Quick start
DirectLane · Apple Silicon · macOS 14+ · Pre-release
Choose a connection rule, try it for 90 seconds, then check the result before keeping it. Start with one application so the effect is easy to understand.
Before you begin
Keep the app in Applications. DirectLane needs permission for its network extension and background safety service; macOS presents the approval steps when you enable it.
Your first rule
- Open Direct applications and add the application you want to connect directly.
- Review the selected application and any existing blocking or conditional rules.
- Enable DirectLane and complete the macOS approval prompts.
- During the 90-second safety trial, reconnect the selected application and open Diagnostics.
- Check the physical-interface evidence and errors. Keep the configuration only when the result is correct; otherwise stop DirectLane.
An application loading successfully does not by itself prove a direct connection. Check the connection’s binding evidence in Diagnostics.
Choose another kind of rule →
Connection rules
Rules decide what happens to the connections DirectLane can control. Unmatched connections keep the system’s normal networking path.
Choose the right group
| Group | Use it for |
|---|
| ⓪ Block connections | Block a selected application or a global domain/IP target. |
| ① Conditional networking | Block or force direct access when another application is running or not running. |
| ② Direct applications | Route the selected application’s controlled TCP/UDP connections directly. |
| ③ Direct domains/IPs | Route matching targets directly across applications, within the TCP scope. |
| ④ Domains/IPs within an application | Route only that application’s selected targets directly, within the TCP scope. |
Write a target
Use example.com or *.example.com; both match the domain and its subdomains. Use a real public IP or a canonical CIDR, such as 1.1.1.0/24. Internationalized names use punycode. URLs, paths, ports and local/private addresses are not accepted as domain/IP targets.
Priority and changes
Active blocks take priority over conditional direct rules, then ordinary direct rules. A condition ending does not remove another rule’s block. Edits are saved immediately; check whether the running extension reports them as applied. Effective rule changes close controlled relays so connections can reconnect under the new policy.
Read the connection scope →
Conditional networking
A condition has a trigger application, a running/not-running state, an action and its own application or domain/IP targets.
Two examples
- When a selected work application is running, force another selected application to connect directly.
- When a selected proxy application is not running, block a selected application’s connections.
Enable the rule, select the trigger and state, then choose Block or Force direct and add its targets. Check the observed state in Diagnostics.
What the state means
“Running” means the application was identified as running. It does not prove that its proxy is ready, check a proxy node, or inspect Global/TUN mode. If the state cannot be established, blocking stays conservative and direct access is not granted.
When it changes
New connections use the new effective rules. Controlled relays close when the effective policy changes. Connections already handed back to macOS cannot be guaranteed to stop immediately. Once the extension is stopped, conditional rules no longer provide protection.
Check a condition in Diagnostics →
The 90-second safety trial
The trial is a short opportunity to check the network configuration before retaining it. It is separate from any purchase or licensing terms.
Try, inspect, keep
- Enable DirectLane and check that the trial has started.
- Make a new connection from your selected application.
- Inspect the physical interface, condition state and recent errors in Diagnostics.
- Confirm that you want to keep the configuration before the trial expires, or stop it.
If you do not confirm in time, DirectLane’s safety flow rolls back its own network configuration. If a safety check fails, the trial can end early. Changing rules does not extend the countdown or confirm the trial.
If readiness fails
Do not assume the extension is active because an approval prompt was accepted. Read the status and diagnostic error, check macOS permission/background-service settings, and stop if the state is unclear. Contact support with the version and error rather than repeatedly trying to retain an unverified configuration.
Stopping DirectLane returns traffic to normal system networking; its blocking rules do not continue protecting connections while the extension is off.
Diagnostics
Use Diagnostics to understand whether a rule matched and whether a controlled connection used the requested physical interface.
What to inspect
- Status: extension state, trial state and recent validation errors.
- Identity: whether the selected application could be identified and its signature accepted.
- Conditions: the observed trigger state and whether each rule is active.
- Connections: connected, blocked and failed counts, plus recent errors.
- Binding: the requested and observed physical interface for a controlled direct connection.
