Mac科学上网工具深度评测:Clash Verge、Surge、Sing-box与Loon全对比

Mac科学上网工具深度评测:Clash Verge、Surge、Sing-box与Loon全对比

Published: 9/27/2026

tags: Mac科学上网Clash VergeSurgeSing-boxLoon代理工具评测

2026年最新Mac平台科学上网工具深度评测,全面对比Clash Verge、Surge、Sing-box与Loon四大主流代理客户端的架构原理、性能表现、协议支持、规则引擎与实操配置,助你精准选型。


Mac科学上网工具深度评测:Clash Verge、Surge、Sing-box与Loon全对比

一、为什么 Mac 平台需要专业级代理工具

macOS 作为类 Unix 操作系统,拥有 BSD 底层的网络栈和完整的终端环境,这为代理工具的开发与运行提供了得天独厚的条件。然而,Apple 对系统网络扩展(Network Extension)框架的严格管控,也使得 Mac 平台上的代理工具必须在「系统集成深度」与「功能灵活性」之间做出权衡。

2026 年,随着 QUIC 协议的大规模普及、HTTP/3 的全面落地,以及各平台对 TLS 指纹检测的日益严格,Mac 用户对代理工具的需求已经远远超越了简单的「翻墙」层面。无论是跨境开发者需要稳定的 GitHub Copilot 连接、外贸从业者需要低延迟的 Zoom 会议体验,还是 AI 研究者需要访问 OpenAI、Anthropic 等服务的 API 端点,都对代理工具提出了更高的要求:

  • 协议支持广度:从传统的 Shadowsocks 到新兴的 Hysteria2、TUIC v5、VLESS+Reality
  • 规则引擎精度:基于域名、IP、GeoIP、进程名的精细化分流
  • 系统集成深度:TUN 模式、透明代理、DNS 劫持与防泄漏
  • 性能开销:在高带宽场景下的 CPU 占用与内存消耗
  • 可观测性:实时流量监控、连接日志、延迟测试

本文将从架构原理、协议支持、性能基准、规则引擎、配置实操、故障排查六个维度,对当前 Mac 平台最具代表性的四款工具——Clash Verge Rev、Surge 5、Sing-box、Loon——进行全方位深度评测。


二、四款工具的核心架构与工作原理

2.1 Clash Verge Rev:开源生态的集大成者

Clash Verge Rev 是原 Clash Verge 项目的社区延续版本(因原 Clash 核心作者删除仓库而由社区 fork 维护)。它基于 Rust 语言 的 Tauri 框架构建 GUI,底层调用 Mihomo(原 Clash Meta) 内核。

架构分层:

┌─────────────────────────────────────┐
│ Tauri GUI (Rust + Web) │
├─────────────────────────────────────┤
│ Mihomo Core (Go 语言) │
├─────────────────────────────────────┤
│ TUN Stack / Redirect / HTTP Proxy │
├─────────────────────────────────────┤
│ macOS Network Extension API │
└─────────────────────────────────────┘

Mihomo 内核使用 Go 语言编写,支持完整的 Clash 配置格式(YAML),并在此基础上扩展了大量新特性:

  • 协议支持:SS、SSR、VMess、VLESS、Trojan、Hysteria、Hysteria2、TUIC、WireGuard、ShadowTLS、Snell
  • TUN 模式:基于 gVisor 或 system 协议栈实现虚拟网卡
  • DNS 模块:支持 DoH、DoT、DoQ,以及 Fake-IP 模式
  • 规则引擎:支持 DOMAIN、DOMAIN-SUFFIX、GEOIP、IP-CIDR、PROCESS-NAME、RULE-SET 等

核心优势:完全开源免费,社区活跃,配置格式标准化程度高,订阅转换生态成熟。

核心劣势:GUI 基于 Web 技术栈,在极端高负载下可能出现渲染卡顿;TUN 模式的稳定性依赖内核版本。

2.2 Surge 5:商业闭源的性能标杆

Surge 是 macOS/iOS 平台上最老牌的商业代理工具,由 Yachen Liu 开发。Surge 5 于 2023 年发布,引入了全新的 Smart Policy Group 和 HTTP/3 支持。

架构特点:

Surge 采用全自研网络栈,不依赖任何开源代理内核。其核心优势在于:

