Technical details
Technical details on Colitu's infrastructure, ports, service tests and server health.
This page summarises the Colitu infrastructure for network administrators and curious users.
Ports and transports
| Protocol | Transport | Port |
|---|---|---|
| Hysteria2 | UDP (QUIC) | 8443 |
| VLESS Reality | TCP | 8443 |
| Trojan | TCP (TLS) | 4433 |
| Shadowsocks 2022 | TCP + UDP | 8388 |
Colitu deliberately runs VLESS on a port other than 443: networks with deep packet inspection target Reality on 443 more often. On a company network, traffic to these ports must be allowed.
Connection profile
The apps fetch the server list and connection profiles from the Colitu API over an encrypted connection. Profiles are short-lived and renew automatically; the last valid profile keeps working for a while if the internet drops briefly. The apps use the servers' domain names, never their IP addresses.
Service tests
About every 6 hours each server automatically tests these services from its own internet exit:
- ChatGPT, Gemini, Claude (AI)
- Netflix, YouTube Premium (streaming)
The AI filter in the app shows servers where ChatGPT and Gemini both open. Test results update the location list automatically.
Server health
Servers regularly report CPU, memory, disk, running VPN cores and connection counts. An unhealthy server is automatically taken out of rotation for new connections and the apps are sent to another server.
Server categories
Labels in the location list:
- Streaming: streaming platforms tested
- Gaming: low latency and balanced load
- Privacy: privacy-focused locations
- Speed: high bandwidth
- Torrent: suitable for P2P traffic
- AI: ChatGPT and Gemini open
DNS
While connected, DNS queries are resolved through the tunnel on the server side, so your provider cannot see which domain names you look up.
Still need help?
Colitu Bot answers in seconds and hands you over to live support if it can't solve it.