SSID Suspend
Available on Chute iOS, Chute Mac and Chute Android. Not available on Apple TV.
You may configure Chute to suspend while the device is on specified Wi-Fi networks.
[SSID Setting]
"Corp-VPN" suspend=true
How it is enforced:
- iOS: entries with an exact network name (bare, quoted, or
SSID:<name>) andTYPE:WIFI/TYPE:CELLULARentries become on-demand disconnect rules of the VPN configuration;TYPE:WIFIcovers every Wi-Fi network. The system drops the tunnel when the device joins such a network and keeps it down while it stays there; after the next network change the usual on-demand rules apply again, so 'Always On' reconnects automatically.BSSID:andROUTER:entries,TYPE:WIRED, and names with*or?cannot be expressed as an on-demand rule: when the engine's own check matches one, the tunnel stops itself and you reconnect by hand once you have left the network — unless 'Always On' is enabled, whose connect rules would bring the tunnel straight back, so such entries do not suspend on iOS and Chute only tells you why. Whenever a suspension starts, Chute iOS posts a 'Suspended on This Network' notification (subject to the app's notification setting). - Mac: while the current network matches a
suspend=trueentry, Chute turns the system proxy and TUN off and restores them when the network no longer matches. All selector kinds are honoured. When the configuration names a Wi-Fi network, Chute asks once for the location permission (macOS 10.15 and later); from macOS 14 the Wi-Fi name cannot be read without it, and onlyTYPE:andROUTER:entries can match. - Apple TV: network-based settings are kept in the configuration for the other platforms but never apply; the app shows a notice when you save them.
- Android: Chute reads the transport, SSID, BSSID and gateway, matches the entries on every network change and once a minute, and pushes a matching entry's
dns-server/encrypted-dns-serverinto the resolver. In VPN mode a matchingsuspend=trueentry takes the VPN interface down while the engine keeps running, so traffic bypasses Chute; Chute posts a 'Suspended on This Network' notification, the main screen names the entry that matched, and the interface comes back by itself once the device leaves the network. All selector kinds are honoured. Local Proxy mode does not suspend. For the network name, the app asks for the location permission (Android 12 and earlier) or the nearby Wi-Fi devices permission (Android 13 and later) when an[SSID Setting]section is present; a start that cannot show the request posts a notification instead — see Getting Started on Android.
A later matching entry with suspend=false cancels the suspension on Mac and Android, and on iOS as well: the on-demand rules are scanned last-match-wins like the engine's own verdict, so the disconnect rule is not written. Two cancellations the on-demand rules cannot express: across selector kinds, TYPE:WIFI suspend=true followed by SSID:Home suspend=false still drops the tunnel on that network, because the rule is built for all Wi-Fi; and a wildcard entry cannot cancel a specific one, so SSID:Home suspend=true then Home* suspend=false leaves the rule in place. The engine's own verdict honours both.
Per-Network DNS
An entry may also change DNS while its network is current:
[SSID Setting]
SSID:Home dns-server=192.168.1.1, 192.168.1.2:5353, encrypted-dns-server=off
BSSID:AA:BB:CC:DD:EE:FF encrypted-dns-server=https://doh.example/dns-query, tls://dot.example
TYPE:CELLULAR dns-server=1.1.1.1
dns-server=replaces the plain resolvers of the main pool. It takes plain entries only — an IP address with an optional port ([v6]:portfor IPv6),systemorsyslib, written as in the globaldns-server. An encrypted resolver's URL, which the global key does take, is dropped here with a notice; list it inencrypted-dns-server=instead. Atcp://IP[:port]entry, for DNS over TCP, is accepted as well.encrypted-dns-server=offturns every encrypted resolver off; a list of URLs replaces them instead, sorted into DoH, DoT, DoQ and DoH3 by scheme.- Selectors are the ones used for suspension: a quoted network name,
SSID:<name>,BSSID:<address>,TYPE:WIFI,TYPE:CELLULAR,TYPE:WIREDandROUTER:<gateway address>; names may use the*and?wildcards.MCCMNC:is accepted but never matches. - The override is applied when the network changes and when the configuration loads. When several entries match, the later one wins; leaving the network restores the configured servers.
- One entry may combine
suspend=with the DNS parameters.
Shadowrocket's [Host] form ssid:<name> = server:<dns> becomes an entry of this kind — see Local DNS Mapping. On Apple TV these entries are kept but never apply.