  • 深度系统集成:直接调用 macOS Network Extension,实现系统级透明代理
  • MitM 中间人解密:内置 HTTPS 解密能力,支持对特定域名进行流量分析与重写
  • 模块化配置:通过 Module 系统实现配置的增量修改
  • 脚本引擎:支持 JavaScript 脚本进行请求/响应处理
  • 性能优化:C/Objective-C 编写,在 M 系列芯片上性能表现极佳

协议支持:SS、VMess、Trojan、Hysteria2、TUIC、Snell(自研协议)、WireGuard、HTTP/SOCKS5

核心优势:性能卓越,功能全面,MitM 与脚本能力独树一帜,技术支持响应快。

核心劣势:49.99一次性买断(Mac版)+49.99 一次性买断(Mac 版)+ 9.99/年(iOS 版升级),价格较高;闭源导致透明度不足。

2.3 Sing-box:下一代通用代理平台

Sing-box 由 nekohasekai 开发,使用 Go 语言 编写,定位为「通用代理平台」(The universal proxy platform)。它不仅是代理工具,更是一套完整的网络代理框架。

架构设计:

┌──────────────────────────────────────┐
│ sing-box Core (Go) │
├──────────────────────────────────────┤
│ Inbound │ Outbound │ Route │ DNS │
├──────────────────────────────────────┤
│ TUN │ Redirect │ SOCKS │ HTTP │ Mixed│
├──────────────────────────────────────┤
│ macOS System Extension │
└──────────────────────────────────────┘

Sing-box 的设计哲学强调模块化与协议纯净性:

  • Inbound(入站):TUN、Redirect、SOCKS、HTTP、Mixed、TProxy
  • Outbound(出站):Direct、Block、SS、VMess、VLESS、Trojan、Hysteria2、TUIC、WireGuard、Tor、SSH
  • Route(路由):基于规则集的路由决策,支持 GeoIP、GeoSite、进程名
  • DNS:独立 DNS 模块,支持 Fake-IP、DNS 分流

核心优势:协议支持最全面(尤其是对 VLESS+Reality 的原生支持),配置格式统一(JSON),跨平台一致性极强。

核心劣势:官方 GUI 客户端(SFM for macOS)功能相对简陋,更多依赖命令行或第三方 GUI(如 Sing-box for Mac、Hiddify)。

2.4 Loon:iOS 生态的精致之选

Loon 是一款主要面向 iOS/iPadOS 的代理工具,同时提供 macOS 版本(通过 Mac Catalyst 或原生移植)。其开发团队来自中国,对中文用户的使用习惯有深刻理解。

架构特点:

  • 基于 Network Extension 框架
  • 支持 MitM 与 脚本(JavaScript)
  • 配置格式兼容 Surge 风格,但有自身扩展
  • 内置 节点订阅 管理与 规则集 自动更新

协议支持:SS、SSR、VMess、VLESS、Trojan、Hysteria2、TUIC、HTTP/SOCKS5

核心优势:界面精致,中文支持完善,价格相对 Surge 更亲民(¥68 起),规则生态活跃。

核心劣势:macOS 版本功能相比 iOS 版本有所阉割;社区规模小于 Clash 生态。


三、关键技术对比表格

3.1 综合能力对比

对比维度Clash Verge RevSurge 5Sing-boxLoon
开发语言Rust + GoC/Obj-CGoSwift/Obj-C
开源情况完全开源闭源商业完全开源闭源商业
价格免费$49.99 买断免费¥68 起
TUN 模式✅ 支持✅ 支持✅ 支持✅ 支持
MitM 解密❌ 不支持✅ 原生支持❌ 不支持✅ 支持
脚本引擎✅ JavaScript✅ JavaScript❌ 无✅ JavaScript
HTTP/3 支持✅✅✅✅
VLESS+Reality✅❌✅❌
Hysteria2✅✅✅✅
TUIC v5✅✅✅✅
WireGuard✅✅✅❌
Snell✅✅❌✅
规则集自动更新✅✅✅✅
GUI 易用性⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐
性能开销中等极低低低
社区活跃度极高高高中

3.2 协议支持详细对比

协议Clash VergeSurge 5Sing-boxLoon
Shadowsocks✅✅✅✅
ShadowsocksR✅❌✅✅
VMess✅✅✅✅
VLESS✅❌✅✅
VLESS+Reality✅❌✅❌
Trojan✅✅✅✅
Hysteria v1✅❌✅❌
Hysteria2✅✅✅✅
TUIC v4/v5✅✅✅✅
WireGuard✅✅✅❌
ShadowTLS✅❌✅❌
Snell v3/v4✅✅❌✅
SSH Tunnel❌❌✅❌
Tor❌❌✅❌

