Repository navigation
EN Core Proxy Modes
dongle edited this page Oct 9, 2026
·
2 revisions
SniShaper supports 5 proxy modes to handle different network environments and bypass requirements.
- Architecture: Client -> Optimization Node -> Target Site.
- Principle: Modifies the local DNS resolution or directly connects to the destination IP without terminating the TLS session. Suitable for environments where only DNS poisoning exists.
- Architecture: Client -> SniShaper (CA Decryption) -> Target Site.
- Principle: Decrypts the request using a local root certificate and then modifies the Custom Host/SNI or uses ECH injection before forwarding.
- Prerequisite: You must install the local root certificate.
- Note: If certificate verification fails, please click "Reinstall Certificate" in the settings.
- Architecture: Client -> Local H3 Replay -> Target Site.
-
Principle: The client-to-proxy connection is standard HTTPS, but the proxy-to-destination connection is forced to HTTP/3. It utilizes the scrambling features of
quic-goto bypass SNI detection. - Scenario: Use when the target site supports H3 (e.g., Google, YouTube) and TLS fragmentation is also ineffective.
- Architecture: Client -> Fragmented Handshake -> Target Site.
-
Principle: A customized TLS handshake feature blurring scheme. It performs the following:
- Multi-layer Fragmentation: Encapsulates the handshake packets into multiple TLS Record Layers or splits them into multiple TCP segments.
-
Precise Point Cutting: Tends to break at the last dot (
.) of the SNI domain. - Time Delay Interference: Introduces a small delay (e.g., 50ms) between segments to disrupt real-time firewall reassembly.
- Feature Confusion: Modifies TLS minor version numbers or uses OOB data injection.
- Note: Success rate depends on DPI iterations and may decrease over time.
-
Principle: With the help of a migration server (
migration server), an established TLS session with the target site is migrated to a new connection without redoing the handshake. - Use Case: Fast recovery when a connection gets reset mid-stream, reducing both the fingerprint exposure and the latency of a fresh handshake.
-
Configuration:
migration status|on|off|server|test(CLI).