Enhanced Mode
Only Chute Mac supports this feature
Some applications may not obey the system proxy settings. Enhanced Mode forces all network traffic through Chute by operating at a lower level than the system proxy. Chute Mac provides two Enhanced Mode implementations, selectable in the main window's Misc tab under Enhanced Mode Type (in the older interface, the Misc section of Preferences...). VIF Mode — Helper utun (Legacy) — is the default.
Mode Comparison
| Feature | VIF Mode (Legacy) | VPN Mode (Recommended) |
|---|---|---|
| Type | Virtual network interface | VPN |
| Traffic interception | Route-based | System-level |
| DNS configuration | Automatic (privileged helper) | Automatic |
| macOS requirement | No extra requirement | macOS 10.15+ |
| App location | Anywhere | Must be in /Applications |
Common Behavior
Both modes share the following characteristics:
Chute creates a virtual network interface and registers as the default route, redirecting traffic through the proxy for inspection and routing.
DNS queries inside the tunnel are answered with virtual IP addresses for every domain, including domains your rules send
DIRECT. Only hosts listed inalways-real-ipand the proxy servers' own domains get their real addresses.Chute Enhanced Mode can only process TCP, UDP, and ICMP traffic. Only enable this feature when necessary.
ICMP traffic (ping) cannot be proxied. By default Chute answers an echo request inside the tunnel itself, IPv4 and IPv6 alike, without sending anything to the target — so a ping that succeeds inside the tunnel says nothing about whether the target is reachable. See
icmp-auto-reply.UDP traffic is relayed through the matched policy when the policy supports UDP relay. If the matched policy does not support UDP (or has
udp-relay=false), the datagram is not sent at all and is recorded as NotSend. That is the default;udp-policy-not-supported-behaviour = DIRECTsends it directly instead.
Type 1: VIF Mode (Legacy)
This is the original Enhanced Mode implementation using a virtual network interface.
How it works
Chute creates a virtual network interface and configures system routes to direct all traffic through it.
When IPv6 is enabled (
ipv6 = truein config), IPv6 traffic is also routed through the virtual interface.On teardown, all routes are removed and the original network configuration is restored.
Requirements
- A privileged helper component must be installed and running.
- DNS is handled for you: once the interface is up, the helper points a network service at Chute's own resolver — the one chosen under Helper in the same Misc tab: the primary service by default (Primary Interface (Auto)), every service with All Interfaces — and puts the previous servers back when Enhanced Mode is disabled. The replaced servers are saved under
/Library/Application Support/Chute/— see File Locations.
Type 2: VPN Mode (Recommended)
This is the newer implementation using the system VPN framework.
How it works
Chute starts a VPN tunnel that captures all network traffic at the system level.
When IPv6 is enabled, IPv6 traffic is also routed through the VPN tunnel.
On teardown, the VPN tunnel is stopped and the original network configuration is restored.
Requirements
- macOS 10.15 or later.
- The app must be located in
/Applications. - On first use, you must approve the network extension in System Settings > General > Login Items & Extensions > Network Extensions.
- The mode type cannot be changed while Enhanced Mode is active — disable first, then switch.
Important notes
- HTTP/HTTPS system proxy settings become ineffective while VPN Mode TUN is active. The system proxy will resume when Enhanced Mode is disabled.
- DNS configuration is automatic — no manual DNS override is needed.
- If the VPN is manually turned off in System Settings, Chute will clean up and disconnect gracefully.
Configuring Enhanced Mode Type
- Open the main window — Open Dashboard... (⌘,) in the menu bar; in the older interface, Preferences... (⌘,) opens a window with the same Misc section
- Go to the Misc tab
- Select the desired mode under Enhanced Mode Type:
- Helper utun (Legacy) — the original virtual-interface-based mode
- PacketTunnel (Recommended) — the newer VPN-based mode
- The change takes effect the next time you enable Enhanced Mode.
Note: You cannot change the mode type while Enhanced Mode is currently active. Disable first, then switch.
Troubleshooting
- VPN Mode won't start: Ensure the app is in
/Applicationsand that you have approved the network extension in System Settings. - "Allow Chute in Login Items" or "Approval Required": macOS is holding back Chute's privileged helper, which VIF mode and the system proxy both depend on. Turn Chute on in System Settings > General > Login Items & Extensions; Chute connects to the helper by itself once it is allowed.
- "System Extension Blocked" message: Go to System Settings > General > Login Items & Extensions > Network Extensions and enable the Chute extension.
- Stale VPN configuration: If the VPN gets stuck, use the Reset VPN... button in the main window's Misc tab. It only removes the VPN configuration, and only while the tunnel is disconnected; the next Enhanced Mode start creates a fresh one.
- DNS not working in VIF mode: the helper swaps the interface DNS itself when the tunnel comes up. If that step fails, Chute reports TUN DNS swap failed and turns Enhanced Mode back off. The notice shown when VIF mode is turned on is unconditional — it is not a sign that something is unconfigured. It appears each time VIF mode is turned on until you tick Don't show this message again; VPN Mode has a notice of its own, PacketTunnel Enhanced Mode, that behaves the same way.