Advanced

How to Make Games and Downloads Bypass Clash Verge with DIRECT Rules

Domestic games and cloud downloads often get slower through a proxy, because every packet is dragged out to a node and back for no benefit—those hosts are reachable directly. Add DIRECT rules so matched traffic exits locally. Use Merge/override—don't edit the provider body, or the next subscription update wipes your work.

Routing basics: routing; where the rules go: Merge; slow throughput: slow speed.

Decide what should bypass

Not everything belongs in DIRECT. A good candidate is traffic to a host or region you can already reach without the proxy: domestic game servers, app-store and OS update CDNs, local NAS or intranet addresses. A bad candidate is anything the provider requires to exit through a supported region—pulling AI or streaming traffic into DIRECT just breaks it. When in doubt, measure first: if a host is fast and reliable without the proxy, add a DIRECT rule; if it only works through a node, leave it alone.

Three common matchers

  • DOMAIN-SUFFIX for update/CDN hosts, e.g. steampowered.com, download.microsoft.com. Covers every subdomain under it.
  • IP-CIDR for known ranges you have verified belong to a domestic service. Add no-resolve when the address is already an IP and DNS lookup is pointless.
  • PROCESS-NAME for "this exe always DIRECT" (names differ per OS—Steam.exe on Windows, no extension on macOS/Linux).

These lines have to sit ahead of the provider ruleset or a broad rule eats them: right-click the profile you use, choose Edit Rules, and fill the prepend area. Writing prepend-rules into Merge stopped working in v1.7.x—see the version note in Merge custom rules. Steam-specific steps: Steam DIRECT.

Paste-ready example

Put these in the Edit Rules prepend area, above the subscription rules:

  - DOMAIN-SUFFIX,steampowered.com,DIRECT
  - DOMAIN-SUFFIX,steamcontent.com,DIRECT
  - DOMAIN-SUFFIX,download.microsoft.com,DIRECT
  - PROCESS-NAME,Steam.exe,DIRECT
  - IP-CIDR,23.0.0.0/8,DIRECT,no-resolve

Edit the names to match what the Connections view actually shows for your traffic. A rule for a host you never hit does nothing; a missing rule for a host that hammers the tunnel is the whole point of this page.

With Tun and AI

DIRECT still applies under Tun—confirm on the Connections view, where the policy column should read DIRECT for the matched flow. Don't over-broaden suffixes: a careless DOMAIN-SUFFIX,google.com,DIRECT would also yank Gemini and the OAuth login out of the proxy and break them. Keep DIRECT narrow. Tun + AI guidance: Tun & AI. DNS interaction: DNS.

Acceptance

  1. Reload; game/download shows DIRECT hits.
  2. Latency/speed sane (latency).
  3. Sites that need PROXY still do.

Stop

Copy the Merge text before edits; roll back if it gets messy. Logs: logs. LAN share (another use of direct egress): LAN share. Builds: download center.

Rules set — is your client current?

PROCESS-NAME rules lean on a recent core. Check the download center to make sure you are on the latest build.