Skip to content

EN Core Proxy Modes

dongle edited this page Oct 9, 2026 · 2 revisions

中文 | English | Русский

Core Proxy Modes Introduction

SniShaper supports 5 proxy modes to handle different network environments and bypass requirements.

1. Transparent (Direct)

  • Architecture: Client -> Optimization Node -> Target Site.
  • Principle: Modifies the local DNS resolution or directly connects to the destination IP without terminating the TLS session. Suitable for environments where only DNS poisoning exists.

2. MITM (Intermediate)

  • Architecture: Client -> SniShaper (CA Decryption) -> Target Site.
  • Principle: Decrypts the request using a local root certificate and then modifies the Custom Host/SNI or uses ECH injection before forwarding.
  • Prerequisite: You must install the local root certificate.
  • Note: If certificate verification fails, please click "Reinstall Certificate" in the settings.

3. QUIC (HTTP/3 Replay)

  • Architecture: Client -> Local H3 Replay -> Target Site.
  • Principle: The client-to-proxy connection is standard HTTPS, but the proxy-to-destination connection is forced to HTTP/3. It utilizes the scrambling features of quic-go to bypass SNI detection.
  • Scenario: Use when the target site supports H3 (e.g., Google, YouTube) and TLS fragmentation is also ineffective.

4. TLS-RF (TLS Fragmentation)

  • Architecture: Client -> Fragmented Handshake -> Target Site.
  • Principle: A customized TLS handshake feature blurring scheme. It performs the following:
    • Multi-layer Fragmentation: Encapsulates the handshake packets into multiple TLS Record Layers or splits them into multiple TCP segments.
    • Precise Point Cutting: Tends to break at the last dot (.) of the SNI domain.
    • Time Delay Interference: Introduces a small delay (e.g., 50ms) between segments to disrupt real-time firewall reassembly.
    • Feature Confusion: Modifies TLS minor version numbers or uses OOB data injection.
  • Note: Success rate depends on DPI iterations and may decrease over time.

5. Migration (TLS 1.2 Session Resumption)

  • Principle: With the help of a migration server (migration server), an established TLS session with the target site is migrated to a new connection without redoing the handshake.
  • Use Case: Fast recovery when a connection gets reset mid-stream, reducing both the fingerprint exposure and the latency of a fresh handshake.
  • Configuration: migration status|on|off|server|test (CLI).

Clone this wiki locally