Skip to main content

All Nodes

This page is a quick inventory of the public configurable WaterWall nodes found in the current source tree. Use the dedicated node page for exact settings, lifecycle behavior, and examples.

Basic Reading Guide

  • Listener and device nodes usually sit at the edge of a chain and create or receive traffic.
  • Connector nodes usually sit at the outbound edge and connect to an external endpoint.
  • Packet nodes carry raw IP packets or datagram-like packet buffers, not ordinary TCP byte streams.
  • Bridge nodes cross between packet and stream models or between separate chain branches.
  • Most Client / Server protocol pairs must be configured on opposite sides of the path.

Public Configurable Nodes

NodeMain useCommon placement
AuthenticationClientAttaches authenticated user identity or credentials for authentication-aware server-side nodes.Before an authentication-aware server/protocol node.
AuthenticationServerAuthenticates incoming identities and controls accepted users.Server-side chain before protected traffic.
Bgp4ClientClient side of the BGP4-style tunnel pair.Paired with Bgp4Server.
Bgp4ServerServer side of the BGP4-style tunnel pair.Paired with Bgp4Client.
BlackHoleTerminal sink adapter that drops payload or rejects traffic for blocking and tests.End of a policy/test chain.
BridgeConnects two independent chain branches inside one config.Usually used as a named pair/branch join.
ConnectionFisherClientOpens or races multiple client-side paths and keeps the useful connection.Paired with ConnectionFisherServer.
ConnectionFisherServerServer side for ConnectionFisher paths.Paired with ConnectionFisherClient.
DisturberSimulates loss, delay, or corruption for testing.Test chains.
DomainResolverAdvanced support node that resolves dest_ctx domains before forwarding Init.Usually created internally by connector/router/client nodes.
EncryptionClientClient-side AEAD framing/encryption.Paired with EncryptionServer.
EncryptionServerServer-side AEAD framing/decryption.Paired with EncryptionClient.
HalfDuplexClientSplits or coordinates half-duplex upload/download behavior.Paired with HalfDuplexServer.
HalfDuplexServerServer side of the half-duplex tunnel pair.Paired with HalfDuplexClient.
HeaderClientPrepends a one-time WaterWall port header or IPv4 PROXY protocol header.Paired with HeaderServer for WaterWall headers, HeaderServer PROXY source mode, or before a PROXY-aware backend.
HeaderServerConsumes a WaterWall port header, reads IPv4 PROXY source fields, or applies a constant destination port.Paired with HeaderClient or placed behind a trusted PROXY sender.
HttpClientWraps payload in HTTP, HTTP/2, h2c, custom upgrade, split HTTP, or WebSocket client framing.Before TlsClient for HTTPS, or before a transport node for cleartext HTTP.
HttpServerParses HTTP/WebSocket server-side framing and forwards body payload.After TlsServer for HTTPS, or after a listener for cleartext HTTP.
IpManipulatorApplies packet-level TCP/TLS/SNI manipulation tricks.Packet chains.
IpOverriderRewrites source/destination IP or port fields in packet traffic.Packet chains.
JunkDatagramSenderSends extra datagrams according to configured modules/policies.Packet or UDP-oriented evasion/test paths.
KeepAliveClientSends keepalive/heartbeat data to detect broken paths.Paired with KeepAliveServer.
KeepAliveServerServer side of keepalive/heartbeat handling.Paired with KeepAliveClient.
LoggerTunnelLogs or dumps payload without modifying chain behavior.Anywhere suitable for debugging.
MuxClientMultiplexes many logical lines over shared transport connections.Paired with MuxServer.
MuxServerDemultiplexes logical lines from MuxClient.Paired with MuxClient.
ObfuscatorClientClient-side lightweight payload obfuscation.Paired with ObfuscatorServer.
ObfuscatorServerServer-side deobfuscation/obfuscation counterpart.Paired with ObfuscatorClient.
PacketReceiverReceives packet traffic for source-IP discovery in restricted environments.Packet/IP discovery chains.
PacketSenderSends packet traffic for source-IP discovery or packet-path tests.Packet/IP discovery chains.
PacketSplitStreamSplits mixed packet/stream behavior across packet and stream sides.Packet/stream boundary chains.
PacketsToConnectionConverts packet traffic through lwIP into normal WaterWall connection lines.Packet-to-stream bridge.
PacketsToStreamCarries raw IPv4 packet boundaries over a stream-facing line.Paired with StreamToPackets.
PingClientEncapsulates packet payload into IPv4 ICMP-style traffic.Packet chains, paired with PingServer.
PingServerDecapsulates the packet payload from the Ping tunnel direction.Packet chains, paired with PingClient.
