Skip to content

Inbound, listeners, and TUN

Clash creates a Packet Tunnel through Apple Network Extension. Apple owns the virtual interface, routes, and lifecycle, so Linux and desktop TUN settings do not map literally to iOS, macOS, and tvOS.

What is supported

  • iOS, macOS, and tvOS support Packet Tunnel and TUN configuration. Routine use does not require a virtual-device name or desktop routing parameters.
  • Hako installs platform-appropriate routes and may force, repair, or ignore TUN fields that do not apply to Network Extension.
  • macOS can expose process name, path, and UID routing metadata. iOS and tvOS cannot.

Three TUN stacks on Apple platforms

On iOS, macOS, and tvOS, Hako supports the gVisor, System, and Mixed TUN stacks across startup, TCP/UDP/DNS traffic, routing, reconnection, cross-stack switching, and clean shutdown.

Mixed runtime state is currently confirmed through configuration readback, switch state, and data-plane behavior; a dedicated runtime stack identifier will follow in a later Core delivery.

Not a default product surface

Local ports, allow-lan, custom listeners, tunnels, server configurations, and external controllers can expose services on the device. Core recognition does not mean a field is appropriate to enable by default. Apple Packet Tunnel also does not provide Linux interface-name, routing-mark, iptables, or TPROXY routing.

83 fields shown

FieldTypeiOSmacOStvOSPlatform notes
allow-lanboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
authentication[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
bind-addressstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
inbound-mptcpboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
inbound-tfoboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
interface-namestringUnsupportedUnsupportedUnsupportedLinux-style interface, mark, or iptables routing is unavailable in Apple Packet Tunnel.
iptables.bypass[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
iptables.dns-redirectboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
iptables.enableboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
iptables.inbound-interfacestringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
lan-allowed-ips[]netip.PrefixAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
lan-disallowed-ips[]netip.PrefixAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
listeners[]map[string]anyAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
mixed-portintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
portintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
redir-portintUnsupportedUnsupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime.
routing-markintUnsupportedUnsupportedUnsupportedLinux-style interface, mark, or iptables routing is unavailable in Apple Packet Tunnel.
skip-auth-prefixes[]netip.PrefixAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
socks-portintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
ss-configstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tproxy-portintUnsupportedUnsupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime.
tuic-server.alpn[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.authentication-timeoutintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.certificatestringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.congestion-controllerstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.cwndintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.enableboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.listenstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.max-idle-timeintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.max-udp-relay-packet-sizeintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.private-keystringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.token[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.usersmap[string]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tun.auto-detect-interfaceboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.auto-redirectboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-redirect-input-markuint32Not applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-redirect-iproute2-fallback-rule-indexintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-redirect-output-markuint32Not applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-routeboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.devicestringManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.disable-icmp-forwardingboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.dns-hijack[]stringManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.enableboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.endpoint-independent-natboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-dst-port[]uint16UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-dst-port-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-interface[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-mac-address[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-package[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.exclude-src-port[]uint16UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-src-port-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-uid[]uint32UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-uid-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.file-descriptorintManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.gsoboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.gso-max-sizeuint32Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.icmp-timeoutint64Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-android-user[]intNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.include-interface[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-mac-address[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-package[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.include-uid[]uint32UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-uid-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet4-route-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet4-route-exclude-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet6-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet6-route-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet6-route-exclude-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.iproute2-rule-indexintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.iproute2-table-indexintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.loopback-address[]netip.AddrManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.mtuuint32Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.recvmsgxboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.route-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.route-address-set[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.route-exclude-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.route-exclude-address-set[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.sendmsgxboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.stackC.TUNStackSupportedSupportedSupportediOS, macOS, and tvOS support gVisor, System, and Mixed. A dedicated Mixed runtime stack identifier will follow in a later Core delivery.
tun.strict-routeboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.udp-timeoutint64Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tunnels[]LC.TunnelAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
vmess-configstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.