____ _ _______ __
/ __ \ | /| / / __/ |/ /
/ /_/ / |/ |/ / _// /
\____/|__/|__/___/_||_/
owenclave / app/src/main/res/values/strings.xml
Owenclave
Project
Source code
Version
Version (%s)
Export debug information
Configuration
Group
About
Theme
Ungrouped
Toggle
Traffic
Group name
Update
Subscription link
Create group
Edit group
Empty group
Not updated yet
- %d profile
- %d profiles
- %d profile | Last update: %s
- %d profiles | Last update: %s
%s: No change
- %s: Updated %d profile
- %s: Updated %d profiles
Diff (%s)
Are you sure you want to remove this group?
Added: \n%s
Updated: \n%s
Deleted: \n%s
Duplicate: \n%s
Service mode
Proxy only
VPN
SOCKS5 proxy port
HTTP proxy port
Transparent proxy port
Route settings
Allow connections from LAN
Bind inbounds to 0.0.0.0
Inbound settings
App settings
Enable HTTP inbound
WebSocket settings
Max early data
Browser forwarding
Forward WebSocket through browser
Speed notification update interval
Misc settings
Show direct speed
Show direct traffic speed in notification as well
Security settings
Skip certificate verification
Enabling this option without deploying other security measures leads to the success of man-in-the-middle attacks. Do NOT enable unless you know what you are doing.
%1$s↑ %2$s↓
Proxy: %1$s↑ %2$s↓
\nDirect: %3$s↑ %4$s↓
%s/s
Testing…
Success: HTTPS handshake took %d ms
Success: HTTP handshake took %d ms
Failed: %s
DNS settings
Remote DNS
Direct DNS
Enable DNS routing
Resolve domains in bypass routes with direct DNS
Enable fake DNS
May cause other applications to need to be restarted to reconnect to the network after the proxy is disconnected
Hijack DNS
Hijack DNS queries that are not sent to TUN DNS address with DNS sniffer
Domain rewriting
Local DNS port
Enable transparent proxy inbound
Transparent proxy mode
Connection test URL
Custom test URL
Profile name
Server
Server port
Username
Password
Encryption method
Protocol
Protocol parameters
Obfs
Obfs parameters
User ID
Alter ID
Transport layer security
Network
Flow
Obfuscation header type
WebSocket host
WebSocket path
HTTP host
HTTP path
QUIC Security
QUIC key
mKCP seed
gRPC service name
URL
SNI
ALPN
Certificate
Pinned certificate chain SHA-256
Early data header name
Extra headers
Config type
Edit Config
IPv6 route
Metered Hint
Hint system to treat VPN as metered
Route
Create route
Are you sure you want to remove this route?
Route name
Proxy
Bypass
Block
Select profile…
Empty route
Configure some rules before saving
Domain rule for %s
Play store rule for %s
IP rule for %s
Reset
Manage route assets
Assets
Route assets provider
Official
Local version: %s
Already up-to-date
Updated
Not an asset file: excepted .dat, but %s
Bypass private addresses
Domain strategy
Enable sniffing
Enable Mux
Mux concurrent Connections
Per-app VPN
Exclude selected apps from VPN or include selected apps in VPN
Off
Search…
Scanning…
Invert selections
Clear selections
Bypass
Show system apps
Auto connect
Restore the previous connection status after device boot or app update
VPN Service
Proxy Service
Proxy started.
Invalid server address
Stop
Stopping…
VPN permission denied
Failed to start VPN service. You might need to reboot your device.
Please select a profile
Connect
Clipboard is empty
Settings
Edit
Share
Add profile
Select profile
SOCKS
HTTP
Shadowsocks
ShadowsocksR
VMess
VLESS
Trojan
NaïveProxy
Hysteria 2
SSH
WireGuard
mieru
TUIC
HTTP/3
AnyTLS
olcrtc
Proxy chain
Custom config
Balancer
Balancer settings
Type
Strategy
Use group landing proxy
Use group front proxy
Chain settings
Config settings
Circular reference
Route cannot contain itself.