Evidence for a direct path
In detailed connection data, look for bindingVerified=true, matching non-zero requestedInterfaceIndex and observedInterfaceIndex, and the intended physical bindingInterface. A website response or the presence of traffic on Wi-Fi alone is insufficient.
Share a useful report
Include your macOS and DirectLane versions, the rule group, expected behavior, observed behavior and relevant error. Review copied/exported diagnostics before sending them; they can contain application names, domains, IPs and local network information.
Contact support →
Scope & compatibility
DirectLane works with the connection metadata available to its network extension. Choose rules with these boundaries in mind.
TCP and UDP
Application direct rules support controlled TCP/UDP. Domain/IP direct rules grant TCP paths. Without application-level direct authorization, matching Web UDP on ports 80/443 is refused to encourage a TCP retry; other UDP keeps its system path.
Names and identities
Encrypted or hidden hostnames, including ECH, can limit domain matching. Not every proxy protocol exposes its final target. Store builds identify the source of the current connection and do not promise to identify arbitrary external child processes through their parent application. Applications outside supported locations may fail signature checks.
Your existing network
DirectLane does not change Clash, the system proxy or other applications’ proxy settings. Verified Clash/Mihomo integration is optional. Local, loopback and overlay-network traffic generally retains its existing route; blocking rules have their own scope. When no usable physical interface exists or direct binding fails, a selected direct connection fails rather than falling back to the system path.
Network changes
Changing Wi-Fi, switching Ethernet or waking the Mac can interrupt controlled connections. Allow the target application to reconnect, then check fresh diagnostics. Do not assume an existing connection migrated seamlessly.
Common questions
Do I need Clash?
No. The Store build uses the system environment by default. Verified Clash/Mihomo integration is an additional capability.
Why did my direct rule not work?
Check active blocking rules first, then the condition, source identity, destination visibility and physical interface. Make a new connection; a connection created before the effective rule changed may have remained with macOS.
Why did the trial stop early?
A failed safety or readiness check can end it before 90 seconds. Read the reported failure in Diagnostics; do not treat an early stop as a successful retained configuration.
How do I stop or remove it?
Stop direct networking in the app, then use its network-extension removal control and wait for macOS to report the result before removing the application. If needed, stop the extension in System Settings. Removing an app does not necessarily remove data retained in its macOS container.
