docs/configuration/shared/pre-match.md
!!! quote "Changes in sing-box 1.14.0"
:material-alert: [route](#route)
:material-plus: [sniff](#sniff)
!!! quote "Changes in sing-box 1.13.0"
:material-plus: [bypass](#bypass)
Pre-match is rule matching that runs before the connection is established.
When an L3 inbound (TUN, WireGuard, or Tailscale) receives a connection request, the connection has not yet been established: for TCP connections no connection data is available, while for UDP connections only the first packet is available. In this phase, sing-box runs the routing rules in pre-match mode.
When a rule matches an action that requires more connection data than available, pre-match stops at that rule.
Reject with TCP RST / ICMP unreachable.
See reject for details.
!!! quote "Changes in sing-box 1.14.0"
Since sing-box 1.14.0, TCP and UDP connections can also be forwarded at L3;
previously only ICMP connections were supported.
Forward connections directly at L3 to the specified outbound, without going through L3 to L4 translation.
Supported targets:
L3 forwarding also applies when no rule matches and the default outbound is a supported target; for outbound groups, the currently selected outbound is used.
FakeIP destinations require a resolve action performed in pre-match,
otherwise connections will be rejected.
See route for details.
!!! question "Since sing-box 1.14.0"
For UDP connections, the first packet is available in pre-match, so protocol sniffing runs on it directly and rule matching continues with the sniffed metadata.
When sniffers require more data (like a fragmented QUIC Client Hello), pre-match stops at that rule.
For TCP connections, pre-match always stops at that rule.
See sniff for details.
!!! question "Since sing-box 1.13.0"
!!! quote ""
Only supported on Linux with `auto_redirect` enabled.
Bypass sing-box and connect directly at kernel level.
If outbound is not specified, the rule only matches in pre-match from auto redirect,
and will be skipped in other contexts.
For all other contexts, bypass with outbound behaves like route action.
See bypass for details.