Overview
Developed by GitMetaio, Surfing is an advanced network redirection module that transforms rooted Android devices into full-fledged transparent routing gateways.
Instead of running battery-draining VPN interfaces that monopolize Android’s single VpnService slot, Surfing operates directly at the Linux kernel firewall layer. Using native iptables and nftables rule chains, it intercepts socket traffic at the network stack and directs it into high-performance core daemons including Clash.Meta (mihomo), sing-box, Xray, or Hysteria.
Technical Architecture & How It Works
Kernel Firewall Interception & Core Forwarding
Surfing isolates its configuration, runtime binaries, and routing rules inside /data/adb/box_bll/:
- Proxy Modes:
- TPROXY (Default): Leverages
iptables -t mangle -A PREROUTING -p tcp/udp -j TPROXYto redirect both TCP and UDP sockets transparently to local port1536without touching application headers. - REDIRECT: Fallback TCP-only redirection to local port
7891. - TUN: Emulates a virtual network device (
Meta) for protocols incompatible with socket splicing.
- TPROXY (Default): Leverages
- Network State Automation: The helper daemon monitors network interface transitions (switching from Wi-Fi to cellular, roaming between Wi-Fi SSIDs). Rules dynamically disable or enable proxy chains based on the whitelist/blacklist definitions in
box.config. - App Isolation & UID Exclusions: Uses Linux cgroups and
net_adminGIDs to exempt the core proxy binary and specified Android application packages from being looped back into the proxy listener.
Installation & Setup
1. Flash the Module
- Download
Surfing-v*.zipfrom the project’s official releases. - Flash the module via Magisk, KernelSU, or APatch.
- Reboot your device.
2. Configure Subscriptions
Before network redirection takes effect, you must provide a valid proxy subscription:
- Open the SurfingTile application on your home screen and grant it superuser access.
- In Menu > Config Override, paste your provider subscription URL and trigger an update.
- Alternatively, place your raw configuration directly into:
/data/adb/box_bll/clash/config.yaml - Restart the service or reboot to apply the routing configuration.
Configuration & Practical Usage
Fine-tuning is handled directly in /data/adb/box_bll/scripts/box.config:
- Proxy Method Selection:
proxy_method="TPROXY" # Options: REDIRECT, TPROXY, TUN, or MIXED - App Bypass List:
Exclude specific application UIDs and user profiles from proxy interception:
user_packages_list=("0:com.android.captiveportallogin" "0:com.google.android.gms") - Wi-Fi Filtering:
Automatically disable the proxy on trusted home or enterprise networks:
enable_ssid_filter="true" use_wifi_list_mode="blacklist" blacklist_wifi_ssids="Home_Network,Office_5G"
Troubleshooting & Common Issues
- No Internet Access After Boot: Check
/data/adb/box_bll/run/clash.pidto ensure the core binary started successfully. If your subscription fails to fetch due to strict remote validation, try changing the user agent setting (Ua) in your configuration profile. - Hotplug Bypass Conflicts: When using
proxy_method="TUN", ensure thatbypass_via_iptablesis set to"false"inbox.configto prevent routing loop conflicts between TUN interfaces and iptables mangle chains.
Frequently Asked Questions
Why does the management dashboard fail to display in SurfingTile?
The management panel relies on modern Chromium features. If the dashboard fails to render or displays a blank screen, update the com.google.android.webview package through the Google Play Store.
Can I use both Wi-Fi SSID filtering and MAC address filtering at the same time?
No. According to box.config documentation, SSID filtering and MAC address filtering are mutually exclusive. When both are enabled simultaneously, SSID filtering takes priority over MAC filtering.