How do I change the language?
The application and this website each offer Follow system, English, Traditional Chinese and Simplified Chinese. The website remembers its own choice; changing it does not change your app preference.
Still need help? →
快速開始
DirectLane · Apple Silicon · macOS 14+ · 發佈前
選擇規則,進行 90 秒安全試用,再檢查結果後保留。第一次先選一個應用程式,方便觀察規則的效果。
開始前
將應用程式放在「應用程式」中。DirectLane 需要網路延伸功能與背景守護程式權限;啟用時依 macOS 提示完成允許步驟。
第一條規則
- 開啟「直連應用」,加入希望直連的應用程式。
- 檢查所選應用程式,以及既有禁止和條件規則。
- 啟用 DirectLane,完成 macOS 的權限提示。
- 在 90 秒安全試用內,讓目標應用程式重新連線並開啟診斷。
- 檢查實體介面證據與錯誤。結果正確才確認保留,否則關閉 DirectLane。
應用程式能載入內容,並不能單獨證明已直連。請在診斷中核對連線的介面綁定證據。
了解其他規則 →
連線規則
規則決定 DirectLane 能控制的連線如何處理。未符合規則的連線維持系統原本的網路路徑。
選擇分組
| 分組 | 適用情境 |
|---|
| ⓪ 禁止聯網 | 禁止指定應用程式,或全域網域/IP 目標連線。 |
| ① 條件聯網 | 依另一個應用程式執行/未執行,禁止或強制直連。 |
| ② 直連應用 | 讓所選應用程式的受管 TCP/UDP 連線直連。 |
| ③ 直連網域、IP | 所有應用程式符合目標的連線直連,限 TCP 範圍。 |
| ④ 應用裡的網域、IP | 只讓該應用程式的指定目標直連,限 TCP 範圍。 |
填寫目標
網域使用 example.com 或 *.example.com,兩者均包含該網域及子網域。IP 使用真實公用位址或規範 CIDR,例如 1.1.1.0/24。國際化網域使用 punycode。不接受 URL、路徑、連接埠或本機/私有位址作為網域/IP 目標。
優先順序與修改
生效的禁止規則優先於條件直連,再優先於普通直連。一條條件解除,不會解除其他規則的禁止。修改立即儲存,執行中的延伸功能是否已套用,請查看下發狀態。有效規則改變會關閉受管中繼,重新連線後使用新策略。
查看連線範圍 →
條件聯網
一條條件規則包含觸發應用程式、執行/未執行狀態、動作,以及獨立的應用程式或網域/IP 目標。
兩個例子
- 當指定工作應用程式正在執行,強制另一個所選應用程式直連。
- 當指定代理應用程式未執行,禁止所選應用程式連線。
啟用規則,選擇觸發應用程式與狀態,再選擇「禁止聯網」或「強制直連」並加入目標。在診斷中核對實際觀察到的狀態。
狀態的含義
「正在執行」代表已識別該應用程式正在執行,不代表代理服務已就緒,也不檢查代理節點或 Global/TUN 模式。無法確認狀態時,禁止規則保守生效,直連不會取得授權。
狀態改變時
新連線使用新的生效規則。有效策略改變會關閉受管中繼;已交還 macOS 的既有連線,無法保證立即切斷。延伸功能停止後,條件規則不再提供保護。
在診斷中查看條件 →
90 秒安全試用
安全試用讓你在保留網路設定前檢查效果,與購買或授權條款分開。
試用、檢查、保留
- 啟用 DirectLane,確認安全試用已開始。
- 讓所選應用程式建立新的連線。
- 在診斷中查看實體介面、條件狀態與近期錯誤。
- 在期限內確認保留,或關閉 DirectLane。
逾時未確認時,DirectLane 的安全流程會回復自身網路設定;安全檢查失敗時,試用也可能提早結束。修改規則不會延長倒數,也不會自動確認試用。
未能就緒時
允許了權限提示,不代表延伸功能一定已啟用。請查看狀態與診斷錯誤,檢查 macOS 權限及背景服務設定;狀態不明時先停止。向支援提供版本及錯誤,不要反覆嘗試保留未驗證的設定。
關閉 DirectLane 後,流量回到系統一般網路;延伸功能關閉期間,禁止規則不會持續保護連線。
診斷
診斷協助你確認規則是否符合,以及受管直連是否使用指定的實體介面。
檢查項目
- 狀態:延伸功能、試用狀態與近期驗證錯誤。
- 身分:是否識別所選應用程式,簽名是否通過檢查。
- 條件:觸發應用程式的觀察狀態,以及規則是否生效。
- 連線:已連線、禁止與失敗計數,以及近期錯誤。
- 綁定:受管直連所要求與實際讀回的實體介面。
直連的證據
詳細連線資料應包含 bindingVerified=true,非零且相同的 requestedInterfaceIndex 與 observedInterfaceIndex,以及預期實體介面的 bindingInterface。僅網站回應成功,或 Wi-Fi 上有流量,都不足以證明。
提供有用的回報
請附 macOS 與 DirectLane 版本、規則分組、預期與實際行為,以及相關錯誤。複製/匯出診斷後,傳送前先檢查內容:其中可能包含應用程式名稱、網域、IP 與本機網路資訊。
聯絡支援 →
範圍與相容性
DirectLane 使用網路延伸功能可取得的連線中繼資料。選擇規則時,請考慮以下範圍。
TCP 與 UDP
應用程式直連支援受管 TCP/UDP。網域/IP 直連授予 TCP 路徑;沒有應用程式層級直連授權時,符合目標的 Web UDP 80/443 被拒絕以促使 TCP 重試,其他 UDP 維持系統路徑。
名稱與身分
加密或隱藏主機名稱(例如 ECH)可能限制網域比對,不是每種代理協定都會暴露最終目標。Store 版本識別目前連線的來源,不保證透過父應用程式識別任意外部子進程。不在支援位置的應用程式,可能無法通過簽名檢查。
既有網路
DirectLane 不變更 Clash、系統代理或其他應用程式的代理設定;已驗證的 Clash/Mihomo 整合是額外能力。本機、回環與組網流量通常維持原路徑,禁止規則有自己的作用範圍。沒有可用實體介面或直連綁定失敗時,所選直連會失敗,不會退回系統路徑。
網路變化
更換 Wi-Fi、切換有線網路或喚醒 Mac,可能中斷受管連線。讓目標應用程式重新連線,再查看新的診斷;不要假設既有連線已無縫遷移。
常見問題
需要 Clash 嗎?
