Skip to content

Helper local ports and LAN access ​

Complete installation and sign-in first. The default loopback listener is for Surge or another proxy app on the same Mac.

Helper: local ports and LAN access
Chinese simulated interface with fictional data · Click to view full size

Configuration ports versus proxy ports ​

Default portPurpose
6172HTTP configuration/node-list service, not an ordinary HTTP proxy
7100Mixed proxy in menu-bar single-port mode
Starting at 7200Per-node listeners in mapping mode

Check actual values under Connection → Local port…. After changing them, update consuming clients and run Apply in Surge again.

The default configuration service is http://127.0.0.1:6172:

PathContent
/Surge profile for the current mode
/listSurge policy-path node list
/clashClash YAML Provider to reference from a full configuration
/opensurgeOpenSurge import configuration
/mapMenu-bar mode's port-mapping configuration
/healthHTTP-service liveness check
/statusRuntime and mapping status

Use Copy local node list URL for local apps expecting a node list. Export OpenSurge configuration produces a different import format, not a universal profile for every client.

Access from trusted LAN devices ​

  1. Set a dedicated username/password under Connection → LAN authentication….
  2. Enable Allow LAN access and permit the required trusted-LAN traffic through the system firewall.
  3. On the other device, use the Helper computer's LAN IP, not 127.0.0.1. Choose the configuration or proxy port according to the task.
  4. Supply HTTP Basic credentials when retrieving protected profiles, or HTTP/SOCKS5 proxy credentials for the proxy protocol in use.
  5. Refresh the receiving client's configuration and test a new connection. Update it again when the Mac's IP, port or authentication changes.

Allow only the network scope you need; do not expose these ports publicly through router forwarding. LAN authentication is separate from your oixCloud sign-in credentials.

Fixed mappings and node changes ​

In CLI configuration, omitting listeners enables automatic mappings, [] creates no mapped listeners, and a nonempty array creates only declared listeners. A fixed node name must exactly match the current list; filtering it out prevents that listener from being created.

Automatic mappings change with the node list. Do not assume an automatic port permanently identifies one node. Use fixed mappings for applications requiring stable ports and confirm the target node remains available.

UDP and reachability ​

SOCKS5 UDP forwarding uses separate association ports; opening only the TCP proxy port is insufficient. Containers/NAT also need a UDP range and a reachable advertised address; see Linux and runtime diagnostics.

For LAN failures, check listening address, computer IP, firewall, credentials, retained nodes and port conflicts in that order. Reaching the configuration page does not prove an upstream proxy works.

Features checked: 29 September 2026 · One topic per page