Clear
Export to file
Export to Clipboard
Export
Import from clipboard
Import from file
Successfully export!
Failed to export.
Successfully import!
Failed to import.
Your device lacks an Android standard file selector, please install one, such as Material Files.
Profile config
Remove
Are you sure you want to remove this profile?
QR code
Scan QR code
Manual settings
- %d item removed
- %d items removed
- %d item added
- %d items added
Undo
Connecting…
Connected, tap to check connection
Not connected
Subscriptions
Cleartext HTTP traffic is insecure
Error
No proxy found in the link
No proxy found in the subscription
No proxy found in the file
No proxy found in the clipboard
Deduplication
Ignore battery optimizations
Remove some restrictions
Plugin
Configure…
Disabled
Unknown plugin: %s
Server settings
Shadowsocks settings
Changes are not saved. Do you want to save?
Apply
Reload proxy service to apply changes
License
Make sure you have read the documentation before adding custom rules, otherwise you may not be able to connect to the Internet.
- %d line
- %d lines
Night mode
Follow system
Enable
Disable
Auto
List
Random
Balancer observation interval (s)
%d ms
Unavailable
Always show address
Always display the server address on the configuration card
Clear traffic statistics
Connection test
Clear test results
URL test
Domain not found
Connection refused
Unreachable
Timeout
Append HTTP proxy to VPN
Some supported apps will use HTTP proxy directly and their traffic will not go through the VPN interface.
Protocol settings
Basic
Group settings
Subscription
Subscription settings
Group type
Subscription type
Are you sure you want to remove this group?
Remove duplicate configurations when updating
Raw
Update settings
Automatic update
Automatic update interval (minutes)
Update only when connected
Prevent IP address leak
User agent
Confirm
Missing plugin
Profile %s requires %s plugin, but it was not found.
Proxy is not connected, are you sure you want to continue updating?
Subscription Update Service
Subscription update
Updating %s …
%s used
%s used / %s remaining
Import subscription
Are you sure you want to import subscription %s? If the source is not trustworthy, your IP and behavior will be leaked.
Import profile
Are you sure you want to import profile %s?
Are you sure you want to clear this group?
Applications
Select applications
- %d application
- %d applications
Obfuscation password
Authentication type
Max upload speed (Mbps)
Max download speed (Mbps)
Experimental settings
Make the length of each payload segment no longer malleable. This experiment requires the server and client use the same version of v2ray-core. More breaking updates on this experiment is expected.
Do not send connection single duplex termination signal for TCP connection when transferred over VMess. This will break some applications.
uTLS fingerprint
Sort
By original order
Alphabetically
By latency
Profile %s requires %s plugin, but your proprietary equipment vendor (usually surveillance capital giants and malware maker) tampered with your Android, making the plugin unusable.
%s | %s/s ↑
%s | %s/s ↓
%s ↑
%s ↓
Active
Statistics
- %d TCP connection
- %d TCP connections
- %d UDP connection
- %d UDP connections
Turn on VPN to record traffic statistics
Copy app name
Copy package name
Open in Settings
Create a rule
Successfully copy!
Failed to copy.
The app has no interface.
Rule for %s
Routing rule `%s` requires VPN, ignored.
App traffic statistics
Profile traffic statistics
May increase power consumption
When disabled, used traffic will not be counted
No statistics yet
App traffic statistics disabled
None
Public key
Private key
Private key passphrase
Tools
Logs
Clear Logcat
Local address
Peer public key
Peer pre-shared key
TCP/IP stack
Override destination
Override the destination address with the sniffed domain name, not for routing only
Resolve destination
PCAP
Enable PCAP
Save traffic to .pcap file
Pcap files will be saved to %s
Insecure concurrency
Use N concurrent tunnel connections to be more robust under bad network conditions. More connections make the tunneling easier to detect and less secure. This project strives for the strongest security against traffic analysis. Using it in an insecure way defeats its purpose. \n\nIf you must use this, try N=2 first to see if it solves your issues. It is strongly recommended not to use more than 4 connections.