不需要。Store 版本預設使用系統環境;已驗證的 Clash/Mihomo 整合提供額外能力。
直連規則為什麼沒有生效?
先檢查生效的禁止規則,再查看條件、來源身分、目標是否可見,以及實體介面。請建立新連線;規則改變前已建立的連線,可能仍由 macOS 處理。
試用為什麼提早結束?
安全或就緒檢查失敗,可能讓試用在 90 秒前結束。請在診斷中查看失敗原因,不要把提早結束當成已成功保留設定。
如何停止或移除?
先在應用程式中關閉直連,再使用移除網路延伸功能的控制,等待 macOS 回報結果後再移除應用程式。必要時從系統設定停止延伸功能。移除應用程式不一定會刪除 macOS 容器內保留的資料。
如何切換語言?
應用程式與本網站各自提供隨系統、英文、繁體中文與簡體中文。網站單獨儲存自己的選擇,不會改變應用程式的語言偏好。
仍需要協助? →
快速开始
DirectLane · Apple Silicon · macOS 14+ · 发布前
选择规则,进行 90 秒安全试用,再检查结果后保留。第一次先选一个应用,方便观察规则的效果。
开始前
将应用放在“应用程序”中。DirectLane 需要网络扩展和后台守护权限;开启时按 macOS 提示完成允许步骤。
第一条规则
- 打开“直连应用”,添加希望直连的应用。
- 检查所选应用,以及现有禁止和条件规则。
- 开启 DirectLane,完成 macOS 的权限提示。
- 在 90 秒安全试用内,让目标应用重新连接并打开诊断。
- 检查物理接口证据和错误。结果正确才确认保留,否则关闭 DirectLane。
应用能加载内容,并不能单独证明已直连。请在诊断中核对连接的接口绑定证据。
了解其他规则 →
连接规则
规则决定 DirectLane 能控制的连接如何处理。未命中规则的连接保持系统原本的网络路径。
选择分组
| 分组 | 适用场景 |
|---|
| ⓪ 禁止联网 | 禁止指定应用,或全局域名/IP 目标连接。 |
| ① 条件联网 | 按另一个应用运行/未运行,禁止或强制直连。 |
| ② 直连应用 | 让所选应用的受管 TCP/UDP 连接直连。 |
| ③ 直连域名、IP | 所有应用命中目标的连接直连,限 TCP 范围。 |
| ④ 应用里的域名、IP | 只让该应用的指定目标直连,限 TCP 范围。 |
填写目标
域名使用 example.com 或 *.example.com,两者均包含该域名及子域。IP 使用真实公网地址或规范 CIDR,例如 1.1.1.0/24。国际化域名使用 punycode。不接受 URL、路径、端口或本地/私有地址作为域名/IP 目标。
优先级与修改
生效的禁止规则优先于条件直连,再优先于普通直连。一条条件解除,不会解除其他规则的禁止。修改立即保存,运行中的扩展是否已应用,请查看下发状态。有效规则改变会关闭受管中继,重新连接后使用新策略。
查看连接范围 →
条件联网
一条条件规则包含触发应用、运行/未运行状态、动作,以及独立的应用或域名/IP 目标。
两个例子
- 当指定工作应用正在运行,强制另一个所选应用直连。
- 当指定代理应用未运行,禁止所选应用连接。
启用规则,选择触发应用与状态,再选择“禁止联网”或“强制直连”并添加目标。在诊断中核对实际观察到的状态。
状态的含义
“正在运行”代表已识别该应用正在运行,不代表代理服务已就绪,也不检查代理节点或 Global/TUN 模式。无法确认状态时,禁止规则保守生效,直连不会获得授权。
状态改变时
新连接使用新的生效规则。有效策略改变会关闭受管中继;已经交还 macOS 的现有连接,无法保证立即切断。扩展停止后,条件规则不再提供保护。
在诊断中查看条件 →
90 秒安全试用
