www.cloudflare.com/cdn-cgi/trace
Look for warp=on in the response.
Transports
| Transport | Flag | Carrier |
|---|---|---|
| MASQUE | --masque (default) | QUIC/HTTP-3 on UDP 443, or HTTP/2 on TCP 443 |
| WireGuard | --wg | WireGuard on UDP 2408 |
| Gool | --gool | WireGuard inside WireGuard |
Endpoint Scanning
Aether does not ship a fixed address. It sweeps Cloudflare edge ranges, verifies candidates with real data-plane checks, and keeps the best one.
| Mode | Behavior |
|---|---|
| turbo | Stops at the first candidate that answers |
| balanced | Default. Collects a few and keeps the fastest |
| thorough | Sweeps whole ranges, best for blocked networks |
| stealth | Few probes in flight, for networks that notice scanning |
| ironclad | Full tunnel and a real HTTP request per candidate |
Obfuscation Profiles
MASQUE
- firewall (default) — Balanced, recommended for most restricted networks
- gfw — Heavier, try when firewall does not work
- off — No obfuscation, for open networks
WireGuard / Gool
- balanced (default) — Sweet spot between stealth and speed
- aggressive — Heaviest, for very strict networks
- light — Minimal, least overhead
- off — No obfuscation
H2 vs H3 in MASQUE
HTTP/3 (H3) — Default
- + Runs on QUIC over UDP
- + Faster handshake, fewer round trips
- + Packet loss does not stall connection
HTTP/2 (H2) — Fallback
- + Runs on TLS/TCP 443
- + Looks like ordinary web traffic
- + Survives QUIC/UDP blocking
- + Supports ClientHello fragmentation
Rule of thumb: Try H3 first. If UDP/QUIC is blocked, switch to H2. If H2 gets blocked, enable --fragment.
Routing Rules
Two lists control traffic. Block is checked first, then direct, otherwise the tunnel is used.
| Entry | Matches |
|---|---|
| example.com | The name and every subdomain |
| full:example.com | That exact name only |
| keyword:doubleclick | Any name containing it |
| regexp:^ad[0-9]+ | A regular expression |
| 10.0.0.0/8 | A network or bare address |
| port:25 | A port or range |
| private | LAN, loopback and CGNAT space |
Identity Files
| File | Contents |
|---|---|
| aether.toml | WireGuard identity |
| aether-masque.toml | MASQUE identity and certificate |
| aether-team-<name>.toml | One identity per Zero Trust team |
| aether-*-lastconn.toml | Last working endpoint cache |
Keep these files. Deleting them registers a new device.
Environment Variables
Every flag maps to an environment variable. Flags win when both are set.
AETHER_SOCKSSOCKS5 listen address
AETHER_PROTOCOLmasque, wg, or gool
AETHER_SCANScan mode
AETHER_NOIZEObfuscation profile
AETHER_MASQUE_HTTP2Use H2 carrier
AETHER_MASQUE_H2_FRAGMENTFragment TLS ClientHello
AETHER_QUICK_RECONNECTReuse last endpoint
AETHER_WG_KEEPALIVEWireGuard keepalive interval
AETHER_TEAMZero Trust team name
AETHER_UPSTREAMUpstream proxy address
AETHER_ROUTE_BLOCKBlock routing rules
AETHER_ROUTE_DIRECTDirect routing rules
Examples
MASQUE on H2 for UDP-blocked networks
AETHER_PROTOCOL=masque AETHER_MASQUE_HTTP2=1 AETHER_NOIZE=firewall aetherWireGuard on strict network
AETHER_PROTOCOL=wg AETHER_NOIZE=aggressive AETHER_SCAN=thorough aetherDocker
docker run -it -p 127.0.0.1:1819:1819 -v aether-data:/data \
-e AETHER_PROTOCOL=masque ghcr.io/cluvexstudio/aether:latestTroubleshooting
Does not connect
Switch protocol. If MASQUE failed on H3, try H2. If H2 gets blocked, try --fragment. If nothing works, try WireGuard or Gool.
Connects but nothing loads
Gateway silently drops data. Aether auto-detects this. Use --no-data-check to override.
Keeps dropping
Increase the obfuscation profile one step.
Slow
If on Gool, try single-layer WireGuard. If on H2 and UDP is open, try H3.
Configuration Reference
Complete reference of all environment variables and flags.
AETHER_SOCKSSOCKS5 address. Default: 127.0.0.1:1819
AETHER_HTTP_PROXYHTTP CONNECT address
AETHER_PROTOCOLmasque, wg, gool
AETHER_SCANturbo, balanced, thorough, stealth, ironclad
AETHER_NOIZEObfuscation profile
AETHER_IP4, 6, dual
AETHER_DNSTunnel DNS resolvers
AETHER_LOG_LEVELerror to trace
AETHER_MASQUE_HTTP2H2 carrier. Values: 1, true, h2, yes, on
AETHER_MASQUE_H2_PEERManual H2 destination
AETHER_MASQUE_H2_FRAGMENTFragment TLS ClientHello
AETHER_MASQUE_H2_FRAGMENT_SIZEChunk size. Default: 16-32
AETHER_MASQUE_H2_FRAGMENT_DELAYDelay in ms. Default: 2-10
AETHER_MASQUE_NO_DATA_CHECKSkip data-plane probe
AETHER_MASQUE_VALIDATE_SECSProbe timeout. Default: 10s
AETHER_MASQUE_STARTUP_SECSStartup deadline. Default: 30s
AETHER_MASQUE_RECONNECT_SECSReconnect delay. Default: 2s
AETHER_WG_KEEPALIVEKeepalive seconds. Default: 5
AETHER_WG_NO_DATA_CHECKSkip data verification
AETHER_WG_NO_PROFILE_RETRYDo not retry profiles
AETHER_WG_RECONNECT_SECSReconnect delay. Default: 2s
AETHER_WG_ENDPOINT_COOLDOWN_SECSCooldown. Default: 300s
AETHER_TEAMZero Trust team name
AETHER_ACCESS_EMAILEmail auth
AETHER_ACCESS_CLIENT_IDService token ID
AETHER_ACCESS_CLIENT_SECRETService token secret
AETHER_ACCESS_TOKENExisting JWT token
AETHER_GATEWAYRoute through org gateway
AETHER_UPSTREAMUpstream proxy
AETHER_REPROVISIONReplace refused identity
AETHER_QUICK_RECONNECTReuse last gateway
AETHER_ROUTE_BLOCKBlock rules
AETHER_ROUTE_DIRECTDirect rules
AETHER_ROUTES_FILERoute config file
AETHER_ROUTE_SNIFFRead name from bytes. Default: on
AETHER_CONFIGConfig file path
AETHER_TLS_GROUPSTLS key-share groups