NAT behavior discovery
Discover client\'s NAT mapping behavior and NAT filtering behavior defined in RFC 5780 using STUN.
Start
This may take a few minutes…
NAT mapping behavior
NAT filtering behavior
Wi-Fi SSID
Missing permissions
Location disabled
Routing rule `%s` requires access to your **Wi-Fi SSID**, but this requires **location enabled**
Routing rule `%s` requires access to your **Wi-Fi SSID**, but this requires **background location permission**
Routing rule `%s` requires access to your **Wi-Fi SSID**, but this requires **fine location permission**
Routing rule `%s` requires access to your **Wi-Fi SSID**, but this requires **coarse location permission**
Network type
Mobile network
Wi-Fi
Bluetooth
Ethernet
Network
Backup
Groups and configurations
Routing rules
Settings
If routing rules are not backed up with the configurations, custom outbounds will be lost. No backward or forward compatibility guaranteed.
Not a backup file: excepted .json, but %s
Invalid backup file
Import
Importing will overwrite existing data.
Importing…
Use system DNS as direct DNS
Tasker settings
Action
Start service
Stop service
Current profile
Start profile %s
Root CA provider
Mozilla
System
Packet encoding
MTU
This is GFWReport\'s proposal for a countermeasure for the random stream like protocol blocking behavior observed on GFW.
\n\nThis option remap the first 6 bytes of IV to printable characters, it\'s possible for anyone on the privileged network path to identify the protocol when enabled.
UDP over TCP
UDP relay mode
Congestion control
Disable SNI
0-RTT handshake
REALITY public key
REALITY Short ID
REALITY uTLS fingerprint
Reserved
Bootstrap DNS
Use system DNS as Bootstrap DNS
Fragment
Turn on flash
Switch camera
Turn off flash
Port hopping interval (s)
Clear unavailable
STUN server
UDP over stream
Disable post-quantum key agreement
Hysteria2 password
Juicity
NAT Type
NAT type test
Determine client\'s NAT type defined in RFC 3489 using STUN.
External Address
Expire: %s
Show group name in notification
Remote DNS query strategy
Direct DNS query strategy
Custom
geosite.dat URL
geoip.dat URL
HTTP proxy exception list
Mux settings
Update subscription
This group is not a subscription.
Enable TLS Client Hello fragmentation
May help circumvent SNI censorship. This option may get removed in the future.
Fragmentation length
Fragmentation interval
Also enable fragmentation for direct
Certificate prober
Probe the TLS certificate of a server.
Front proxy
Landing proxy
Resolve destination (direct)
EDNS client IP
Allow apps to bypass VPN
Allow apps to bypass VPN using system-provided methods on their own
Update all subscriptions
XHTTP settings
ECH Config
ECH DoH server
Mode
Extra
Backup all profiles
Please download v2ray-extra.zip from v2ray-core release and place index.html and index.js in Android/data/%s/files or import index.html and index.js as route assets.
Multiplexing level
Add route asset
Add URL
Invalid filename: %s
Filename can\'t be %s
Asset with filename %s already exists
Invalid URL: %s
Are you sure you want to delete this asset?
Asset name
Asset URL
Asset settings
HTTPUpgrade settings
Name exclusion (regular expression)
System and user
One per line.
One per line. Format:\n%s
Please input an IP address. IPv4 uses a subnet of /24 and IPv6 uses a subnet of /96.
If the address of direct DNS is a domain name and "resolve destination" is enabled, use bootstrap DNS to resolve it. Please input a DNS server with IP address or with "+local".
More
Acquire WakeLock
Log level
Floating action button style
Persistent keepalive (s)
Language
System default
USB
Satellite
Invalid network type: Android %s is required.
