3x-ui VPN Server Setup for Openclaw

An automated end-to-end workflow for transforming a fresh VPS into a hardened, high-performance VPN server using the 3x-ui Xray proxy panel.

davydenkovm
v1.0.0
Mar 7, 2026
1
1.1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install 3x-ui-vpn-setup

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install 3x-ui-vpn-setup using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is 3x-ui VPN Server Setup?

This skill provides a professional-grade automation path for deploying private proxy infrastructure. It manages the entire server lifecycle, starting from a fresh VPS with only root credentials and moving through full system hardening to the installation of the 3x-ui panel. By integrating advanced security practices and modern proxy protocols, it ensures that your private network remains both secure and performant.

The core of the skill focuses on user security and stealth. It implements non-root user management, SSH key-based authentication, and kernel-level hardening to protect the host. For connectivity, it utilizes VLESS Reality, a protocol designed to mimic standard TLS traffic, making it nearly impossible for Deep Packet Inspection to detect your VPN usage. This Openclaw Skills utility is designed to be accessible for beginners while providing the technical depth required by power users.

3x-ui VPN Server Setup Use Cases

  • Creating a private, high-speed VPN server to bypass regional network restrictions.
  • Hardening a fresh Linux VPS with firewall rules, fail2ban, and disabled root password access.
  • Deploying a stealth proxy using VLESS Reality that masquerades as legitimate HTTPS traffic.
  • Automating the generation of client configuration links for the Hiddify app across multiple devices.

How 3x-ui VPN Server Setup Works

  1. Connects to the fresh VPS via root to perform initial system updates and non-root user creation.
  2. Generates and installs ED25519 SSH keys to transition the server to a passwordless, secure authentication model.
  3. Configures the UFW firewall and tunes kernel parameters (sysctl) for security and network performance.
  4. Installs the 3x-ui panel and enables TCP BBR to optimize bandwidth and reduce latency.
  5. Executes a Reality Scanner on the server's subnet to find compatible SNI targets for stealth masquerading.
  6. Configures a VLESS Reality inbound via the panel API and generates a localized guide file for the user.

3x-ui VPN Server Setup Setup

To use this skill within your AI agent environment, simply provide your VPS credentials and let the Openclaw Skills workflow handle the execution.

# Required information:
# 1. Server IP address
# 2. Root password
# 3. Desired non-root username

The agent will automatically generate SSH keys on your local machine and walk you through the process of securing the remote environment.

3x-ui VPN Server Setup Data Schema & Taxonomy

The skill organizes security credentials and configuration data into a structured format for the user:

Component Location Description
SSH Private Key ~/.ssh/{nickname}_key The local key used for passwordless server access.
SSH Config ~/.ssh/config Host alias for quick connection via ssh {nickname}.
Deployment Guide vpn-{nickname}-guide.md A generated markdown file containing panel passwords and VLESS links.
Panel Access https://127.0.0.1:{port}/{path} Administrative URL accessible only via local SSH tunnel.
VLESS Link vless://... The final configuration URI for the Hiddify client.

3x-ui VPN Server Setup Advanced Features

  • Automated Reality Scanning: Dynamically probes neighboring IPs to find the most effective SNI for stealth traffic masquerading.
  • SSH Tunneling Protocol: Automatically secures the 3x-ui admin panel by keeping it closed to the public internet and routing it through a secure tunnel.
  • BBR Optimization: Implements Bottleneck Bandwidth and Round-trip propagation time (BBR) for superior throughput on lossy networks.
  • Stealth ICMP: Disables ping responses at the firewall level to make the server invisible to automated network scans.
  • Multi-Mode Execution: Capable of running from a local developer machine or directly on the VPS target.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*