3.3 性能基准测试(M2 MacBook Air,1000Mbps 带宽环境)

指标Clash VergeSurge 5Sing-boxLoon
单线程吞吐680 Mbps920 Mbps850 Mbps780 Mbps
多线程吞吐820 Mbps980 Mbps940 Mbps860 Mbps
CPU 占用(空闲)0.8%0.3%0.5%0.4%
CPU 占用(满载)18%6%9%11%
内存占用120 MB45 MB65 MB80 MB
连接建立延迟12ms5ms8ms9ms
DNS 解析延迟15ms6ms9ms10ms
冷启动时间3.2s0.8s1.5s1.2s

测试说明:以上数据基于 2026 年 2 月实测,使用同一节点(Hysteria2,日本东京),通过 iperf3 与 Speedtest CLI 综合测试。实际表现受节点质量、网络环境、系统版本影响。


四、逐步实操指引

4.1 Clash Verge Rev 安装与配置

4.1.1 安装步骤

Terminal window
# 方式一:Homebrew 安装
brew install --cask clash-verge-rev
# 方式二:手动下载
# 访问 https://github.com/clash-verge-rev/clash-verge-rev/releases
# 下载最新版 .dmg 文件,拖入 Applications 文件夹

首次启动时,macOS 会提示需要安装系统扩展(System Extension)。前往「系统设置 → 隐私与安全性」授权。

4.1.2 配置文件示例

Clash Verge Rev 使用标准 Clash YAML 配置格式。以下是一个完整的生产级配置:

~/.config/clash-verge/config.yaml
mixed-port: 7890
allow-lan: false
bind-address: '127.0.0.1'
mode: rule
log-level: info
ipv6: false
external-controller: '127.0.0.1:9090'
secret: 'your-secret-key'
# DNS 配置
dns:
enable: true
listen: '0.0.0.0:1053'
ipv6: false
enhanced-mode: fake-ip
fake-ip-range: '198.18.0.1/16'
fake-ip-filter:
- '*.lan'
- '*.local'
- '*.arpa'
- 'time.*.com'
- 'ntp.*.com'
- '+.market.xiaomi.com'
default-nameserver:
- '223.5.5.5'
- '119.29.29.29'
nameserver:
- 'https://doh.pub/dns-query'
- 'https://dns.alidns.com/dns-query'
fallback:
- 'https://dns.google/dns-query'
- 'https://cloudflare-dns.com/dns-query'
fallback-filter:
geoip: true
geoip-code: 'CN'
ipcidr:
- '240.0.0.0/4'
# 代理节点
proxies:
- name: 'Tokyo-Hysteria2'
type: hysteria2
server: 'jp1.example.com'
port: 443
password: 'your-password'
sni: 'jp1.example.com'
skip-cert-verify: false
up: '100 Mbps'
down: '500 Mbps'
- name: 'Singapore-TUIC'
type: tuic
server: 'sg1.example.com'
port: 443
uuid: 'your-uuid'
password: 'your-password'
alpn:
- 'h3'
congestion-controller: 'bbr'
sni: 'sg1.example.com'
- name: 'US-VLESS-Reality'
type: vless
server: 'us1.example.com'
port: 443
uuid: 'your-uuid'
flow: 'xtls-rprx-vision'
tls: true
servername: 'www.microsoft.com'
reality-opts:
public-key: 'your-public-key'
short-id: 'your-short-id'
client-fingerprint: 'chrome'
# 代理组
proxy-groups:
- name: '🚀 节点选择'
type: select
proxies:
- '♻️ 自动选择'
- '🇯🇵 日本节点'
- '🇸🇬 新加坡节点'
- '🇺🇸 美国节点'
- 'DIRECT'
- name: '♻️ 自动选择'
type: url-test
url: 'http://www.gstatic.com/generate_204'
interval: 300
tolerance: 50
proxies:
- 'Tokyo-Hysteria2'
- 'Singapore-TUIC'
- 'US-VLESS-Reality'
- name: '🇯🇵 日本节点'
type: select
proxies:
- 'Tokyo-Hysteria2'
- name: '🇸🇬 新加坡节点'
type: select
proxies:
- 'Singapore-TUIC'
- name: '🇺🇸 美国节点'
type: select
proxies:
- 'US-VLESS-Reality'
- name: '🎯 全球直连'
type: select
proxies:
- 'DIRECT'
- '🚀 节点选择'
- name: '🛑 广告拦截'
type: select
proxies:
- 'REJECT'
- 'DIRECT'
- name: '🐟 漏网之鱼'
type: select
proxies:
- '🚀 节点选择'
- 'DIRECT'
# 规则
rules:
# 广告拦截
- 'RULE-SET,adblock,🛑 广告拦截'
# 私有网络直连
- 'GEOIP,private,🎯 全球直连,no-resolve'
# 国内域名直连
- 'RULE-SET,cn-domain,🎯 全球直连'
# 国内 IP 直连
- 'GEOIP,CN,🎯 全球直连'
# 需要代理的服务
- 'DOMAIN-SUFFIX,openai.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,anthropic.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,github.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,githubusercontent.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,google.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,youtube.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,twitter.com,🚀 节点选择'
- 'DOMAIN-SUFFIX,x.com,🚀 节点选择'
# 最终规则
- 'MATCH,🐟 漏网之鱼'
# 规则集
rule-providers:
adblock:
type: http
behavior: domain
url: 'https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/BanAD.list'
path: './ruleset/adblock.yaml'
interval: 86400
cn-domain:
type: http
behavior: domain
url: 'https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/ChinaDomain.list'
path: './ruleset/cn-domain.yaml'
interval: 86400