RawSocketSends and receives raw IP packets.Packet edge.
RealityClientPerforms a visitor TLS handshake, then sends Reality-authenticated payload in TLS-like records.Client side, before a transport to RealityServer.
RealityServerRoutes ordinary visitor traffic to a destination and switches authenticated Reality clients to protected next.Server side after a listener.
ReverseClientBuilds the client side of a reverse tunnel for NAT/firewall traversal.Paired with ReverseServer.
ReverseServerServer side of reverse tunnel coordination.Paired with ReverseClient.
RouterRoutes lines by context, filters, or rule branches.Middle of complex chains.
SniffRouterRoutes by sniffed traffic metadata.Middle of sniffing/routing chains.
Socks5ClientSpeaks to an upstream SOCKS5 server.Before a transport/proxy destination.
Socks5ServerAccepts SOCKS5 client requests and forwards accepted traffic.After a listener or TLS/protocol wrapper.
SoftIpLimiterLimits how many source IPs may concurrently use the same early VLESS UUID or Trojan SHA224 identity.Before VlessServer or TrojanServer, after any TLS/protocol wrapper.
SpeedLimitApplies throughput limiting.Middle of a chain.
SpeedTestClientGenerates speed-test traffic.Test chains, paired with SpeedTestServer.
SpeedTestServerResponds to speed-test traffic.Test chains, paired with SpeedTestClient.
StreamToPacketsReconstructs IPv4 packets from a stream-facing line.Paired with PacketsToStream.
TcpConnectorOpens outbound TCP connections.Chain end.
TcpListenerAccepts inbound TCP connections and creates normal lines.Chain head.
TcpOverUdpClientCarries stream-like TCP data over UDP-style packet transport.Paired with TcpOverUdpServer.
TcpOverUdpServerServer side of TCP-over-UDP handling.Paired with TcpOverUdpClient.
TcpUdpConnectorCombines TCP and UDP connector behavior behind one node.Chain end for mixed TCP/UDP routing.
TcpUdpListenerCombines TCP and UDP listener behavior behind one node.Chain head for mixed TCP/UDP entry.
TesterClientGenerates deterministic validation traffic and verifies responses.Test chain head.
TesterServerResponds to deterministic tester traffic.Test chain end.
TlsClientPerforms real client-side TLS and carries encrypted TLS records.Before TcpConnector or another transport.
TlsServerPerforms real server-side TLS termination.After TcpListener and before cleartext protocol nodes.
TrojanClientWrites Trojan client request/auth framing.Paired with TrojanServer, usually inside TLS.
TrojanServerParses and authenticates Trojan client traffic.Paired with TrojanClient, usually inside TLS.
TunDeviceReads and writes packets through an operating-system TUN device.Packet edge.
UdpConnectorSends outbound UDP traffic, with optional destination selection/resolution.Chain end.
UdpListenerAccepts UDP peers and creates stateful lines per peer.Chain head.
UdpOverTcpClientCarries UDP-style packets over stream transport.Paired with UdpOverTcpServer.
UdpOverTcpServerServer side of UDP-over-TCP handling.Paired with UdpOverTcpClient.
UdpStatelessSocketSends/receives UDP datagrams using routing context instead of per-peer lines.UDP packet edge, often with WireGuardDevice.
UserControllerAdvanced support node that enforces authenticated-user limits through AuthenticationClient.Usually created internally by authenticated server nodes.
VlessClientWrites plain VLESS v0 client request framing.Paired with VlessServer, often inside TLS/Reality transport.
VlessServerParses and authenticates plain VLESS v0 traffic.Paired with VlessClient.
WireGuardDeviceImplements in-chain WireGuard crypto, peer state, and allowed-IP routing.Between packet side and UdpStatelessSocket.

Scaffold Node Type

This node type exists in source but is not a normal user-facing tunnel doc:

NodeRole
TemplateDeveloper scaffold for creating new tunnels.

Choosing A Starting Chain

  • Simple TCP proxy: TcpListener -> ... -> TcpConnector
  • Stateful UDP proxy: UdpListener -> ... -> UdpConnector
  • Stateless UDP packet edge: UdpStatelessSocket -> ...
  • Full IP tunnel: TunDevice -> ... -> TunDevice
  • WireGuard-style packet transport: TunDevice -> WireGuardDevice -> UdpStatelessSocket
  • Packet over stream bridge: PacketsToStream on one side and StreamToPackets on the other
  • Multiplexed stream transport: MuxClient on one side and MuxServer on the other
  • HTTPS-looking transport: HttpClient -> TlsClient -> TcpConnector, with TlsServer -> HttpServer on the server side
  • Reality-style visitor/protected split: RealityClient toward RealityServer, with RealityServer.settings.destination pointing to the visitor branch