Outline VPN - VPN server resistant to blocking | INTROSERV
EUR
european

EUR

usa

USD

English En
Ex. VAT Ex. VAT 0%

How to set up Outline VPN server to bypass blocking

Outline is a free, open-source tool for running your own VPN service on a VPS. It uses the Shadowsocks protocol to route traffic through your server, and it includes features designed to make this traffic harder to detect and block. This guide shows how to install the Outline server on a Linux VPS, connect it to Outline Manager, create access keys and connect client devices.

What Outline is and how it works

Outline consists of three parts:

  • Outline Server: runs on your VPS in a Docker container and handles the encrypted traffic;
  • Outline Manager: a desktop application for Windows, macOS and Linux that you use to manage the server and create access keys;
  • Outline Client: an application for Windows, macOS, Linux, iOS and Android that connects a device to the server with an access key.

Outline uses Shadowsocks with mandatory AEAD encryption, protection against active probing and replay attacks, and variable packet sizes. Your server is privately managed, and you share access keys directly with the people or devices you authorize. However, no VPN or proxy protocol is resistant to every blocking method. If a server is blocked, you can deploy another Outline server and create new access keys.

Info

Outline protects your traffic from network observers, but it is not an anonymity tool. Websites can still identify you when you log in or through browser and device fingerprinting.

Outline was launched in 2018 by Jigsaw, a Google incubator. Since 2026 the project is maintained by the Outline Foundation, an independent non-profit organization. It remains free and open source.

Outline needs very few resources, so a budget VPS is enough. INTROSERV offers Linux VPS in locations across Europe, North America, Asia and Australia.

What you need

You need:

  • a VPS or dedicated server with an x86_64 processor and a public IP address;
  • a current Linux distribution supported by Docker, for example Ubuntu or Debian;
  • root access or a user with sudo rights;
  • a computer with Windows, macOS or Linux to run Outline Manager;
  • a device on which you install Outline Client.

Info

If Docker is not installed, the installation script asks whether to install it automatically with the official get.docker.com script.

Install Outline Manager

Download Outline Manager for your operating system from the official Outline website, install it and open it. In the server setup screen, find Set up Outline anywhere (the Advanced option for any provider) and click Set up.

Outline Manager shows the installation command for the server. Copy it.

The current command is:

sudo bash -c "$(wget -qO- https://raw.githubusercontent.com/OutlineFoundation/outline-apps/master/server_manager/install_scripts/install_server.sh)"

Install the Outline server

Connect to your server over SSH. For details, see Connecting via SSH. Paste the copied command and press Enter.

If wget is not installed, install it and run the installation command again. On Ubuntu and Debian:

sudo apt update sudo apt install -y wget

The script checks whether Docker is installed. If it is not, the script asks whether to install it. Press Y and Enter.

The script then starts two containers: shadowbox, which runs the Outline server and its management API, and watchtower, which updates the server automatically. Installation usually takes 2 to 3 minutes.

When the installation finishes, the console shows the message CONGRATULATIONS! Your Outline server is up and running, and a green line in curly brackets:

{"apiUrl":"https://203.0.113.10:12345/AbCdEfGhIjKlMnOp","certSha256":"1A2B3C..."} Make sure to open the following ports on your firewall, router or cloud provider: - Management port 12345, for TCP - Access key port 54321, for TCP and UDP

The values in your output will be different. Copy the whole line, including the curly brackets. You will paste it into Outline Manager.

Danger

The apiUrl line contains the credentials for the management API of your Outline server. Anyone who obtains it can manage the server, including creating and deleting access keys. Treat it as a secret: do not publish it or send it over insecure channels. If you lose it, you can find it on the server in the /opt/outline/access.txt file.

Below the line, the script lists the two ports that must be reachable from the internet: the management port (TCP) and the access key port (TCP and UDP). Both ports are chosen at random during installation. Note them down for the next step.

Tip

You can set the ports and the address yourself by adding flags at the end of the installation command. For example, --keys-port=443 sets the access key port to 443 (TCP and UDP). This can help when a network blocks uncommon ports, but port 443 does not make Shadowsocks traffic indistinguishable from HTTPS. The --hostname=vpn.example.com flag makes access keys use a domain name instead of the IP address. If you later move the server to a new IP address, update the DNS record, and the existing keys can continue to work. The full command then looks like this:

sudo bash -c "$(wget -qO- https://raw.githubusercontent.com/OutlineFoundation/outline-apps/master/server_manager/install_scripts/install_server.sh)" install_server.sh --keys-port=443

Open the ports in the firewall

Depending on your Linux distribution and network setup, a firewall may block incoming connections. If you use a firewall, allow the ports shown in the installation output. Replace 12345 with the management port and 54321 with the access key port.

