Advanced

Rule-Based Routing Basics: Rule vs Global vs Direct and Safe Edits

Routing rules send traffic to proxy, DIRECT, or reject by domain/IP/process. Daily use Rule mode; Global proxies almost everything; Direct mostly bypasses. Wrong mode makes rules look “broken.”

Read the connections page hit first—then edit. Don’t paste giant rule sets preemptively.

Pick the right mode

Mode Behaviour When to use
Rule Matches your rule set, then falls back to the default policy Daily driving
Global Sends nearly all traffic through the proxy Quick test, or when rules misfire
Direct Bypasses the proxy entirely Local or trusted networks

Safe edits

Never edit the provider body — an update wipes it. To add your own rules, right-click the profile card and use the prepend area of Edit Rules; for your own policy groups, use Edit Proxy Groups. Extended Configuration (called Merge config before v1.7.x) is for key-value items like DNS or ports only: it overrides rather than appends, so a rules block written there replaces the entire provider ruleset (Merge). Copy real group names. Reload and confirm hits.

A minimal rule example

DOMAIN-SUFFIX,github.com,Proxy
DOMAIN-SUFFIX,api.openai.com,Proxy
DOMAIN-SUFFIX,cn,DIRECT
GEOIP,CN,DIRECT
MATCH,Proxy

Add a few lines, reload, and watch the connections page. Small patches first; huge third-party sets add lag and conflicts.

Tun, DNS, AI

Change rules, DNS, or Tun one layer at a time (DNS, Tun, AI). Huge third-party sets add lag and conflicts—small patches first.

Looks right, connections disagree

Earlier broad rules, caches, or actually being in Global/Direct cause “edits did nothing.” After Rule/Global switches, recheck daily sites and DIRECT exceptions. Stubborn cache: reload/restart.

Stop adding rules

If it already works, more “optimization” mostly confuses you. Roll back Merge from your copy. Game downloads: Steam DIRECT, DIRECT rules. Builds: download center.