Snell
Snell is a lean encrypted proxy protocol developed by our team. Here are some highlights:
Extreme performance.
Support UDP over TCP relay.
Single binary with zero dependencies. (except glibc)
A wizard to help you start.
Proxy server will report remote errors to the client if an error encounters. Clients may choose countermeasures for different scenarios.
https://dl.nssurge.com/snell/snell-server-v5.0.1-linux-amd64.zip
https://dl.nssurge.com/snell/snell-server-v5.0.1-linux-i386.zip
https://dl.nssurge.com/snell/snell-server-v5.0.1-linux-aarch64.zip
https://dl.nssurge.com/snell/snell-server-v5.0.1-linux-armv7l.zipSnell is a proxy protocol designed with performance as its primary objective. As a deliberate design trade-off, it omits certain security properties and uses lighter-weight cryptographic parameters where the associated overhead would have a measurable impact on performance.
If your primary goal is maximizing security guarantees rather than minimizing overhead, we recommend using a TLS-based proxy protocol instead. Snell is designed for users who are willing to make carefully considered security-performance trade-offs in exchange for lower latency, lower resource consumption, and higher throughput.
Release Notes
v6.0.0 Beta
Snell v6 features PSK-derived deployment-level protocol diversity that generates unique traffic characteristics for each deployment, significantly reducing reliance on a single protocol fingerprint while preserving Snell’s core goals of performance, deployment simplicity, accurate error reporting, and full TCP semantics. Snell v6 also removes QUIC Proxy Mode, adds new IPv4/IPv6 network stack controls including dns-ip-preference and multi-address listen support, and is currently available for beta testing.
Please check our blog for more information.
Beta 2 Updates
Fixed an issue that performance unexpectedly dropped significantly.
Fixed an issue with external dynamic dependency libraries.
Please note that this version adjusts the protocol profile, so Surge Mac also needs to be updated to the latest version.
Beta 3 Updates
Snell v6 beta 3 has added a mode setting.
mode=defaultDefault mode, enables traffic obfuscation and AES encryption.mode=unshapedDisables obfuscation and uses only AES encryption. Compared with the default mode, throughput performance can be improved by about 10%. This mode is equivalent to Snell v3, where the encrypted traffic appears completely random.mode=unsafe-rawDisables encryption and obfuscation, forwarding all traffic in plaintext. It should only be used in secure network environments, such as an intranet or under another secure tunnel.
Please note that the server mode and client mode must be consistent.
Beta 4 Updates
Fixed some potential issues in UDP forwarding mode.
Upgraded all dependency libraries to the latest versions.
Removed UPX shell to avoid failure to run in certain server environments.
RC Updates
Fix the issue where the first few UDP packets may be truncated when forwarding starts.
RC2 Updates
When
ipv6=false, return a clearer error message when the client explicitly accesses an IPv6 address.
v5.0.1
Fixed a low-probability crash caused by an assertion.
v5.0.0
Dynamic Record Sizing
This feature will improve latency performance under network environments with packet loss. For technical details, refer to: Cloudflare Blog
QUIC Proxy Mode
Snell v5 introduces a special QUIC Proxy mode designed for QUIC traffic. This mode works as UDP over UDP to avoid TCP over UDP issues. (The server needs to open a UDP port.)
This working mode is specially optimized for QUIC. It is only enabled when Surge detects QUIC traffic; other UDP traffic still uses the UDP over TCP mode.
QUIC Proxy will only strongly encrypt the QUIC Handshake packets to protect SNI and target hostnames, while also performing authentication. All subsequent QUIC packets, already strongly encrypted by QUIC itself, will be forwarded as raw packets, greatly reducing unnecessary encryption and decryption overhead. Additionally, since no extra bytes are introduced, QUIC's PMTU probing will not be affected.
Egress Control
Supports configuration of the
egress-interfaceparameter to control the egress interface (requires root privileges orCAP_NET_RAW/CAP_NET_ADMINlicense, and the interface must have routing tables for the target address and DNS).Supports systemd's Socket Activation mechanism, which can be used to configure network namespaces as well as for egress interface profile. We will provide configuration examples later.
v4.1.1
Fix a potential crash that may occur during UDP forwarding.
v4.1.0
Add a dns parameter for customizing DNS server addresses, supporting multiple address configurations.
Update the DNS library c-ares to the latest version to resolve compatibility issues with specific DNS records.
Add output of the currently used DNS server at startup.
Adjust log output to lower broken pipe error messages to verbose level.
Update libuv to v1.48.0 to fix potential crashes when accessing IPv6 addresses on certain systems.
Improve log information for DNS errors.
Fix an issue where certain invalid DNS records could cause a crash.
v4.0.1
Fixed a bug that UDP packets can't be forwarded to IPv6 addresses.
Surge Mac as Snell Proxy Server
You may also use Surge Mac as a Snell proxy server (Starting from version 3.1.0). Add the following lines to your profile.
The embedded Snell server in Surge uses the Snell V1 protocol.
Last updated