For UFW on Ubuntu and Debian:

sudo ufw allow 12345/tcp sudo ufw allow 54321/tcp sudo ufw allow 54321/udp

Tip

If your computer has a static IP address, you can allow the management port only from this address, for example sudo ufw allow from 198.51.100.7 to any port 12345 proto tcp. Clients do not need the management port.

For firewalld:

sudo firewall-cmd --permanent --add-port=12345/tcp sudo firewall-cmd --permanent --add-port=54321/tcp sudo firewall-cmd --permanent --add-port=54321/udp sudo firewall-cmd --reload

Warning

If the management port is closed, Outline Manager cannot connect to the server. If the access key port is closed, clients cannot connect, even though the server works. If the script prints BLOCKED next to Checking host firewall, make sure that both ports are reachable from the internet.

Connect the server to Outline Manager

Return to Outline Manager, paste the copied line into the field in step 2 and click Done.

The server appears in the list on the left. Its page shows the access keys and the amount of traffic used.

Tip

You can add several servers to Outline Manager, for example VPS in different locations, and manage them all from one window.

Create and share access keys

The installation automatically creates a first access key. To create a key for another person or device, click Add new key.

To rename a key, for example after the person who will use it, open the key menu (three dots) and choose Rename. In the same menu, you can set a data limit for this key. The server settings let you set a default limit for all keys.

To get the key for a client, click the share icon next to the key.

Copy the access key. It starts with ss:// and contains the server address, port and access secret. Click Done.

Warning

An access key works like a password. Send it only through a private channel. If a key leaks, delete it in Outline Manager and create a new one: the deleted key stops working immediately.

Info

Create a separate key for each person. Then you can see the traffic of each key and revoke access for one person without affecting the others.

Connect a client device

Download Outline Client from the official Outline website and install it on the device. In the application, click the plus button or Add server, paste the access key and click Confirm.

Click Connect. On the first connection, the operating system asks you to allow the VPN configuration. Confirm it.

To check the connection, open a service that shows your IP address, for example ifconfig.me, in a browser. It must show the IP address of your VPS.

Manage and update the server

The watchtower container checks for a new version of the Outline server every hour and installs it automatically.

To check that both containers are running, run:

sudo docker ps

The list must include shadowbox and watchtower with the Up status. If the server does not work, view its log:

sudo docker logs shadowbox

To remove Outline from the server completely, delete the containers and the data directory:

sudo docker rm -f shadowbox watchtower sudo rm -rf /opt/outline

Warning

These commands permanently delete the Outline server state and all access keys stored in /opt/outline. This cannot be undone: make sure you no longer need them. Clients will not be able to connect until you install the server again and issue new keys.

Outline can be useful when a conventional VPN protocol is blocked on your network. If you need a classic VPN protocol, see How to set up your personal WireGuard VPN server.

VAT

  • Other

    Ex. VAT

    0%
  • austria

    Austria

    20%
  • Belgium

    Belgium

    21%
  • Bulgaria

    Bulgaria

    20%
  • Croatia

    Croatia

    25%
  • Cyprus

    Cyprus

    19%
  • Czech Republic

    Czech Republic

    21%
  • Denmark

    Denmark

    25%
  • Estonia

    Estonia

    22%
  • France

    France

    20%
  • Finland

    Finland

    24%
  • Germany

    Germany

    19%
  • Greece

    Greece

    24%
  • Hungary

    Hungary

    27%
  • Ireland

    Ireland

    23%
  • Italy

    Italy

    22%
  • Latvia

    Latvia

    21%
  • Lithuania

    Lithuania

    21%
  • Luxembourg

    Luxembourg

    17%
  • Malta

    Malta

    18%
  • Netherlands

    Netherlands

    21%
  • Poland

    Poland

    23%
  • Portugal

    Portugal

    23%
  • Romania

    Romania

    19%
  • Slovakia

    Slovakia

    20%
  • Slovenia

    Slovenia

    22%
  • Spain

    Spain

    21%
  • Sweden

    Sweden

    25%
  • USA

    USA

    0%
european
states
  • germany
  • Español
  • Italiano
  • Poland
  • Русский
  • Slovenski
  • Türkçe
  • ukraine
  • kingdom
  • French
  • Hrvatska
  • Other
  • Austria
  • Belgium
  • Bulgaria
  • Croatia
  • Cyprus
  • Czech Republic
  • Denmark
  • Estonia
  • Finland
  • France
  • Germany
  • Greece
  • Hungary
  • Ireland
  • Italy
  • Latvia
  • Lithuania
  • Luxembourg
  • Malta
  • Netherlands
  • Poland
  • Portugal
  • Romania
  • Slovakia
  • Slovenia
  • Spain
  • Sweden
  • USA