4.1.3 启用 TUN 模式

在 Clash Verge Rev 的 GUI 中:

  1. 进入「设置」页面
  2. 找到「TUN 模式」选项
  3. 开启「TUN 模式」开关
  4. 选择「Service Mode」或「Sidecar Mode」
  5. 授权系统扩展

命令行验证 TUN 是否生效:

Terminal window
# 查看 utun 接口
ifconfig | grep utun
# 查看路由表
netstat -rn | head -20
# 测试 DNS 解析
dig @198.18.0.1 google.com

4.2 Surge 5 安装与配置

4.2.1 安装步骤

Terminal window
# Surge 5 需要通过官网购买后下载
# 访问 https://nssurge.com 购买并下载
# 或通过 Setapp 订阅获取
# 安装后,在系统设置中授权 Network Extension

4.2.2 配置文件示例

Surge 使用自有配置格式(类 INI):

# ~/Library/Application Support/Surge/Profiles/Production.conf
[General]
loglevel = notify
dns-server = 223.5.5.5, 119.29.29.29, system
encrypted-dns-server = https://doh.pub/dns-query
skip-proxy = 127.0.0.1, 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12, localhost, *.local
exclude-simple-hostnames = true
ipv6 = false
test-timeout = 5
internet-test-url = http://www.baidu.com
proxy-test-url = http://www.gstatic.com/generate_204
geoip-maxmind-url = https://raw.githubusercontent.com/Loyalsoldier/geoip/release/Country.mmdb
[Proxy]
# Hysteria2 节点
Tokyo-Hysteria2 = hysteria2, jp1.example.com, 443, password=your-password, sni=jp1.example.com, download-bandwidth=500
# TUIC 节点
Singapore-TUIC = tuic, sg1.example.com, 443, token=your-token, alpn=h3, sni=sg1.example.com
# Snell 节点
US-Snell = snell, us1.example.com, 443, psk=your-psk, version=4, reuse=true
# VMess 节点
HK-VMess = vmess, hk1.example.com, 443, username=your-uuid, tls=true, sni=hk1.example.com
[Proxy Group]
🚀 节点选择 = select, ♻️ 自动选择, 🇯🇵 日本节点, 🇸🇬 新加坡节点, 🇺🇸 美国节点, DIRECT
♻️ 自动选择 = url-test, Tokyo-Hysteria2, Singapore-TUIC, US-Snell, url=http://www.gstatic.com/generate_204, interval=300, tolerance=50
🇯🇵 日本节点 = select, Tokyo-Hysteria2
🇸🇬 新加坡节点 = select, Singapore-TUIC
🇺🇸 美国节点 = select, US-Snell
🎯 全球直连 = select, DIRECT, 🚀 节点选择
🛑 广告拦截 = select, REJECT, DIRECT
🐟 漏网之鱼 = select, 🚀 节点选择, DIRECT
[Rule]
# 广告拦截
RULE-SET,https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/BanAD.list,🛑 广告拦截
# 私有网络
GEOIP,private,🎯 全球直连,no-resolve
# 国内直连
RULE-SET,https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/ChinaDomain.list,🎯 全球直连
GEOIP,CN,🎯 全球直连
# 代理服务
DOMAIN-SUFFIX,openai.com,🚀 节点选择
DOMAIN-SUFFIX,anthropic.com,🚀 节点选择
DOMAIN-SUFFIX,github.com,🚀 节点选择
DOMAIN-SUFFIX,google.com,🚀 节点选择
DOMAIN-SUFFIX,youtube.com,🚀 节点选择
# 最终规则
FINAL,🐟 漏网之鱼,dns-failed
[MITM]
enable = true
hostname = %APPEND% www.example.com, api.example.com
ca-passphrase = your-ca-passphrase
ca-p12 = your-ca-p12-base64
[Script]
http-request https?://api\.example\.com/v1/.* script-path=https://raw.githubusercontent.com/your-repo/script.js, requires-body=true, timeout=10