安全试用让你在保留网络设置前检查效果,与购买或许可条款分开。
试用、检查、保留
- 开启 DirectLane,确认安全试用已开始。
- 让所选应用建立新的连接。
- 在诊断中查看物理接口、条件状态与近期错误。
- 在期限内确认保留,或关闭 DirectLane。
超时未确认时,DirectLane 的安全流程会恢复自身网络配置;安全检查失败时,试用也可能提前结束。修改规则不会延长倒计时,也不会自动确认试用。
未能就绪时
允许了权限提示,不代表扩展一定已开启。请查看状态与诊断错误,检查 macOS 权限及后台服务设置;状态不明时先停止。向支持提供版本和错误,不要反复尝试保留未验证的设置。
关闭 DirectLane 后,流量回到系统正常网络;扩展关闭期间,禁止规则不会持续保护连接。
诊断
诊断帮助你确认规则是否命中,以及受管直连是否使用指定的物理接口。
检查项目
- 状态:扩展、试用状态与近期验证错误。
- 身份:是否识别所选应用,签名是否通过检查。
- 条件:触发应用的观察状态,以及规则是否生效。
- 连接:已连接、禁止与失败计数,以及近期错误。
- 绑定:受管直连所要求与实际读回的物理接口。
直连的证据
详细连接数据应包含 bindingVerified=true,非零且相同的 requestedInterfaceIndex 与 observedInterfaceIndex,以及预期物理接口的 bindingInterface。仅网站响应成功,或 Wi-Fi 上有流量,都不足以证明。
提供有用的反馈
请附 macOS 与 DirectLane 版本、规则分组、预期与实际行为,以及相关错误。复制/导出诊断后,发送前先检查内容:其中可能包含应用名称、域名、IP 与本地网络信息。
联系支持 →
范围与兼容性
DirectLane 使用网络扩展能获得的连接元数据。选择规则时,请考虑以下范围。
TCP 与 UDP
应用直连支持受管 TCP/UDP。域名/IP 直连授予 TCP 路径;没有应用级直连授权时,命中目标的 Web UDP 80/443 被拒绝以促使 TCP 重试,其他 UDP 保持系统路径。
名称与身份
加密或隐藏主机名(例如 ECH)可能限制域名匹配,不是每种代理协议都会暴露最终目标。Store 版本识别当前连接的来源,不保证通过父应用识别任意外部子进程。不在支持位置的应用,可能无法通过签名检查。
现有网络
DirectLane 不更改 Clash、系统代理或其他应用的代理配置;已验证的 Clash/Mihomo 集成是额外能力。本地、回环与组网流量通常保持原路径,禁止规则有自己的作用范围。没有可用物理接口或直连绑定失败时,所选直连会失败,不会回退到系统路径。
网络变化
更换 Wi-Fi、切换有线网络或唤醒 Mac,可能中断受管连接。让目标应用重新连接,再查看新的诊断;不要假设现有连接已无缝迁移。
常见问题
需要 Clash 吗?
不需要。Store 版本默认使用系统环境;已验证的 Clash/Mihomo 集成提供额外能力。
直连规则为什么没有生效?
先检查生效的禁止规则,再查看条件、来源身份、目标是否可见,以及物理接口。请建立新连接;规则改变前建立的连接,可能仍由 macOS 处理。
试用为什么提前结束?
安全或就绪检查失败,可能让试用在 90 秒前结束。请在诊断中查看失败原因,不要把提前结束当成已成功保留设置。
如何停止或移除?
先在应用中关闭直连,再使用移除网络扩展的控制,等待 macOS 返回结果后再移除应用。必要时从系统设置停止扩展。移除应用不一定会删除 macOS 容器内保留的数据。
如何切换语言?
应用与本网站各自提供随系统、英文、繁体中文与简体中文。网站单独保存自己的选择,不会改变应用的语言偏好。
仍需要帮助? →