Colitu Adaptive Connect
How Colitu Adaptive Connect picks a server, tries five connection modes in order, checks that real traffic flows and falls back on its own when one is blocked.
Adaptive Connect is the part of every Colitu app that decides how your device reaches a Colitu server. You press Connect; the Colitu panel chooses a server, and the app tries several connection modes until one of them actually carries your traffic. You never pick a protocol, port or key, and there is nothing to configure.
This page is the starting point of the Protocol Hub. Each connection mode has its own page that explains how the protocol works and where it is strong or weak.
Four protocol families, five connection modes
Every Colitu server offers the same five connection modes. They belong to four protocol families: Hysteria2, VLESS (in two variants, Reality and XHTTP), Trojan and Shadowsocks. The modes are deliberately different from each other: one runs over UDP, the others over TCP; four look like HTTPS or HTTP/3 in different ways, and one imitates nothing at all. A filter that stops one of them rarely stops all of them the same way.
| Mode | Transport | Camouflage | Best for |
|---|---|---|---|
| Hysteria2 | UDP, QUIC, TLS 1.3 | Looks like HTTP/3 to a site with a valid certificate | Mobile data, busy Wi-Fi, long lossy routes |
| VLESS Reality | TCP, TLS 1.3 with Reality | Borrows the TLS handshake of a real third-party website | Networks with deep packet inspection (DPI) |
| VLESS XHTTP | TCP, HTTP-style requests over Reality | HTTP requests inside the Reality layer | Networks that cut long single TCP connections |
| Trojan | TCP, TLS 1.3 | Looks like HTTPS to a site with a valid certificate | TLS-based fallback where UDP is blocked |
| Shadowsocks 2022 | TCP, AEAD encryption | None: the stream looks like random data | Lightly filtered networks, low overhead |
Step 1: choosing the server
Before any protocol is tried, the Colitu panel picks the server for your device:
- If you chose a location and it has an available server, that location is used. If it has none, the panel picks a server in another location instead of failing (fallback location).
- Among the candidate servers it prefers the one with the lowest current load.
- The choice stays stable for 24 hours per user and device, so you do not land on a different server and IP address every time you reconnect.
You can still choose automatic selection, a location or a specific server in the app; Adaptive Connect handles everything below that choice. Server locations and their service checks are listed on the servers page.
Step 2: the connection order
The app then tries the five modes in a fixed priority. The order differs slightly by platform:
| Platform | Order |
|---|---|
| Android (including Android TV) and iOS | Hysteria2 → VLESS Reality → VLESS XHTTP → Trojan → Shadowsocks 2022 |
| Windows and Linux | Hysteria2 first, then the TCP modes sorted by measured TCP connect time; modes that could not be reached go last |
Hysteria2 comes first everywhere because, when UDP gets through, it copes best with packet loss. On Windows and Linux the app measures how quickly each TCP mode answers from your current network and tries the fastest one first.
Step 3: checking that traffic really flows
A connection that is "established" is not necessarily useful. Some filters let a handshake complete and then quietly drop everything that follows. Adaptive Connect therefore does not trust the handshake alone:
- The app starts a mode and sends real traffic through it.
- It waits for that traffic to pass a check: about 12 seconds on Android and about 9 seconds on iOS before the mode is given up.
- If the check passes, you are connected.
- If the mode carried nothing, it is pushed back and the next mode in the order is tried.
How a failed mode is pushed back depends on the platform: Windows and Linux move it to the back of the queue for 10 minutes, Android stores it as stalled, and iOS applies a stall penalty so it is tried later.
While you are connected
- Android remembers the last mode that worked for each server and starts with it next time. A network that only lets one mode through does not cost you a full round of attempts on every connection.
- Windows keeps checking the tunnel every 2 seconds. If it stops carrying traffic, the app reconnects and Adaptive Connect runs again. The Windows kill switch, on by default, stops traffic from leaving outside the tunnel when it is lost; details are on the security page.
Learning from what works
The apps report to the Colitu panel which modes worked and which did not. These reports are aggregated and used to improve the default settings. They describe connection outcomes, not your activity: access logs are off on Colitu servers, as the security page explains.
Why you cannot pick a protocol manually
None of the Colitu apps (Windows, Android, iOS, Linux) has a manual protocol switch, on purpose:
- The working mode changes. A protocol that works on home Wi-Fi may fail on mobile data an hour later, or on the same network after a filter update. An automatic check reacts faster than a person changing settings.
- A wrong manual choice looks like a broken VPN. A fixed choice stays wrong after the network changes, and the app could not help.
- Nothing to copy or mistype. Server addresses, ports and keys are delivered to the app in encrypted form after you sign in. They are never shown and never published.
If a connection still fails, the guide VPN not connecting lists what to check.
Limitations
- Adaptive Connect can only choose among the modes the network lets through. If a network blocks every encrypted connection to unknown servers, or only allows traffic through a filtering web proxy, no mode will pass.
- On hotel and café Wi-Fi with a sign-in page (captive portal), sign in in the browser first. Until then no VPN can connect.
- On heavily filtered networks, trying modes in turn takes time, so the first connection can take noticeably longer than on a clean network. On Android, the memory of the last working mode shortens later connections.
Security and encryption
Every mode encrypts your traffic between your device and the server. The details differ per protocol: TLS 1.3 for Hysteria2, VLESS Reality, VLESS XHTTP and Trojan, and the AEAD cipher 2022-blake3-aes-256-gcm for Shadowsocks 2022. Each device has its own connection credentials. Switching modes never means falling back to an unencrypted connection: all five modes are encrypted.
Sources
- Hysteria 2 documentation
- Project X (Xray) documentation
- REALITY on GitHub
- Trojan protocol documentation
- sing-box documentation
- SIP022: Shadowsocks 2022 edition
Try it
Adaptive Connect is built into every Colitu app, including the free plan with 10 GB per month and no card required. Download Colitu for Windows, Android, iOS or Linux, or browse the server locations first.