New Features - IP Rewrite
- Added the
[IP Rewrite] section, which handles packets entering Surge VIF at the IP layer based on their destination address, before they reach any rule or policy. Available actions:- reflect: Swaps the source and destination addresses and sends the packet back to its sender.-
reject: Responds with a TCP RST to connection attempts and with an ICMP administratively prohibited message to other packets, so the sender fails immediately.-
drop: Silently discards the packet.For example, you can use the following module to make Surge work as LocalDevVPN, allowing you to use certain developer toolchains on iOS devices.
#!name=Local Device Loopback
#!desc=Reflect 10.7.0.1 back to this device for on-device developer tools.
[General]
ipv6-vif = disabled // Some tools only recognize utun interfaces without an IPv6 address.
tun-included-routes = %INSERT% 10.7.0.1/32
[IP Rewrite]
10.7.0.1 = reflect