Enable DNS inbound
Disable REALITY X25519MLKEM768
Be compatible with REALITY servers that do not support this breaking change. This is a temporary option and will be removed in the future.
Idle session check interval (s)
Idle session timeout (s)
Minimal idle sessions
%1$s %2$s
Use binary prefixes
Use binary prefixes (1 KiB = 1024 bytes) rather than decimal prefixes (1 kB = 1000 bytes).
B
kB
MB
GB
TB
PB
KiB
MiB
GiB
TiB
PiB
Add IPv6 address to VPN interface
Exclude private addresses from VPN
Sniff domain name from HTTP Host, TLS SNI and QUIC SNI and sniff protocol type
Resolve the specified domain name to the specified IP address
IPv4 only
Prefer IPv4
IPv4 and IPv6
Prefer IPv6
IPv6 only
Disable all
Enable all
Resolve destination (server address)
- Are you sure you want to import %d profile to %s?
- Are you sure you want to import %d profiles to %s?
Route mode
rule
global
direct
ShadowQUIC
Running configuration will be printed to the system log, so the log will contain secret keys used to connect to servers. This log level is required for reporting issues, and please remove sensitive information before posting log files publicly.
Don\'t show again
Format: %s
Handshake mode
Fragmentation method
TLS record fragmentation
TCP segmentation
TLS record fragmentation and TCP segmentation
Pinned certificate public key SHA-256
Pinned certificate SHA-256
Use with "skip certificate verification" if the certificate itself is untrusted or invalid. One per line in Base64 encoding.
Use with "skip certificate verification" if the certificate itself is untrusted or invalid. One per line in hex encoding.
mTLS certificate
mTLS certificate private key
Are you sure you want to remove these profiles?
Interrupt reused connections when network changes
Create shortcut
Server port range
gRPC settings
gRPC service name compatibility
Be compatible with Xray\'s breaking change but break the compatibility with non-Xray servers.
Multi mode
All existing rules will be deleted.
It is for compatibility purpose only and does not contain complete information.
Please place root_store.certs file in Android/data/%s/files, or import root_store.certs as a route asset.
Use alternative method to query installed apps
Third party notices
Name inclusion (regular expression)
Translation platform
Discard ICMP
Discard ICMP and ICMPv6
Security tips
Display warnings for profiles with equivalent security to cleartext.
ECH
ServerNameToVerify
Traffic pattern
The security of this profile is equivalent to cleartext.\n\nThis warning is displayed because \"security tips\" is enabled.
Minimum port hopping interval (s)
Maximum port hopping interval (s)
BBR profile
Enable SOCKS5 inbound
Custom package name or UID
UDP
REALITY mldsa65Verify
SOCKS5 UDP is not protected by username/password authentication. If UDP is enabled, the authentication can be bypassed easily.
Enable Hysteria 2 OmitMaxDatagramFrameSize
OmitMaxDatagramFrameSize
If the Hysteria 2 server does not support this breaking change, UDP will be unusable. This is a temporary option and may be removed in the future.
Keepalive interval (s)
Custom outbound
Maximum packet size
Minimum packet size
This requires the \"nearby devices\" permission to work, but the permission has not been granted.
Snell
Connection reuse
Pre-shared key
Obfuscation mode
Obfuscation host
Mode
Disable connection reuse
SOCKS proxy chaining
Route SOCKS traffic through another SOCKS proxy (proxy -> proxy -> site)
Chain proxy host
Chain proxy port
Chain proxy username
Chain proxy password
Enable twps2 (zapret2)
Global DPI bypass using twps2 local proxy from zapret2
twps2 strategy
Unlock AI and EN services (Russia)
Apply routing rules to bypass blocks on AI and EN services in Russia
Direct proxy mode
Direct traffic through the device itself using zapret2 and unlock rules
Auth provider
Transport
Room ID
Encryption key (hex)
DNS server
SOCKS host
SOCKS port