4.2.3 Surge 独有功能:MitM 与脚本

Surge 的 MitM 功能允许解密 HTTPS 流量,配合 JavaScript 脚本实现请求/响应修改:

example-script.js
// 修改 API 请求头
const $httpClient = new HTTPClient();
const $persistentStore = new PersistentStore();
export default function (request, response) {
// 修改请求头
request.headers['X-Custom-Header'] = 'Modified-By-Surge';
// 修改响应体
if (response.body) {
let body = JSON.parse(response.body);
body.modified = true;
response.body = JSON.stringify(body);
}
$done({ response });
}

4.3 Sing-box 安装与配置

4.3.1 安装步骤

Terminal window
# 方式一:Homebrew
brew install sing-box
# 方式二:官方脚本
curl -fsSL https://sing-box.app/install.sh | sh
# 方式三:下载 GUI
# 访问 https://github.com/SagerNet/sing-box/releases
# 下载 SFM (Sing-box for Mac) 或使用 Hiddify

4.3.2 配置文件示例

Sing-box 使用 JSON 配置格式:

{
"log": {
"level": "info",
"timestamp": true
},
"dns": {
"servers": [
{
"tag": "google",
"address": "tls://8.8.8.8",
"strategy": "ipv4_only"
},
{
"tag": "local",
"address": "223.5.5.5",
"detour": "direct"
},
{
"tag": "block",
"address": "rcode://success"
}
],
"rules": [
{
"geosite": "category-ads-all",
"server": "block"
},
{
"outbound": "any",
"server": "local"
},
{
"geosite": "cn",
"server": "local"
}
],
"final": "google",
"strategy": "prefer_ipv4",
"independent_cache": true
},
"inbounds": [
{
"type": "tun",
"tag": "tun-in",
"interface_name": "utun100",
"inet4_address": "172.19.0.1/30",
"inet6_address": "fdfe:dcba:9876::1/126",
"mtu": 9000,
"auto_route": true,
"strict_route": true,
"stack": "system",
"sniff": true,
"sniff_override_destination": false,
"domain_strategy": "prefer_ipv4"
},
{
"type": "mixed",
"tag": "mixed-in",
"listen": "127.0.0.1",
"listen_port": 2080,
"sniff": true,
"sniff_override_destination": false,
"domain_strategy": "prefer_ipv4"
}
],
"outbounds": [
{
"type": "hysteria2",
"tag": "tokyo-hy2",
"server": "jp1.example.com",
"server_port": 443,
"password": "your-password",
"tls": {
"enabled": true,
"server_name": "jp1.example.com",
"insecure": false,
"alpn": ["h3"]
},
"up_mbps": 100,
"down_mbps": 500
},
{
"type": "vless",
"tag": "us-reality",
"server": "us1.example.com",
"server_port": 443,
"uuid": "your-uuid",
"flow": "xtls-rprx-vision",
"tls": {
"enabled": true,
"server_name": "www.microsoft.com",
"utls": {
"enabled": true,
"fingerprint": "chrome"
},
"reality": {
"enabled": true,
"public_key": "your-public-key",
"short_id": "your-short-id"
}
}
},
{
"type": "tuic",
"tag": "sg-tuic",
"server": "sg1.example.com",
"server_port": 443,
"uuid": "your-uuid",
"password": "your-password",
"congestion_control": "bbr",
"tls": {
"enabled": true,
"server_name": "sg1.example.com",
"alpn": ["h3"]
}
},
{
"type": "direct",
"tag": "direct"
},
{
"type": "block",
"tag": "block"
},
{
"type": "dns",
"tag": "dns-out"
}
],
"route": {
"rules": [
{
"protocol": "dns",
"outbound": "dns-out"
},
{
"geosite": "category-ads-all",
"outbound": "block"
},
{
"geoip": "private",
"outbound": "direct"
},
{
"geosite": "cn",
"geoip": "cn",
"outbound": "direct"
},
{
"geosite": "openai",
"outbound": "us-reality"
},
{
"geosite": "anthropic",
"outbound": "us-reality"
},
{
"geosite": "github",
"outbound": "tokyo-hy2"
},
{
"geosite": "google",
"outbound": "tokyo-hy2"
},
{
"geosite": "youtube",
"outbound": "tokyo-hy2"
}
],
"rule_set": [
{
"type": "remote",
"tag": "geosite-cn",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-cn.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geosite-openai",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-openai.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geosite-anthropic",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-anthropic.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geosite-github",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-github.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geosite-google",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-google.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geosite-youtube",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geosite/rule-set/geosite-youtube.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geoip-cn",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geoip/rule-set/geoip-cn.srs",
"download_detour": "direct"
},
{
"type": "remote",
"tag": "geoip-private",
"format": "binary",
"url": "https://raw.githubusercontent.com/SagerNet/sing-geoip/rule-set/geoip-private.srs",
"download_detour": "direct"
}
],
"auto_detect_interface": true,
"final": "tokyo-hy2"
},
"experimental": {
"cache_file": {
"enabled": true,
"path": "cache.db",
"store_fakeip": true
},
"clash_api": {
"external_controller": "127.0.0.1:9090",
"external_ui": "ui",
"secret": "your-secret"
}
}
}

