Advanced Matching Rule

Chute supports several advanced matching rules for fine-grained traffic control.

Notice: SUBNET matches against the network the device is currently on, and HOSTNAME-TYPE against the request's address family or hostname. Apple TV has no network identity, so SUBNET never matches there. IN-TYPE and IN-USER match live traffic too: IN-TYPE names the inbound a connection arrived on (HTTP, SOCKS5 or TUN), and IN-USER the user name that inbound verified against http-auth — with no credentials configured nothing is verified, so IN-USER matches nothing. IN-NAME is accepted so that a Surge profile loads, but Chute runs a single unnamed HTTP listener and a single unnamed SOCKS5 listener, so there is no inbound name to match and the rule never fires; use IN-TYPE or IN-PORT instead.

SUBNET

Rule matches based on network subnet attributes. Uses KEY:VALUE syntax.

SUBNET,TYPE:WIFI,Proxy
SUBNET,SSID:MyWiFi,DIRECT
SUBNET,BSSID:00:11:22:33:44:55,Proxy
SUBNET,ROUTER:192.168.1.1,DIRECT

Supported keys:

Key Description
TYPE Network type (e.g. WIFI, CELLULAR, WIRED)
SSID Wi-Fi SSID name
BSSID Wi-Fi access point BSSID (MAC address)
ROUTER Router/gateway IP address
MCCMNC Carrier code — accepted so that a Surge profile loads, logged with a notice, and never matches

HOSTNAME-TYPE

HOSTNAME-TYPE,AAAA,Proxy

Rule matches on the DNS record type of the request — the address family the client connects to: A for an IPv4 destination (resolved or a literal address), AAAA for IPv6. On the HTTP and SOCKS5 proxy inbounds a hostname that has not been resolved yet has no record type and does not match; on the TUN inbound the record type is read from the address family of the packet's destination, fake IP included, so a domain session matches A or AAAA on the first pass already. Useful for routing IPv4 and IPv6 traffic differently. DOMAIN matches a request that names a hostname rather than an IP address, and SIMPLE one whose hostname is a single label with no dot (such as printer); neither needs a resolved address.

Values: A or IPv4, AAAA or IPv6, DOMAIN, SIMPLE. Any other value is a configuration error.


IN-TYPE

IN-TYPE,SOCKS5,Proxy

Rule matches based on the inbound connection type. Supported values:

Value Description
HTTP HTTP proxy inbound
SOCKS5 SOCKS5 proxy inbound
TUN TUN/VIF interface inbound

Alternatives are separated with /, so IN-TYPE,HTTP/SOCKS5,Proxy takes both proxy inbounds and leaves TUN traffic to the rules below it. The value is compared case-insensitively.


IN-USER

IN-USER,user1,Proxy

Rule matches based on the inbound authentication username. Useful when Chute is configured with multiple inbound proxies with different credentials.


IN-NAME

IN-NAME,my-proxy,Proxy

Rule matches based on the named inbound proxy configuration. Useful when running multiple proxy server instances with different names.

S. Smart Rabbit LLC © All Rights Reserved            updated 2026-09-25 00:02:29

results matching ""

    No results matching ""