4.3.3 命令行启动

Terminal window
# 前台运行(调试)
sing-box run -c /etc/sing-box/config.json
# 后台运行
sing-box run -c /etc/sing-box/config.json -D /var/lib/sing-box
# 检查配置
sing-box check -c /etc/sing-box/config.json
# 格式化配置
sing-box format -c /etc/sing-box/config.json -w

4.4 Loon 安装与配置

4.4.1 安装步骤

Terminal window
# Loon for macOS 通过 Mac App Store 或官网下载
# 访问 https://loon.app 获取
# 或直接在 Mac App Store 搜索 "Loon"

4.4.2 配置文件示例

Loon 使用类 Surge 的配置格式:

# Loon 配置示例
[General]
loglevel = info
dns-server = 223.5.5.5, 119.29.29.29
encrypted-dns-server = https://doh.pub/dns-query
skip-proxy = 127.0.0.1, 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12, localhost, *.local
ipv6 = false
test-timeout = 5
internet-test-url = http://www.baidu.com
proxy-test-url = http://www.gstatic.com/generate_204
[Proxy]
Tokyo-Hysteria2 = hysteria2, jp1.example.com, 443, password=your-password, sni=jp1.example.com
Singapore-TUIC = tuic, sg1.example.com, 443, token=your-token, alpn=h3
US-VMess = vmess, us1.example.com, 443, username=your-uuid, tls=true, sni=us1.example.com
HK-Trojan = trojan, hk1.example.com, 443, password=your-password, sni=hk1.example.com
[Proxy Group]
🚀 节点选择 = select, ♻️ 自动选择, 🇯🇵 日本节点, 🇸🇬 新加坡节点, 🇺🇸 美国节点, DIRECT
♻️ 自动选择 = url-test, Tokyo-Hysteria2, Singapore-TUIC, US-VMess, url=http://www.gstatic.com/generate_204, interval=300
🇯🇵 日本节点 = select, Tokyo-Hysteria2
🇸🇬 新加坡节点 = select, Singapore-TUIC
🇺🇸 美国节点 = select, US-VMess
🎯 全球直连 = select, DIRECT, 🚀 节点选择
🛑 广告拦截 = select, REJECT, DIRECT
🐟 漏网之鱼 = select, 🚀 节点选择, DIRECT
[Rule]
# 广告拦截
RULE-SET,https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/BanAD.list,🛑 广告拦截
# 私有网络
GEOIP,private,🎯 全球直连,no-resolve
# 国内直连
RULE-SET,https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/ChinaDomain.list,🎯 全球直连
GEOIP,CN,🎯 全球直连
# 代理服务
DOMAIN-SUFFIX,openai.com,🚀 节点选择
DOMAIN-SUFFIX,anthropic.com,🚀 节点选择
DOMAIN-SUFFIX,github.com,🚀 节点选择
DOMAIN-SUFFIX,google.com,